Sun StorEdge Enterprise Storage Manager Base Applications, Release 4.0, Pre-installed Release Notes

This document contains important information about the Sun StorEdge Enterprise Storage Manager (ESM) Base Applications software, Release 4.0, Pre-installed, including information that was not available at the time the product documentation was published. Read this document so that you are aware of issues or requirements that can affect the installation and operation of the Sun StorEdge ESM Base Applications software.


Features in This Release

The Sun StorEdge ESM Base Applications 4.0, which include the Sun StorEdge Management Portal, are pre-installed on a V210 Sun Fire server. The system boots up in the same manner as a system returning from a sys-unconfig (1M) state. After you configure the system through the Solaris command-line interface (CLI), you log in to a Telnet session to run an ESM Base Applications configuration script. Once you provide licensing and network information, configuration of the ESM Base Applications and any other required software proceeds in a non-interactive manner. Periodically, the configuration process provides progress updates and estimates of time remaining.

The product includes a DVD to allow you to recover the ESM Base Applications and reset them to their default state.

The ESM Base Applications are managed as a pre-installed Solaris host, not as an appliance. The ESM Base Applications and the operating system (including required and installed infrastructure software) are maintained and serviced through Solaris commands.

The ESM Base Applications Release 4.0, Pre-installed, includes the following components:

Sun StorEdge Management Portal 1.0 and Sun StorEdge Data Replication Manager 1.0 are new products, available only as part of the ESM Base Applications 4.0 software package; StorADE 2.4 and SANbox Manager 2.1 are existing products that are also available for download from http://www.sun.com.

When you install the ESM Base Applications, dependent packages from Sun Java Enterprise System (Java ES) 2005Q1 are automatically installed on the system. For more information on Java ES, go to the following URL:

http://www.sun.com/software/javaenterprisesystem/


Installing Packages and Patches

This section describes downloading and installing required patches.

ESM Base Applications Patch Maintenance

Apply the latest Solaris operating system patches before installing any ESM Base Applications. These patches are available as Recommended Patch Clusters that you can download from the following patch link:

http://sunsolve.sun.com

Keep the Storage Automated Diagnostic Environment patches (117650-xx and 117654-xx), the Management Portal patch (120594-XX), and the Data Replication Manager patch (120404-xx) on your system current. Furthermore, review the patch Readme notes before installing them.

Follow the instructions in this section for downloading and installing the necessary packages and patches.



Note - You must install the packages before you install new patches.




procedure icon  To Download and Install Patches

1. Access SunSolve at http://sunsolve.sun.com.

2. Under SunSolve Path Contents, click Patch Portal.

3. For each patch that you want to install, follow these steps:

a. Under PatchFinder, type the patch you want, and click Find Patch.

PatchFinder automatically finds the latest version of the specified patch.

b. Verify that the returned patch is the one you want, and click Download Patch.

c. Follow the instructions in the patch README file to install the patch.


Known Issues

This section describes known issues that can affect the configuration, operation, and troubleshooting of the applications and devices that you are managing with the portal.

Management Portal

Slowness of Initial Pages

Bug 6273375 - The first time you launch a Management Portal page it loads slowly. Subsequent launches of that page go much more quickly.

Online Help Timeouts

Bug 6300203 - The online help does not handle session timeouts properly.

Workaround - Return to the Management Portal home page using the browser URL.

Duplicate IP Addresses

Bug 6302254 - Duplicate IP address ranges or subsets of address ranges already defined are allowed but discouraged. Specifying duplicate ranges may cause increased discovery times.

Workaround - Do not enter duplicate IP addresses.

Portlet Help Link and Browser Language Setting

Bug 6313215 - If your web browser's language is not set to English, portlet help ("?") buttons do not open help windows; the message Not Found is displayed.

Workaround - Set the browser language to English.

Only One Active IP Discovery Range at a Time

Bug 6310614 - If discovery of an IP address or range of addresses is in progress, subsequent IP address range requests will not be handled until the next polling interval, which by default is set at 60 minutes.

Workaround - If you do not see the requested IP ranges in the Event Organizer portlet, start a discovery collection cycle by performing the following steps:

1. Click Administration > Configure Information Source Polling Intervals > Device Discovery.

2. Click the Refresh check box, and click OK.

Looping of Redirecting URLs

Bug 6292909 - When attempting to log in to the Management Portal, you might get into an infinite loop of redirecting URLs.

Mozilla browsers (Netscape and Firefox) display a dialog box stating "URL redirection limit exceeded." Internet Explorer browsers simply loop without displaying an error message.

Workaround - Make sure that portal URL contains the fully qualified domain name of the server on which portal resides. For example:

Under some login circumstances, you might be redirected to the Logout page instead of the Management Portal home page.

Workaround - Make sure that the address of the login page specifies the correct or no goto directive. For example:

http://portal.example.sun.com/amserver/UI/Login?goto=http%3A%2F%2Fportal.example.sun.com%3A80%2Fportal%2Fdt

Display of RSS Configuration Changes

Bug 6296397 - When you add feeds to or remove feeds from the RSS reader edit page, it takes approximately 10 minutes for the changes to be displayed. This applies to both personal feeds and global feeds.

Workaround - To view RSS reader configuration changes immediately, exit the portal and log in again.

Display of New News and Information Feed Titles

Bug 6309242 - When you add a news and information source feed, it takes approximately 10 minutes for the title of the source feed to be displayed in the Administration portlet.

Workaround - Log back in or wait about 10 minutes.

Volume Performance Reporter Pareto Chart and Internet Explorer

Bug 6306377 - When you are using Internet Explorer, clicking items in the Volume Performance Reporter Pareto chart does not display further details.

Workaround - To see additional information about items, use another browser.

Display of Sun StorEdge 6920 Pool Information

Bug 6306011 - When you add Sun StorEdge 6920 Pool information, the information may not appear in the Information Sources table for several minutes.

Deletion of Nonexistent Users

Bug 6305829 - The delEsmUser command incorrectly allows you to delete a user that does not exist.

Creation of Existing Users

Bug 6305827 - The AddEsmUser command incorrectly allows you to create a user that already exists.

No Error Message With Invalid Source

Bug 6282491 - When configuring a new information source, if you specify a host name that does not have access to the information source, no error message appears. Although the provider appears to have been added, the information source has not actually been configured.

Back Button in the Administration Tasks Portlet

Bug 6260998 - The Back button does not work in the Administration Tasks portlet. For example, if you select Configure Information Sources and then click the Back button to return to the Administration Tasks portlet, the system redisplays the Configure Information Sources page.

Workaround - To return to the Administration Tasks portlet, click the link to Configuration Tasks or the Back to Configuration Tasks button.

Internal Communication Failures Due to Portal Misconfiguration of the Proxy Server

Bug 6314091 - Portal misconfiguration of the proxy server causes internal communication failures with Storage Automated Diagnostic Environment and other information sources.

Workaround - Configure a valid proxy server by doing the following:

1. Select Administration > Configure Proxy.

2. Enter a valid proxy host and port.

Display of Volume Performance Reporter Data

Bug 6313580 - The Volume Performance Reporter does not display data after running for an extended period of time, such as 36 hours or more.

Under normal operating conditions, one Cacao launcher process and one Java process running the Cacao container are started on the system. Occasionally, multiple Java processes are started. (You can see these processes by issuing the command ps -ef | grep cacao.) When this occurs, one or more of the portlets may no longer show data.

Workaround - To resolve the problem, issue the command ps -ef | grep cacao, and then issue the command kill -9 on the displayed launcher and Java processes associated with Cacao. Finally, issue the command init 6.

Layout Cancel Button

Bug 6323658 - From Home > Layout, when you select a radio button to choose the layout format, the change occurs imediately; you cannot cancel it using the Cancel button. The Cancel button cancels changes made to the order of the portlets, but not to the layout.

Static Feed Content Adjustments

Bug 6309846 - When you adjust static feed content, an installation with the restored database does not reflect changes.

