Cumulative history and Readme for use with HMC V5.1
[ Last updated: June 15, 2006 ]
Contents
The information in this Readme contains hints and errata information about the Hardware Management Console.
There is no Corrective Service package to update to HMC Version 5 Release 1.0 from HMC Version 4. Users must perform a Save Upgrade Data task to preserve HMC configuration data such as partition profiles, HMC users and HMC configuration, and then use HMC Version 5 Release 1.0 media to upgrade.
Recommended code levels
To find recommended HMC and server code levels for the currently supported for IBM Power Systems, consult the POWER code matrix at.
Specific PTF information
This section lists the PTFs released for HMC V5 R1.0. The information for each PTF includes sections for enhancements and fixes, known issues (if applicable), and package information. The Package information section provides information to use during the download, installation and verification procedures for HMC corrective service/upgrade packages. For example, you can check the sizes and checksums of downloaded packages, and use the "Splash panel" information to verify that a fix or update was applied successfully. You can also access this PTF-specific information by clicking on the "View" link for any package on the "Downloads" pages of the HMC web site.
PTF MH00933
This package is critical for customers in China that connect to the IBM service provider using a modem for remote service and support.
The phone numbers used to connect to the IBM service provider from China have changed. You must make configuration changes and install this package prior by January 31, 2007, to avoid a disruption in remote service and support from China. Refer to Enhancements and Fixes for a full description of the steps required to make this change.
You can also reference this package by APAR MB01994.
Package name | Size (bytes) | Checksum | APAR # | PTF# |
---|---|---|---|---|
MH00933.zip MH00933.iso |
33,594,758 35,698,688 |
42425 52741 |
MB01994 | MH00933 |
Splash panel information (lshmc -V command output) | ||||
MH00933: Update Modem Connectivity to the IBM service provider in China (01-15-2007) |
Enhancements and fixes
This package provides the following fix:
Update Modem Connectivity to the IBM service provider in China
As of February 1, 2007, the existing phone numbers used by the HMC to connect to the IBM service provider within China will be discontinued. Effective immediately a new, expanded set of phone numbers are available to connect to IBM in China.
Before your HMC can successfully connect to the IBM service provider using these new numbers, this package must be installed on your HMC. We recommend that you configure a minimum of two phone numbers.
The new North China phone number 16970 can be dialed from the following cities.
- AnShan
- BaoDing
- BeiJin
- ChanChun
- DaLian
- HaRBin
- JiNan
- LinYi
- QingDao
- QinHuangDao
- QuQuHaR
- ShenYang
- ShiJiaZhuang
- Tai Wan
- Tang Shan
- Tian Jin
- WeiFang
- Wei Hai
- YanTai
- ZhenZhou
The new South China phone number 4006 744444 can be dialed from the following cities.
- Beng Bu
- Chang Sha
- Chang Zhou
- Chao Zhou
- Cheng Du
- Chong Qing
- Dong Guan
- Fo Shan
- Fu Zhou
- Guang Zhou
- Gui Lin
- Gui Yang
- Hai Kou
- Hang Zhou
- He Fei
- Jiang Men
- Ka Shi
- Kun Ming
- La Sa
- Long Yan
- Mei Zhou
- Nan Chang
- Nan Jing
- Nan Ning
- Ning Bo
- Pu Tian
- Quan Zhou
- Shan Tou
- Shang Hai
- Shao Xing
- Shen Zhen
- Shun De
- Su Zhou
- Urumqi
- Wen Zhou
- Wu Han
- Wu Xi
- Xi An
- Xi Ning
- Xia Men
- Yi Chang
- Yin Chuan
- Zhan Jiang
- Zhang Zhou
- Zhou Qing
- Zhou Shan
- Zhu Hai
- Zhu Zhou
The following phone numbers will be accessible throughout China.
Beijing
10 64690167
Chongqing
23 86304802
Chengdu
28 66001617
Fuzhou
591 28305594
Guangzhou
20 22235744
Hangzhou
571 28887167
Hefei551
551 7126504
Kunming
871 8099004
Nanchang
791 2174400
Qingdao
532 85765558
Shanghai
21 61006167
Shenzhen
755 33380169
Suzhou
512 85180144
Tianjin
86 22 83310772
Wuhan
86 27 59708844
Xiamen
86 592 3196244
You may continue to connect to the IBM service provider electronically from China without installing this package if you can do either of the following:
Use an existing broadband connection to connect to IBM.��� You can configure either the Internet VPN or Internet SSL option.
OR
Configure your HMC to call home using an international call to an AT&T access point outside of China. The following numbers may be convenient alternatives. Note that international dialing codes must be added to call them from China.
Hong Kong
3001-1700
Singapore
6825-1800
Seoul
02-3018-3073
Steps required to change phone numbers used to connect to the IBM service provider
- Before you begin, install this package.
- Log on the Hardware Management Console. In the navigation area,��� open Service Applications.��� Select the Remote Support Option, and then click Configure Outbound Connectivity.
- Within the Customize Outbound Connectivity Pane, click the Local Modem Tab.��� Within the Local Modem tab, locate the Telephone Number box, and then select Add.
- From the Add Telephone Number pane, make sure that China is selected as the Country or Region.��� Compare the phone numbers displayed to the list shown above.��� If the new numbers are displayed in the list, select a number from the list, and then click Add.���
- If the newer numbers are not yet on your list, you may type the numbers in the Telephone Number field instead of selecting of one of the numbers displayed. Note that if you manually enter these numbers, there is an additional requirement that the System Address, as specified in the Customize Customer Information Pane, is set to China.���
- IBM recommends that a minimum of two phone numbers be configured for each Call Home server.��� You may test your connectivity to each phone number from the Customize Outbound Connectivity Pane.
- Once you have successfully tested your connectivity using the new numbers, you should remove the older numbers from the list of Telephone numbers.������ From the Customize Outbound Connectivity Pane, select the phone number you wish to remove, and then click Remove.
- After you have completed all your changes, click OK from the Customize Outbound Connectivity Pane.
PTF MH00891 (Security fixes)
This package provides OpenSSL and Open SSH security fixes for HMC V5. You can also reference this package by APAR MB01905. It replaces MH00857
Package name | Size (bytes) | Checksum | APAR # | PTF# |
---|---|---|---|---|
MH00891.zip MH00891.iso |
3570046 3958784 |
40431 17045 |
MB01905 | MH00891 |
Splash panel information (lshmc -V command output) | ||||
MH00891: OpenSSL/OpenSSH security fixes for HMC V5 (11-07-2006) |
Enhancements and fixes
This package provides the following security fixes:
Name | Description |
---|---|
CVE-2006-3738/VU#547300 | Fix buffer overflow condition. |
CVE-2006-4343/VU#386964 | OpenSSL SSLv2 client code fails to properly check for NULL which could lead to a server program using openssl to crash. |
CVE-2006-2937 | Fix mishandling of an error condition in parsing of certain invalid ASN1 structures, which could result in an infinite loop which consumes system memory. |
CVE-2006-2940 | Certain types of public keys can take disproportionate amounts of time to process. This could be used by an attacker in a denial of service attack to cause the remote side top spend an excessive amount of time in computation. |
CVE-2006-4924 | Denial of service problems have been fixed in OpenSSH which could be used to cause lots of CPU consumption on a remote openssh server. |
CVE-2006-4925 | Fix problem where remote attacker is able to inject network traffic that could cause a client connection to close. |
PTF MH00857 (Security fix)
This package provides an OpenSSL security fix for HMC V5. You can also reference this package by APAR MB01870.
Package name | Size (bytes) | Checksum | APAR # | PTF# |
---|---|---|---|---|
MH00857.zip MH00857.iso |
3530344 3915776 |
33939 11789 |
MB01870 | MH00857 |
Splash panel information (lshmc -V command output) | ||||
MH00857: OpenSSL security fix for HMC V5 (10-10-2006) |
Enhancements and fixes
This package provides the following security fix:
CVE-2006-4339: OpenSSL RSA signature evasion
PTF MH00840
This PTF provides a command monkacpid, that allows processor usage of the keventd kernel daemon. This PTF can be referenced by APAR MB01844.
Package name | Size (bytes) | Checksum | APAR # | PTF# |
---|---|---|---|---|
MH00840.zip MH00840.iso |
4155 389120 |
06580 05331 |
MB01844 | MH00840 |
Splash panel information displayed after installation | ||||
MH00840: monkacpid to monitor acpi events (09-14-2006) |
Enhancements and fixes
A number of internal modems, when installed in HMC Machine Type 7310-C04 or 7310-C05, are affecting the performance of the HMC. If you have such an HMC configuration, install this PTF, and then run the monkacpid command from either
- a restricted shell terminal at the HMC, or
- a remote client over SSH.
This command produces output similar to the following. The output is refreshed every 4 seconds.
Every 4s: /usr/bin/top -s -b -n 1 -p 3 Thu Sep 14 14:57:19 2006 top - 14:57:20 up 53 min, 2 users, load average: 0.17, 0.10, 0.08 Tasks: 1 total, 0 running, 1 sleeping, 0 stopped, 0 zombie Cpu(s): 5.5% user, 1.0% system, 0.0% nice, 93.5% idle Mem: 1022096k total, 919596k used, 102500k free, 32516k buffers Swap: 2032212k total, 0k used, 2032212k free, 264288k cached PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND 3 root 15 0 0 0 0 S 0.0 0.0 0:00.02 keventd
If the number in the %CPU column is greater than 10.0, please contact IBM Hardware support to order a replacement modem. Please reference Retain Tip H187630.
PTF MH00837
Fix missing cron entries after an upgrade
This PTF fixes problems with missing cron entries and file permission that occur following an upgrade.
Notes:
- If you have installed MH00822 and performed the upgrade by using the rstupgdata command, then install MH00837 after the reboot and restore are complete.
- If you happened to install MH00837, and then installed MH00822 to perform the upgrade, then you must re-apply MH00837 after the reboot and restore are complete.
This PTF can also be referenced by APAR MB01796.
Package name | Size (bytes) | Checksum | APAR # | PTF# |
---|---|---|---|---|
MH00837.zip MH00837.iso |
36151 25487 |
7798 403456 |
MB01796 | MH00837 |
Splash panel information (or lshmc -v output) | ||||
MH00837: Fix missing cron entries (09-05-2006) |
Enhancements and fixes
Fixes these problems following and Upgrade to HMC Version 5:
- cron entries needed for LPAR utilization data collection are missing.
- user is unable to log in and download websm client.
PTF MH00822
rstupgdata for HMC Version 5
This PTF provides a new command, rstupgdata, that can be used to restore upgrade data, saved on DVD-RAM, after a new Install of HMC Version 5. You can also reference this package by APAR MB01665.
Package name | Size (bytes) | Checksum | APAR # | PTF# |
---|---|---|---|---|
MH00822.zip MH00822.iso |
21432 440320 |
62248 05297 |
MB01665 | MH00822 |
Splash panel information (or lshmc -v output) | ||||
MH00822: rstupgdata command for HMC V5 (08-18-2006) |
Enhancements and fixes
A number of HMC machine types, 7310CR2/7315CR2/7310CR3/7315CR3, have experienced upgrade failures when moving from HMC V4.x to HMC V5.x, or from HMC V5.1 to HMC V5.2.x. Because of this issue, IBM strongly recommends the use of the following upgrade method to upgrade from HMC V4.X to HMC V5.X, or from HMC V5.1 to HMC V5.2.0 or V5.2.1. This method can be used on all machine types.
PTF MH00690
Fix /var filesystem full problem in V5R1.2
This PTF can only be installed on code level HMC V5R1.2. This PTF (MH00690) is also referenced by APAR MB01377.
Enhancements and fixes
This package includes fixes for the following issues:
- Fix for saving user task roles to be persistent across HMC reboots.
- Corrects problem with /var filesystem filling up. This may result in unpredictable behavior. After a reboot the HMC Login may Fail and Return User to Sign On Prompt.
Package name | Size (bytes) | Checksum | APAR # | PTF# |
---|---|---|---|---|
MH00690.zip MH00690.iso |
13244895 13838336 |
11740 09580 |
MB01377 | MH00690 |
Splash panel information displayed after installation | ||||
MH00690: Fix /var filesystem full problem in V5R1.2 (05-19-2006) |
PTF MH00593
HMC Maintenance Package Version 5, Release 1.2. This package includes fixes previously provided in MH00493, MH00507, MH00607, MH00534 and MH00523. If you are upgrading to HMC Version 5 Release 1.0, you must install this maintenance package.
Enhancements and fixes
This package includes the following fixes or enhancements:
DST
Fix for Daylight Saving Time changes
Code Update
- Code Update enhancement to replace incomplete firmware image on hard drive from a previous failed code update.
- Corrected a Redundant FSP Code Update problem so that HMC will commit code on secondary FSP even if primary FSP has already been accepted ( 595, 590, 570 w/ R-FSP FC).
- Enhancement to Code Update Deferred Fix Pack Messages to better define deferred fix activation and list deferred fixes. Deferred fixes can be applied sequentially with out activating previously applied deferred fixes.
- Fix to allow operating system upgrades using FTP Option and Windows FTP Server
- The Code Update Release Upgrade GUI has been enhanced to allow a user to select a supported release level from a list of currently available releases. Prior to this level of HMC code, the Code Update GUI always defaulted to the most current level of FW and did not give the user a choice.
- The confirmation panel for release upgrades has been enhanced to show the old Engineering Change Number, old Firmware Level, new old Engineering Change Number and new Firmware Level. The previous panel showed only the old EC Number and new EC Number, but not the Firmware levels.
- Code Update levels displayed on System Information panel will reflect only the repository that is being targeted, and not the level on the HMC hard drive.
- Corrected a Firmware Code Update problem that caused the Code Update function to require the hscroot userid if an FSP reboot was required.
- Corrected a managed system common targeting locking issue that could be encountered after canceling an MES Code Update.
- Corrected Dual FSP code Synch to properly set next IPL side on secondary.
- Status messages have been added to the confirmation panel after a release upgrade or downgrade.
Scheduled Operations
Correction of a problem that caused Scheduled Operations to be lost on reboot and the logging of reference code E3550046.
Logging
HMC Logging enhancements which reduce memory usage. Without this enhancement, over time, the creation of many different types of log entries could consume enough memory to impact the stability of the HMC.
Repair and Verify
- Corrected the Repair and Verify panels for model 520 GX adapter replacement
- Repair and Verify support for new concentric clamp hardware for 590/595. New concentric clamp hardware for Squadrons H 590/595 systems requires that before installing a PU Book, the concentric clamp bushing and pin are flush with one another. A check must be performed to ensure they are flush or the PU Book will not seat correctly, causing system downtime and possible damage to the PU Book connectors.
- The Repair and Verify procedures and Exchange parts screens for FSP, VPD, and Clock card programmatically removes power at the node DCA for the managed system only rather than directing the CE to EPO the entire frame.
- Enhanced the Repair and Verify exception handling code to allow for multiple FRU queries and allow for retry.
Save Upgrade Data/Backup
Corrected problem causing virtual retain data to not be sent during a call home operation.
Problem Analysis/Call Home
- The manual call home settings have been disabled for the 7048 switch errors because it is not supported.
- Problem Analysis enhancement to Extended Error Data to include server/partition firmware levels.
- Corrected an issue that caused dump retrieval to fail when multiple threads attempted to read dumps simultaneously.
- Enhanced handling of Managed System disconnects and reconnects so that error logs are not discarded.
- Correction to direct some European calls to proper URSF.
Service Agent
- Service agent enhancement to include hmc hostname in data sent to RETAIN.
- Fix to Service Agent generated emails for RFC 2822 compliancy for users with QMail SMTP.
User Management
- Corrected Japanese Managed Object Roles panels to display Japanese characters in ja_JP Locale.
- Allows user creation with "0" & " ' " in the description field.
HMC Management
Fix compatibility problem when remotely managing HMC's in a mixed environment, where HMC's are installed with different code levels.
Miscellaneous
Provides fix for IBNM performance/hang problems during rendering of IBNM dialogs.
Partition Management
- Fix for activating a VIO server partition with ethernet trunk adapter that's assigned to a shutdown partition.
- Added GUI error message to indicate a required virtual slot cannot be removed.
- Fix problem where system profile partition activation's order is not preserved.
- Fix for the create logical partition profile summary to show the correct number of virtual adapters created.
Security
Fix to disable DNS look-up access for SSH (CVE-2003-0386)
Package name | Size (bytes) | Checksum | APAR # | PTF# |
---|---|---|---|---|
MH00593_1.zip MH00593_2.zip MH00593_1.iso MH00593_2.iso |
565676446 660638136 568715264 660987904 |
32476 53481 52385 24828 |
MB00005 | MH00593 |
Installation verification | ||||
Display the Splash panel or run the lshmc -V command and check for the following information. | ||||
"version= Version: 5 Release: 1.2 HMC Build level 20060225.1 ","base_version=V5.1.0 " |
PTF MH00607
Fixes for Dump Collection issues on redundant FSP
This PTF can only be installed on an HMC that is a one of the following code levels:
- HMC V5R1.0 and PTF MH00507
- HMC V5R1.1
- HMC V5R1.1 and PTF MH00523
For model 9119-590, 9119-595, 9406-595, 9116-561 and 9117-570 systems with redundant service processor feature at system firmware levels SF235_160, SF235_180, and SF235_185:
A system firmware problem has been identified that will cause the secondary service processor (FSP) to reset during run time causing an FSP dump to be taken. The HMC currently does not collect the dump from the secondary FSP so after multiple occurrences, the FSP dump space will fill up resulting in the secondary FSP becoming deconfigured (GARDed) when no hardware problem exists.
The system will lose service processor redundancy and continue to run without interruption. Restoring service processor redundancy will require a scheduled maintenance outage.
To prevent the secondary FSP from becoming GARDed, HMC PTF MH00607 has been created to collect dumps from the secondary FSP so that the FSP's dump space will not fill up.
Enhancements and fixes
This package includes fixes for the following issues:
- Dump is not retrieved properly from redundant FSP.
- SFP event is not logged for missing FSP card.
Package name | Size (bytes) | Checksum | APAR # | PTF# |
---|---|---|---|---|
MH00607.zip MH00607.iso |
13849345 15079424 |
08944 41687 |
MB00011 | MH00607 |
Splash panel information displayed after installation | ||||
MH00607: Fix Dump collection issues (02-25-2006) |
PTF MH00523
Remote HMC Management fix
Notices:
Do not install this PTF if you are using the IBM Network Manager product.
Install this PTF ONLY if your HMC is currently at V5R1.1. That is, this package should be installed only if you have already installed PTF MH00534
Enhancements and fixes
This package includes fixes for the following issues:
- Fix remote HMC management problem:
After applying PTF MH00534, if you add an HMC running V5R1.0 to the list of hosts to be managed by an HMC running V5R1.1, and then try to access tasks on the HMC running V5R1.0, you will get the error "HSCP0155 The task is unavailable. Please try again later." - CVE-2003-0386: OpenSSH Reverse DNS Lookup Access Control Bypass Vulnerability
Package name | Size (bytes) | Checksum | APAR # | PTF# |
---|---|---|---|---|
MH00523.zip MH00523.iso |
4396 395264 |
42746 40202 |
MB01300 | MH00523 |
Splash panel information displayed after installation | ||||
MH00523: Remote HMC Management fix (01-12-2006) |
PTF MH00534 (replaces PTF MH00522)
NLS enhancement for HMC Version 5 Release 1
This PTF can be applied on any HMC at Version 5 Release 1.0, including:
- PTF MH00407
- PTF MH00455
- PTF MH00464
- PTF MH00493
- PTF MH00507
- PTF MH00522
Applying PTF MH00534 to an HMC 5.1 with any of the following PTFs installed:
- PTF MH00455
- PTF MH00493
- PTF MH00507
removes the information entry for the PTF(s) from the output of the lshmc -V command. The fixes provided in these PTFs are not removed, merely the entry for the PTF in the lshmc command output. This PTF includes all the fixes provided by MH00507 and MH00493. PTF MH00534 replaces the previously released PTF MH00522.
Enhancements and fixes
This package includes the following enhancements and fixes:
- Enhancements to support locale setting with the following commands : chhmc and lshmc.
- Additional locale supports: BiDi (Bi-directional), UTF-8, and other locales. Use lshmc ���L to see the list of locales supported.
- Additional keyboards support. There are multiple pages for the keyboard configuration. During the keyboard configuration, enter 98 to go the next page and 97 to go to the previous page.
- IBM Network Manager (IBMNM) product support from an HMC perspective. Please refer to the HPSNM/IBMNM page for availability of the IBMNM Service Packs. The Service Packs, together with the IBMNM enhancement in MH00534, provide full support for IBM Network Manager.
- Fixed problem of creating users after applying PTF MH00522: Users created after applying PTF MH00522 cannot see the console when logging in at the local HMC.
- Fixed problem with GRUB corruption after restoring critical console data: When backing up critical console data, files under /boot are not required to be backed up as they are not needed and can cause GRUB to be destroyed. After installing this PTF, perform a critical console data backup again to make sure these files are no longer backed up.
Package name | Size (bytes) | Checksum | APAR # | PTF# |
---|---|---|---|---|
NLS_MH00534.zip NLS_MH00534_1.iso NLS_MH00534_2.iso |
868656191 568571904 303470592 |
51911 59349 49936 |
MB01310 | MH00534 |
Splash panel information displayed after installation | ||||
The Version is 5 The Release is 1.1 HMC Build level 20060104.1 |
PTF MH00507 (replaces PTF M00455)
Maintenance Fix that must be installed on HMC Version 5 Release 1.0. This fix replaces PTF MH00455. If you have not yet installed MH00455, do not install it. Install MH00507 instead. If you have already installed MH00455, install MH00507 as well.
Enhancements and fixes
This package contains all the fixes included in MH00455, as well as additional fixes. It addresses the following issues:
- Support for code update health check.
- Support for secure ASM proxy.
- Fix for frame name change independent of cage status.
- Fix for miscellaneous repair and verify functions.
- Fix for miscellaneous code update function.
- Fix for multiple call home issues.
- Fix for miscellaneous IBMNM function.
- Fix for logging of IP address by "logssh".
- Fix for help in the GuidedSetupWizard panels.
Package name | Size (bytes) | Checksum | APAR # | PTF# |
---|---|---|---|---|
MH00507.zip MH00507.iso |
476166630 485728256 |
47490 19470 |
MB00003 | MH00507 |
Splash panel information displayed after installation | ||||
The Version is 5 The Release is 1.0 HMC Build level 20051110.1 MH00507: Maintenance Package for V5R1.0 (12-03-2005) |
PTF MH00493
Notice:
Install this PTF ONLY if your HMC is currently at V5R1.0. Check the "About" splash panel on your HMC to find your current Version/Release level.
Fixes for leap second handling, DST time and openssl
Enhancements and fixes
This package includes fixes for the following issues:
- New library to handle leap second and DST time zone properly.
- Provides CAN-2005-0109: OpenSSL update.
- Provides CAN-2005-2969: OpenSSL fix for potential SSL 2.0 Rollback vulnerability
Package name | Size (bytes) | Checksum | APAR # | PTF# |
---|---|---|---|---|
MH00493.zip MH00493.iso |
35701547 36104192 |
13029 31768 |
MB01275 | MH00493 |
Splash panel information displayed after installation | ||||
MH00493: Fixes for leap second handling, DST time and openssl (11-29-2005) |
PTF MH00464
InfoCenter update package
Enhancements and fixes
Update to Information Center for HMC V5R1.0.
Package name | Size (bytes) | Checksum | APAR # | PTF# |
---|---|---|---|---|
MH00464.zip MH00464.iso |
366864620 368089088 |
61910 26943 |
MB01252 | MH00464 |
Splash panel information displayed after installation | ||||
MH00464: InfoCenter Update for V5R1.0 (10-27-2005) |
PTF MH00455 (replaced by MH00507)
This maintenance fix for HMC 5.1 was replaced by MH00507. All the enhancements and fixes for this package are included in MH00507. If you have not yet installed MH00455, do not install it. Install MH00507 instead. If you have already installed MH00455, install MH00507 as well.
Enhancements and fixes
The fixes in this package are included in MH00507:
- Support for code update health check.
- Support for secure ASM proxy.
- Fix for frame name change independent of cage status.
- Fix for miscellaneous repair and verify functions.
- Fix for miscellaneous code update function.
- Fix for multiple call home issues.
- Fix for miscellaneous IBMNM function.
- Fix for logging of IP address by "logssh".
PTF MH00407
HMC V5 R1.0 upgrade and recovery package
Enhancements and fixes
This package includes the following enhancements:
- Install/Backup/Restore over network.
- Support to configure Host Channel Adapter
- Support for Mobile CoD
- Support for Enhanced Manage On/Off CoD
- Support for Virtual IO Server Shared Ethernet failover
- Support for IO Server Enhancements for VIOS and RPA partitions
- Support for Redundant FSP with Dynamic failover
Known Issues with Upgrading from HMC Version 4 to Version 5
This package has the following known issues:
- At HMC 5.1, a License Internal Code update executed by any non-hscroot user will result in error ACT01724 with an E302F927 or E302F874 SRC logged in Service Focal Point.
To resolve the issue, under the Licensed Internal Code Update menus, check the accepted, installed, and activated levels now on the system and if necessary, take appropriate action or restart the code update as hscroot.
- The Certificate Authority public key file for use with Websm Java Webstart client is not preserved when upgrading HMC from version 4 to version 5. The result is a warning message that a non-secure connection will be used when connecting to the upgraded HMC version 5, with Java Webstart client.
To resolve this problem, regenerate the Certificate Authority public key file by following these steps at the local HMC:
- Select System Manager Security ' Certificate Authority ' Copy this Certificate Authority's public key ring file to removable media. Perform this operation at the local HMC where the Certificate Authority was defined and the server keys were previously generated.
- Insert a media to receive the public key ring file, then select HMC or AIX Client option when prompted.
- When the task completes, use the media created on the HMC that the webstart client was downloaded from. Select System Manager Security ' Certificate Authority ' Copy Another Certificate Authority's public key ring file from removable media.
- When the task completes, the Certificate Authority public key ring file will be re-created on the HMC.
- When Jave Webstart client contacts the HMC, it should notice that the file has been modified and will download it to the client automatically.
Package name | Size (bytes) | Checksum | APAR # | PTF# |
---|---|---|---|---|
HMC_Recovery_V5R1.0_1.iso HMC_Recovery_V5R1.0_1.iso |
1510375424 1098940416 |
40076 12769 |
MB01197 | MH00407 |
Splash panel information displayed after installation | ||||
The Version is 5 The Release is 1.0 HMC Build level 20050926.1 |
Hints and Tips for the HMC Desktop
- To launch the browser, right click on the desktop to display the menu. Select "Net", and then "Browser".
- To start a restricted shell terminal, right click on the desktop to bring up the menu. Select Terminals", and then "rshterm".
- Currently, HMC only stores four (4) service processor dumps and four (4) platform system dumps per managed system.
- Changes of a partition profile do not apply immediately to the partition. The changes on the partition only take effect when activation is done through the profile.
- To view keylock positions and SRC values when performing Operator Panel Service Functions through Service Focal Point, use the Server and Partition plugin.
- To view system event logs, you must login as a user with the hmcpe role. From Service Applications, select Service Focal Point -> Service Utilities -> Actions -> View Problem Logs.
- Before using the HMC to upgrade your i5 or p5 Power5 server to the 01SF235_160_160 Firmware code level or greater, your HMC must be installed with the V5 R1.0 HMC code.
- If the HMC is set up as a DHCP server on a private network, do not use the chhmc, mksysconn or rmsysconn commands to make new or remove existing network connections. These commands should only be used if the HMC is on a public network with static IP assignments.
- If the HMC is used in a Cluster 1600 environment, see the following Redbooks Technote: Cluster 1600 and the Hardware Management Console
Enhancements and changes
The Ext3 File System has been enabled since HMC Version 4 Release 3. If you wish to take advantage of journaled file system, you must install or upgrade your HMC using the Version 4 Release 3 or higher Recovery CDs.
Server and Partition - Server Management
HMC 5.1 enhancements for server management include:
- Support to configure Host Channel Adapter.
- Support to configure Virtual IO Server Shared Ethernet failover.
- Support for IO Server Enhancements for VIOS and RPA partitions.
- Secure remote ASM access.
- Support for Redundant FSP with dynamic failover function.
- Support for Enhanced Mange On/Off CoD.
- Support for Mobile CoD.
HMC Code Update
Provides Full Backup and Restore via Network.
LIC Code Update
Deferred Fixes. Deferred fixes have existed in the firmware fixpacks since HMC V4 R5, but the HMC ignored them. In HMC V5 R1.0, support has been added to display a message at the end of the code update to show that there are deferred fixes that have not been activated. The "system information" panel and the lslic command have also been enhanced to display the deferred fix level.
HMC Command Line
- The following commands have been added:
- asmmenu - launches the Advanced System Management (ASM) browser interface
- lsmediadev - lists the storage media devices on the HMC
- An option has been added to the getdump, lsdump, and startdump commands to allow those commands to be targeted to the secondary service processor.
- An option has been added to the lscod command to list Mobile Capacity on Demand (CoD) code generation information.
- The chhwres command has been enhanced so that a virtual slot number is no longer required to be specified when adding a virtual I/O adapter.
- The chsyscfg command has been enhanced to allow the power-on option to be set for a managed system.
- The chsysstate command has been enhanced so that you are no longer required to specify a partition profile when you activate a partition on a managed system that is in the manufacturing default configuration.
- The following commands have been enhanced to support Host Channel adapters (HCA): chsyscfg, lshwres, lssyscfg, and mksyscfg.
- The following commands have been enhanced to support virtual Ethernet trunk adapter priorities: chhwres, chsyscfg, lshwres, lssyscfg, and mksyscfg.
- The following commands have been enhanced to support the addition of the partition workload group ID attribute to partition profiles: chsyscfg, lssyscfg, and mksyscfg.
- The following commands have been enhanced to support service processor failover: chsyscfg, chsysstate, and lssyscfg.
Known Issues
Server and Partition
- Dynamic partition configuration for memory move can take a while. During that time, no other operation can be performed.
- After configuring your network setting, make sure to reboot your HMC. Otherwise, dynamic logical partitioning for AIX/Linux partitions may not work.
- Users cannot change virtual Opticonnect and HSL Opticonnect settings through the GUI without activating the changes through a partition profile. Users can change the settings dynamically through the command line interface.
Usage:
chhwres -m <managed system name> -r virtualio --rsubtype virtualopti -p <partition name> -o s -a virtual_opti_pool_id=[0|1]Usage:
chhwres -m <managed system name> -r virtualio -rsubtype hsl -p <partition name> -o s -a hsl_pool_id=[0|1] - Error messages for some Dynamic Logical Partitioning tasks give 'AIX' as the partition type even though it is actually a Linux partition.
- Unable to perform Dynamic Logical Partitioning virtual I/O remove operations if the partition does not have a current profile.
- The HMC will display the wrong device information since the feature code 2849 is used for two different adapters :
OS/400 p Linux p AIX PCI 100/10Mbps Ethernet IOA 2849 n/a n/a PCI 2D Graphics Accelerator n/a 2849 2849
- Dynamic partition "add" of 5250 CPW cannot be done via the GUI when the partition processor and processing units reach maximum limit. You can dynamically add 5250 processors through the command line interface.
Usage:
chhwres -m <managed system name> -r proc -p <partition name> -o a -5250cpwpercent <percentage> - After an FSP is replaced in a Power5 server, i5/OS partitions do not IPL properly, and get B2xx 3110 SRC and B2xx 3200 SCR's because the IPL Source on the partition is changed to D. On the HMC go to the Partition Properties Panel and select the Setting tab. Change the IPL Source value, and then re-IPL the partition.
- Managed System can go to the incomplete state if the Host Channel Adapter is failing. Replace the adapter or remove it to recover from this state.
Only a visual inspection of the slot on the machine will be able to determine if the adapter is an Ethernet card or a Graphics card. Once the partition is activated with the adapter in the profile, the description should display the correct adapter information.
Service Applications
- To recover from the error message "Invalid user id or password" when you launch ASM on a p575 managed system from an HMC remote client using an invalid user id or password: Close the current browser session, and then relaunch the ASM menu with the correct user id and password.
- You can only perform Enclosure indicator tasks via ASM by launching the ASM Menus from the local HMC console.
Diskette Drive for 7310-CR3 HMC (x336)
The 7310-CR3 does not come with a diskette drive. If you want to configure the HMC as a Certificate of Authority Server, and then copy the public key signed by the server to diskette, you can contact IBM to order the USB diskette drive that can be used with the 7310-CR3.
LIC Code Update
- If the HMC remote client loses its connection while it is downloading firmware, the download fails. Retrying the operation "Change internal Code" might fail again with the message "Object is busy, and the task cannot handle busy objects". Reboot the HMC and retry the "Change internal Code" operation.
- To recover from the error message "ACT01724 The operation failed due to an internal code failure": Verify that the state of the managed systems and frames is connected by using the lssysconn -r all command at the command line. Retry the operation.
- When LIC Code Update is in progress, the Frame state changes from standby/standby to standby/unavailable. This change may happen if a power dump is in progress, and then the code update operation fails. Wait for the Frame state to change back to standby/standby, and then retry the operation.
- To recover when the error message "HSCF0052W Frame tttt-mmm*sssssss is locked by another process" is shown when you perform the Licensed Internal Code Update operation on the p5 595, i5 595, p5 590 and p5 575 managed systems:
- Verify that no other frame operation that uses the following locks:
Repair and Verify Operation
Initialize Frame Operation
Set Frame Number Operation
Licensed Internal Code Updateis in progress on a remote HMC or a dual HMC.
- Next, issue the rmlock command to force the release of the HMC lock on a managed frame.
Usage:
rmlock -e <frame name>
- Verify that no other frame operation that uses the following locks:
- To simultaneously update Licensed Internal code on multiple Managed Systems in a p575 within the same power frame, follow these steps:
- Select one Managed System in each frame from the "Target Option Selection" panel. This action updates the Licensed Internal Code on the Power Subsystem and the selected Managed System.
- Select the remaining Managed Systems in all frames from the "Target Option Selection" panel. This action updates Licensed Internal Code on the remaining managed systems. The Power Subsystem was already updated in Step 1 and will not be updated again.
Note: After the Licensed Internal Code has been updated in Step 1, the image is saved on the HMC. The "disk" repository can then be used for subsequent updates in Step 2.
National Language Support
- Mnemonics are not supported in double-byte and ru locales
- The HMC uses several external components. These components are not developed by the HMC team and are translated as part of a separate translation plan and schedule. The mix of English and translated text is an unavoidable situation and has the potential to occur anytime the HMC is updated or pulls in a new version of an external application that is updated in between normally scheduled translation cycles.
- Due to the limitations of groff, some characters in the output of "man" command might be corrupted in traditional Chinese, simplified Chinese and Korean when the window is too narrow. Widen the window and retry the command.
- Korean input is not supported. Press Shift-Space to switch between English and Korean input mode.
- Traditional and Simplified Chinese input is supported in zh_TW and zh_CN locales. Press CTRL-Space to switch between English and Chinese input mode. Press CTRL-Shift to select an input method. Press space bar to see more Chinese characters.
- Japanese input is supported. Press Shift-Space to switch between English and Japanese input mode.
- User ID, User information, HMC User password, Partition name, managed system name, profile name and system profile name are in English only.
- IBM275 doesn't work well when connecting from IBM Personal Communications or iSeries Access to an HMC. Use another Brazil codepage. The codepage "IBM930 Japan Katakana" doesn't work well either. Use "IBM930 Japan Katakana Extended" instead.
- If the browser on the HMC is used to view Japanese PDF files, Japanese text will not be displayed correctly in the bookmark page. Only English PDF files can be viewed on the HMC, even when the language is set to ja_JP.
- An ibm5250 session opened on the HMC locally will be in the same locale as the one that is set for the HMC. To open a session in a different locale, change the HMC locale first, logout, login, and then invoke ibm5250. The other option is to connect to the HMC using a remote emulator, for example, IBM Personal Communications or iSeries Access, in the desired locale.
- To access the remote_client.html file on the HMC from a remote web browser, please set the HMC locale to one of the following: cs_CZ (Czech), de_DE (German), en_US (English), es_ES (Spanish), fr_FR (French), hu_HU (Hungarian), it_IT (Italian), ja_JP (Japanese), ko_KR (Korean), nl_NL (Dutch), pt_BR (Brazilian Portuguese), ru_RU (Russian), sk_SK (Slovak), zh_CN (Simplified Chinese) or zh_TW (Traditional Chinese).
Note: For any locale that is not supported in the V4 R2 HMC, the numeric, date, time, calendar and currency formats that are specific to a given locale may not be displayed as expected.
Languages | Supported or Not Supported | Locales |
---|---|---|
English | Supported | en_US, en_GB, en_GB@euro, en_AU, en_BE, en_BE@preeuro, en_CA, en_HK, en_Ne, en_IE, en_IE@preeuro, en_NZ, en_PH, en_PK, en_ZA, en_SG |
German | Supported | de_DE, de_DE@preeuro, de_CH, de_AT, de_AT@preeuro, de_LU, de_LU@euro |
French | Supported | fr_FR, fr_FR@preeuro, fr_CH, fr_CA, fr_BE, fr_BE@euro, fr_LU, fr_LU@euro |
Italian | Supported | it_IT, it_IT@preeuro, it_CH |
Spanish | Supported | es_ES, es_ES@preeuro, es_AR, es_BO, es_CL, es_CO, es_CR, es_DO, es_EC,es_SV, es_GT, es_HN, es_MX, es_NI, es_PA, es_PY,es_PE, es_PR, es_US, es_UY,es_VE |
Brazilian Portuguese | Supported | pt_BR |
Japanese | Supported | ja_JP |
Simplified Chinese | Supported | zh_CN, zh_SG |
Traditional Chinese | Supported | zh_TW, zh_HK |
Korean | Supported | ko_KR |
Hungarian | Supported | hu_HU |
Dutch | Supported | nl_NL, nl_NL@preeuro, nl_BE, nl_BE@preeuro |
Russian | Supported | ru_RU |
Czech | Supported | cs_CZ |
Slovakian | Supported | sk_SK |
Miscellaneous Functions
- Help Search is not supported. Help Find is supported.
- Printing is not supported.
- The numerical keypad on some keyboards doesn't work. Use the normal numerical keys instead.
- When your Power5 system is shipped to you it is in a non-HMC managed mode by default. Once you attach
and set up an HMC to manage your Power5 system, the default non-HMC managed mode exits. The
procedure to return to the default non-HMC managed mode is documented on the InfoCenter website under "Resetting the server to a non-partitioned configuration". Use the following link to view the document.
