Sun Microsystems, Inc.  Oracle System Handbook - ISO 7.0 May 2018 Internal/Partner Edition
   Home | Current Systems | Former STK Products | EOL Systems | Components | General Info | Search | Feedback

Asset ID: 1-72-2054991.1
Update Date:2018-05-30
Keywords:

Solution Type  Problem Resolution Sure

Solution  2054991.1 :   Oracle ZFS Storage Appliance: Critical Security bug fixes for ZFSSA BIOS/ILOM (October 2015)  


Related Items
  • Sun ZFS Storage 7420
  •  
  • Sun Storage 7110 Unified Storage System
  •  
  • Oracle ZFS Storage ZS3-2
  •  
  • Sun Storage 7210 Unified Storage System
  •  
  • Oracle ZFS Storage ZS4-4
  •  
  • Sun Storage 7410 Unified Storage System
  •  
  • Oracle ZFS Storage ZS3-4
  •  
  • Sun ZFS Storage 7120
  •  
  • Sun Storage 7310 Unified Storage System
  •  
  • Sun ZFS Storage 7320
  •  
  • Oracle ZFS Storage ZS3-BA
  •  
Related Categories
  • PLA-Support>Sun Systems>DISK>ZFS Storage>SN-DK: 7xxx NAS
  •  




In this Document
Symptoms
Cause
Solution
References


Applies to:

Sun ZFS Storage 7420 - Version All Versions and later
Sun Storage 7110 Unified Storage System - Version All Versions and later
Sun Storage 7210 Unified Storage System - Version All Versions and later
Oracle ZFS Storage ZS3-4 - Version All Versions and later
Oracle ZFS Storage ZS4-4 - Version All Versions and later
7000 Appliance OS (Fishworks)

Symptoms

Critical Security bug fixes for the Oracle ZFS Storage Appliance platforms are now available (October 2015).

The bug fixes take the form of BIOS/ILOM upgrade patches.

 

IMPORTANT NOTE: This document is OBSOLETED by Doc ID 2351298.1 (Oracle ZFS Storage Appliance: Critical Security bug fixes for ZFSSA BIOS/ILOM (October 2017))

 

Cause

Oracle ZFS Storage Appliance platform BIOS/ILOM security bug fixes.

 

Solution

Please upgrade to the latest available BIOS/ILOM version for the specific platform.

Main Bug IDs: 20981644, 20924911, 20924788, 20695314

X3-2/ZS3-ES Specific Bug IDs (Platform-specific duplicates of above Main Bug IDs): 21111281, 21111282, 21111394, 20709512

PLEASE NOTE:  If it is determined that the BIOS/ILOM version needs to be upgraded this MUST be done through Oracle support - Open a Service Request for assistance, OR via an Oracle Certified Partner.

 

NOTE: To determine the 'currently running' BIOS/ILOM version, and/or to discover the latest available BIOS/ILOM versions, please see Doc Id 1174698.1 - How to check the SP BIOS revision level.

 

IMPORTANT NOTE: Latest 'Critical Security bug fixes' are available in Doc ID 2351298.1 - Oracle ZFS Storage Appliance: Critical Security bug fixes for ZFSSA BIOS/ILOM (October 2017)

 

7x10 component firmware

NOTE: There are NO plans to upgrade the 7x10 Appliance BIOS/ILOM firmware

 

 

7x20 component firmware

Sun Storage 7120/7320 (Lynx+)

SW1.7.5-RC7     ILOM 3.1.2.20.g r101361, BIOS 08.14.01.09

SW1.7.5-RC7     ILOM 3.1.2.20.g r101361, BIOS 08.14.01.09           patchId  21745718

Reference: MOS Doc ID 1357409.1 - Sun ZFS Storage Appliance: How to update the BIOS for a 7x20 NAS appliance

*See Note 1 below

 

Sun Storage 7420 (Callisto)

SW 1.6-RC2.0    ILOM 3.0.16.30 r 99823,  BIOS 09.05.02.01

SW 1.6-RC2.0    ILOM 3.0.16.30 r 99823,  BIOS 09.05.02.01          patchId  21666798