Workaround - To have the database reflect changes:

1. From the Administration Tasks portlet, select Configure Information Sources.

2. Delete the static feed that was adjusted.

3. From the Operations menu, choose Add New RSS Feed.

4. Add the feed that you just deleted. Changes are now reflected.

As a result of this workaround, the previous static feed is no longer static. Rather, it is polled regularly, just like "live" feed. If the feed is adjusted again later, the changes will automatically be reflected.

Wrong File Name for Database Backups

Bug 6293063 - The database backup process chooses the wrong file name for the most recent backup.

Workaround - Do not add, delete, or modify the contents of the database backup directory.

Incorrect Link for Configure Storage Pools Information Source

Bug 6311815 - The title of the online help page for the Details link for Configure Storage Pools Information Source is incorrect. The title should be Adding a Storage Pools Information Source.

restorefile Argument Does Not Work

Bug 6322252 - The restorefile argument does not restore the database because the dbrestore.sh command does not correctly process arguments that specify the backup to be used.

Workaround - Use the dbrestore.sh command without an argument to restore the database using the most recent backup.

Database Logging Function

Bug 6322786 - Database logging stops functioning.

Workaround - Restart the database.

Incorrect Message Appears After Deletion of Elements

Bug 6347449 - When all elements have been deleted, an erroneous message appears in the Storage Event Reporter portlet.

Workaround - The message should be "Use the Discover Storage Devices task in the Administration Portlet to discover more SAN elements (contact the StorEdge Management Portal administrator if you do not have permission to log in as administrator)."

Data Replication Manager

Modifying Set and Group Operations When in Scoreboarding Mode

Bug 6260064 - Attempting to modify set and group operation fails when the sets are not in scoreboarding mode.

Workaround - Before performing an operation, be sure to first suspend replication on sets and groups involved in the operation.

License Configuration With the Common Base Element Manager

Bug 6305762 - The license feature does not properly update the number of licenses when a license is configured through the Common Base Element Manager.

Workaround - This bug does not impact the Compliance fields in Data Replication Manager. To view the license count, use the Sun StorEdge 6920 Configuration Service software provided with the Sun StorEdge 6920 system.

Deletion of a Large Number of Replication Sets

Bug 6306527 - Selecting and deleting a large number of replication sets takes a long time, and the user interface appears to hang.

Workaround - Operate on as few sets as practical at a time. Doing this will not shorten the time it takes, but it will provide feedback on the progress of the operation.

Multiple Wizard Sessions

Bug 6307180 - Do not launch multiple wizard sessions. If you do, you get the following message when opening and subsequently closing the second wizard window:

Unrecoverable Wizard Error

Snapshot Operations From the Replication Set Summary Page

Bug 6307197 - If you use the Replication Set Summary page to run snapshot operations on a set that is in a consistency group, you get the following erroneous message:

Error - Replication set not found

Workaround - Perform snapshot operations on the consistency group, not on the member replication sets.

Removing Sets From a Group

Bug 6306601 - Removing sets from a group does not automatically refresh the sets table after completion.

Workaround - Use the Refresh button to refresh the sets table.

Removing a Set From a Consistency Group

Bug 6307819 - When you attempt to remove a set from a consistency group, the resulting action is unclear, because the Data Replication Manager is attempting to refresh its data cache.

Workaround - Refresh the window to see the results of the operation.

Refreshing the View After a Role Reversal

Bug 6307856 - If you refresh after a role reversal while adding a single device, you will receive an application error.

Workaround - Unregister the device with the set in question and re-register the device immediately. This will reconstruct data cache entries, which will eliminate the problem.

Data Replication Manager Alarms

Bug 6308274 - The Data Replication Manager Alarms action does not update some devices and can take a long time to update the view.

Workaround - Verify that Sun StorEdge 6920 system is accessible (for example, it has a valid user name and password, and a network connection). If it is expected to be unavailable for an extended period, unregister the device with Data Replication Manager and re-register it after it is available. Failing to unregister the device will prevent updates from happening in a timely fashion across all registered devices.