http://publib.boulder.ibm.com/infocenter/eserver/v1r2s/en_US/info/iphbl/iphblresetserver.htm
Reference | Abstract |
---|---|
CVE-2004-0175 | OpenSSH SCP Client File Corruption Vulnerability |
CVE-2002-0839 CVE-2002-0840 CVE-2002-0843 |
Apache HTTPD Multiple Vulnerabilities |
CVE-2001-0572 | SSHv1 Protocol Available |
CAN-2003-0989 | tcpdump remote DOS |
CAN-2004-0078 | mutt remote buffer overflow |
CAN-2004-0110 | libxml2 URI Parsing Remote Buffer Overflow |
CAN-2004-0109 CAN-2004-0181 |
Linux kernel ISO9660/JFS local privilege escalation, info leak |
CAN-2004-0183 | tcpdump ISAKMP remote DOS |
CAN-2004-0427 CAN-2004-0424 CAN-2004-0229 CAN-2004-0228 CAN-2004-0394 |
Linux kernel privilege escalation, local DoS |
CAN-2004-0174 CAN-2003-0020 CAN-2003-0993 CAN-2003-0542 |
apache - multiple vulnerabilities |
CAN-2004-0554 | Linux kernel "__clear_fpu()" Macro local DoS |
CAN-2004-0523 | kerberos aname_to_localname remote root compromise |
CAN-2004-0492 | apache: remote overflow in mod_proxy |
CAN-2004-0460 CAN-2004-0461 VU#317350 VU#654390 |
dhcp-server: remote system compromise |
CVE-2002-1363 | libpng remote DoS |
CAN-2004-0590 | Certificate chain authentication in Openswan pluto |
CAN-2004-0649 | L2tpd: remote execution of arbitrary files w/ privs of l2tpd user |
VU#388984 VU#236656 VU#160448 VU#477512 VU#817368 VU#286464 CAN-2004-0597 CAN-2004-0598 CAN-2004-0599 |
libpng: multiple vulnerabilities |
CAN-2004-0415 | kernel: local privilege escalation, race condition in file offset pointer handling |
VU#550464 CAN-2004-0644 |
krb5: remote unauthenticated DoS |
CAN-2004-0817 | imlib: local execution via heap overflow |
CAN-2004-0687 CAN-2004-0688 |
xf86: multiple buffer overflows with malformed xpm images |
CAN-2004-0966 | gettext: Insecure temporary file handling |
CAN-2004-0804 CAN-2004-0886 |
tiff: Buffer overflows in image decoding |
CAN-2004-0884 | Cyrus-sasl2: (ver2.1.7)Insecure handling of environment variable |
CAN-2004-0971 | krb5: krb5-workstation: Possible symlink attack, priv escalation via temproary file mishandling |
CAN-2004-0989 | libxml: remote code execution, buffer overflow |
CAN-2004-0975 | Openssl: possible symlink attack via temp file mishandling |
CAN-2004-0940 | Apache: local buffer overflow in get_tag function in mod_include |
SUSE-SA:2004:041 | xf86: SuSE security updates for libxpm |
CAN-2004-0782 | mlib: SuSE xpm security updates in imlib |
CAN-2004-1010 | zip: buffer overflow in info-zip when using recursive folder compression |
CAN-2004-1308 | tiff: multiple buffer overflows |
CAN-2004-0986 | iptables: variable init failure can cause failure to load firewall rules |
CAN-2004-0883 CAN-2004-0949 CAN-2004-1070 CAN-2004-1071 CAN-2004-1072 CAN-2004-1073 CAN-2004-1074 |
kernel: SuSE update for multiple local and remote DoS vulnerabilities |
CAN-2005-0155 CAN-2004-0452 CAN-2005-0077 |
Perl: SuSE security update to address two priv escalation and a buffer overflow condition |
CAN-2005-0449 CAN-2005-0209 CAN-2005-0529 CAN-2005-0530 CAN-2005-0532 CAN-2005-0384 CAN-2005-0210 CAN-2005-0504 CAN-2004-0814 CAN-2004-1333 CAN-2005-0003 |
SuSE updates for multiple issues on 2.4-2.6.11 kernels |
CAN-2005-1993 | sudo: vulnerabilities allow execution of arbitrary commands |
CAN-2005-1267 CAN-2005-1278 CAN-2005-1279 CAN-2005-1280 |
tcpdump: fix for several DOS vulnerabilities |
CAN-2005-1151 CAN-2005-1152 CAN-2005-1349 CAN-2005-0103 CAN-2005-0104 CAN-2005-1455 CAN-2005-1454 CAN-2004-1456-CAN-2004-1470 |
tiff: buffer overflow allows execution of arbitrary code |
eServer i5 and p5 Education available on Resource Link
The following customer courses will be available from Resource Link for the Product Announce on May 4, 2004.
- How to Use the eServer i5 and p5 Hardware Management Console
This course explains how to install and configure the Hardware Management Console (HMC) for the Model 520/570. It also covers the HMC's basic operations by exploring the general user interface. Partitioning is discussed in detail, with explanations showing both command line and GUI support. - eServer i5 and p5 - Physical Planning for Installation
This course discusses considerations for the physical planning for installation of eServer Models 520 and 570. It then provides the user with links to obtaining the step-by-step installation procedures. - Resource Link Highlights
This course provides an overall look at the major Resource Link (RL) areas and how to use them. These areas are Planning, Education, Library, Forums, Fixes, Problem Solving, Services, Customer Initiated Upgrade, and Tools. It also provides step-by-step procedures in using the Subscription function. - Performing Licensed Internal Code Maintenance
This course discusses about maintaining the software that enables hardware such as the service processor on your eServer POWER5 system.
Access to these courses requires an IBM Registration ID and Resource Link Access.
To obtain an IBM Registration ID
- Go to http://www.ibm.com/servers/resourcelink
- Select "Register" under New users
- On the My IBM Registration, fill in an e-mail address for IBM ID and password, and the Security question and answer and the Country of residence and then click Continue and fill in the rest of the User information and click Submit.
Resource Link Access for New Users
- Go to http://www.ibm.com/servers/resourcelink
- Select "Sign in" enter the IBM ID and password you used to register above
- Select "Customer"
- Click "Submit" Once submitted it will take an hour before the access takes effect
To view a course
- Sign in to Resource Link
- Select Education in the navigation bar on the left
- From the Education page, select "eServer i5 and p5 courses"
- Select "How to Use the eServer i5 and p5 Hardware Management Console"
- Select "Performing Licensed Internal Code Maintenance"
- Double-click the link to open the course.
Notes:
- The courses are browser based. For optimal viewing, we recommend Microsoft Internet Explorer 6.0 or higher with your display set at 1024 x 768. To set your display, go to My Computer -> Display -> Settings
- Course pages can be book marked for easy retrieval.
- Course simulations open in a separate window. Use the X in the upper right corner of the window to close the simulation.
- If there are QuickTime videos in the course, you need to have the QuickTime viewer installed. A link to the free viewer is on each Resource Link course page and on the related page within each course.