cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
8777
Views
0
Helpful
42
Replies

FN - 63979 - ASR9000, CRS, and XR12000 That Run Cisco IOS-XR 5.3.0 and Earlier - Oct 17, 2015 SW Certificate Expiration - SMU Upgrade

Eddie Chami
Cisco Employee
Cisco Employee

This is a place holder for questions on FN 63979

Details are here: http://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63979.html

Use this thread to ask any questions. 

42 Replies 42

NayatelPakistan
Level 1
Level 1

Hi Eddie,

We have ASR9k platform and XR version 5.1.2 and are going to install an SMU to fix a bug. I tried to add the SMU but it showed error of certificate expired. I have gone through this thread and different ones. Is it necessary to install CSCup93021 pie or i can just add certificate through below procedure(example)

RP/0/RSP0/CPU0:ROUTER# run
Wed Dec 21 06:19:43.207 UTC
# samcmd sam add certificate /disk0:/css-root.cer root trust
SAM: Successful adding certificate /disk0:/css-root.cer
I did the same procedure and i guess cert was installed but then when i try to add required SMU it still shows expired cert? what am i missing here? do i have to install SMU CSCup93021 first and then the second SMU?
Cheers

Hi, You'll need to follow these steps:

1) Copy the cert (it looks like you've completed this)

2) Install CSCut52232 (It looks like your missing this)

3) You can then install CSCup93021

Regards

Eddie. 

Hi Eddie,

am sorry i mistyped SMUs in my question. so here i am mentioning the steps again with correct SMUs, pls confirm once more

1. Add cert (have already done through samcmd add cert in shell)

2. Install CSCut52232 (its tagged as hitless means shouldnt interrupt device operations?)

3. Install CSCup93021 (recommnded to fix a bug)

Cheers

Correct steps and correct assumption in step 2 about the SMU being hitless.

Regards

Eddie. 

Hi Guys,

I have the same Issue of Nayatel.

From 5.1.2 to 5.1.3

I downloaded the asr9k-px-5.1.2.CSCut52232.tar and installed correctly, after that Do I need to install another package? CSCup93021? for 5.1.2.o 5.1.3 rel?

After that, can I to proceed with upograde to 5.1.3 rel?

Thanks for your help,

A.

CSCup93021 is already fixed in 5.1.3 release. You can just upgrade from 5.1.2 to 5.1.3 without SMU for.

Please make sure that all the 5.1.3 recommended SMUs are added and activated on the node.

Thanks,

Santosh

Before the uprade I tried to install only asr9k-px-5.1.2.CSCut52232.tar and then upgrade but I receive the same issue: certification expire!

Is it mandatory to install the cert.css from console o Can I install from shell with root and trust?

Thx

A

Yes, cert.css is mandatory.

Below will be the set of steps:

1. add "cert.css".

2. install add/activate "asr9k-px-5.1.2.CSCut52232.tar"

3. Install add 5.1.3 pies/SMUs

4. Install activate 5.1.3 pies/SMUs

Thanks,

Santosh

Thanks, I will try!!!

A.

or if you want to save yourself the hassle, just set your router clock back to 2013 before you upgrade.

Thanks guys, I am upgrading ;)

Try this

run
samcmd sam add certificate „location“ root trust

smailmilak
Level 4
Level 4

Hi, 

command "run" will get me into shell and from there I can add the cert?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: