Validate the digital signature and the SHA 512 digests for all files.
About this task
After you locally upload the LCM
bundles or download them from the Internet, the bundles are automatically verified. To
manually verify the bundles, perform the following steps.
Steps
To download the VxRail updates feature, perform the following:
From VMware vSphere Web Client, select the Inventory icon.
Select the VxRail cluster and click the
Configure tab.
Select
VxRail > Updates.
To upload software to VxRail Manager, select an option from the following tabs:
System: Lists the
Current VxRail System Version and the Installed Components and Versions.
Internet Updates: Downloads a new version of the VxRail software. You must have Internet access. If more than one version is available, select
ALL Available System Updates or
Recommended System Updates.
Local Updates: Uploads a new version of the software from your local storage if you do not have Internet access.
Connect to VxRail Manager using an SSH client such as PuTTy.
Log in as mystic.
Go to the location of the extracted LCM bundle and list the code-signed
artifacts.
>cd /data/store2/lcm/unpacked
>ls -l LCMsign*
-rw-r--r-- 1 tcserver pivotal 15669 Jun 9 06:33 LCMsigninput.txt
-rw-r--r-- 1 tcserver pivotal 15669 Jun 9 06:33 LCMsigninput.txt
Where:
LCMsigninput.txt is the manifest of file
names and original sha384 message digests.
LCMsigninput.txt.signed contains the public key and
digital signature certificate.
To verify the publisher and the certification chain are trusted, enter:
If Verified OK displays, the integrity of the manifest file is assured and the file digests can be trusted. If Verified Failure displays, ensure that the LCM bundle is obtained from a trusted source such as Internet updates (mentioned in step1 to 4) or downloaded from Dell Technologies.
To verify the LCM bundle contents against the message digests, enter:
>sha512sum -c LCMsigninput.txt
This command calculates the sha512 digest for each file in the
extracted bundle and compares the result with digests that are recorded in
the signed manifest. The verified file name displays and if the digests
match, the result is OK. If the digests do not match, the
files were modified or corrupted.
Complete the upgrade process.
Data is not available for the Topic
Please provide ratings (1-5 stars).
Please provide ratings (1-5 stars).
Please provide ratings (1-5 stars).
Please select whether the article was helpful or not.
Comments cannot contain these special characters: <>()\