Reference: MOS Doc ID 1357409.1 - Sun ZFS Storage Appliance: How to update the BIOS for a 7x20 NAS appliance

*See Note 1 below

 

Sun Storage 7420 M2 (Callisto +)

SW1.5-RC5        ILOM 3.1.2.50 r99826,   BIOS 16.04.02.00

SW1.5-RC5        ILOM 3.1.2.50 r99826,   BIOS 16.04.02.00             patchId  21666801

Reference: MOS Doc ID 1357409.1 - Sun ZFS Storage Appliance: How to update the BIOS for a 7x20 NAS appliance

*See Note 1 below

 

 

ZS3-x component firmware

ZS3-2 (Netra X3-2 Server /Sun Netra X4270 M3 Server Concord)

SW1.2           ILOM 3.2.4.58 r101476,    BIOS 21.00.02.25

However, SW1.2 is affected by Bug 22708060 (Head is hung in BIOS init after a takeover was issued on the head)

The impact to the customer is not very high. This hang is only seen during the boot process. If you are not booting, you will not hit this issue - and if you are booting, even if you need to reboot, it will be okay.

SW1.2 is the latest recommended firmware until SW 1.3 is released.

However if you are concerned above the above bug, you have the option of going back to SW 1.1.0  (See Doc ID 1174698.1).

SW1.2           ILOM 3.2.4.58 r101476,    BIOS 21.00.02.25            patchId 21690637

Reference:  Check/Configure BIOS Settings - https://stbeehive.oracle.com/teamcollab/wiki/ZFSSAFieldSupport:ZS3-2+Motherboard+Replacement

 

ZS3-4/ZS3-BA (Sun Server X2-4 / Sun Fire X4470 M2 Callisto+)

SW1.5-RC5    ILOM 3.1.2.50 r99826,   BIOS 16.04.02.00

SW1.5-RC5    ILOM 3.1.2.50 r99826,   BIOS 16.04.02.00           patchId  21666801

Reference:  Check/Configure BIOS Settings - https://stbeehive.oracle.com/teamcollab/wiki/ZFSSAFieldSupport:ZS3-4+Motherboard+Replacement

*See Note 1 below

 

ZS3-ES (Sun Server X3-2 / Sun Fire X4170 M3 Nashua)

SW1.4.1          ILOM 3.2.4.26.a r99980, BIOS 17.11.05.00

SW1.4.1          ILOM 3.2.4.26.a r99980, BIOS 17.11.05.00          patchId  21198510

Reference:  Check/Configure BIOS Settings - https://stbeehive.oracle.com/content/dav/st/ZFSSAFieldSupport/Public%20Documents/PDF_Files/ZS3-ES_MB_Replacement_Procedure.pdf

 

 

ZS4-x component firmware

ZS4-4 (Sun Server X4-4 Callisto)

SW1.2.1-RC2_1   ILOM 3.2.4.38.a r102621, BIOS 24.04.05.00

SW1.2.1-RC2_1   ILOM 3.2.4.38.a r102621, BIOS 24.04.05.00         patchId  21866651

Reference:  Check/Configure BIOS Settings - https://stbeehive.oracle.com/teamcollab/wiki/ZFSSAFieldSupport:ZS4-4+Motherboard+Replacement

 

 

Note 1:

The BIOS configuration values are not enforced for this new BIOS after PXE or AK Fishstick install.

These configurations preserves the ILOM config option but do not preserve the BIOS config option.

After the SW update, the BIOS configuration needs to be manually set as described in the "Configure BIOS" section of the corresponding platform motherboard replacement procedure.

 

 

 

***Checked for relevance on 30-MAY-2018***

References

http://docs.oracle.com/cd/E37444_01/pdf/E37451.pdf
http://iasecontent.disa.mil/stigs/pdf/SecurityReport-ILOM-v1.3.pdf
http://docs.oracle.com/cd/E24707_01/pdf/E24526.pdf
<NOTE:2177437.1> - Oracle ZFS Storage Appliance: Critical Security bug fixes for ZFSSA BIOS/ILOM (April 2016)

Attachments
This solution has no attachment
  Copyright © 2018 Oracle, Inc.  All rights reserved.
 Feedback