Neglecting to Add a Set to a Consistency Group

Bug 6308980 - If you do not select a set for Add Set to Group, and yet you click OK, you will get the following application error:

java.lang.ClassCastException

Workaround - When adding a set to a group, be sure to select a set before clicking the OK button. If you proceed and receive a java.lang.ClassCastException error, simply close the set selection window and restart the process from the Group Details page.

Restoring the Data Replication Manager Server

Bug 6309747 - After the Data Replication Manager server experiences a server crash, you might be unable to launch Data Replication Manager when the server comes back online.

Workaround - To restore the Data Replication Manager server after a server crash:

1. Restart the Solaris system on which the Data Replication Manager server resides.

Stop the Data Replication Server by executing the following command:

/opt/SUNWrrm/bin/drmserver stop

2. Go to the /var/opt/SUNWrrm/datastore directory and remove all files except the following:

rrmfostoredb.btd

3. Start the Data Replication Manager server by executing the following command:

/opt/SUNWrrm/bin/drmserver start

Role Reversal Registration Required on Both Sides

Bug 6309654 - You must register both the primary and secondary sides of a group replication set for role reversal to work.

Workaround - For a role reversal to succeed, both sides (primary and secondary) must be registered with Data Replication Manager. If both sides are not registered with Data Replication Manager and a role reversal must be performed, use the Sun StorEdge 6920 Configuration Service software supplied with your Sun StorEdge 6920 system.

Error Messages After Long-Running Operations

Bug 6311231 - The web browser automatically resubmits a request if the server fails to respond after two minutes. This generates error messages as the resubmitted request is reattempted by Data Replication Manager.

Workaround - Break multi-set operations into smaller operations.

Fast-Starting New Replication Sets

Bug 6311661 - Fast-start functionality is not operating properly through the Data Replication Manager.

Workaround - Use the Common Base Element Manager to fast-start new replication sets.

Removing a Set From a Consistency Group

Bug 6311678 - When you remove a set from a consistency group, an erroneous message might be generated.

Workaround - It is likely that the set was properly removed from the group but Data Replication Manager failed to update its data cache. Perform a refresh operation on the Group Details page to verify that the member sets are as expected. If the set is still reported as a member of the group, retry the operation.

Replicating Suspended Sets

Bug 6310411 - When the "Auto-synchronize" flag is checked, performing a replication action fails on sets that are suspended, and an error message is generated. If the Auto-synchronize feature is enabled, the set will begin replicating a short time after the set is created. Not being in Auto-synchronization mode puts the Data Replication Manager data cache out of sync with the state of the Sun StorEdge 6920 system.

Workaround - Examine the state of the sets to ensure they are Synchronizing or Replicating, and perform a refresh to validate the results, if necessary.

Deleting Multiple Sets From a Group

Bug 6309679 - You might experience intermittent problems attempting to delete multiple sets from a consistency group. Furthermore, there is no confirmation of success, and you might receive an application error message.

Workaround - Do not attempt to remove multiple sets in a single operation; instead, use multiple single-set operations.

Incorrect Message for Snapshot of a Set in Suspended Mode

Bug 6309138 - When issuing a snapshot operation against a replication set or consistency group that is in Suspended mode, be aware that the snapshot will apply only to the primary side. The snapshot operation command for the secondary side must travel across the replication link, which it cannot do if replication is Suspended.

Creating a New Consistency Group

Bug 6309123 - On sets being created in a new group, the Create Replication Set wizard does not verify that the selected consistency group name does not already exist until the last step in the wizard. If an existing group has the same name as the group being created, the set creation will fail.

Workaround - When creating a new consistency group as part of a new replication set, make sure that the chosen consistency group name does not already exist.

Simultaneously Adding Multiple Sets to a Group

Bug 6310571 - When you attempt to simultaneously add multiple sets to a consistency group, not all sets are added.

Workaround - Add each replication set individually.

Simultaneously Deleting Multiple Sets From a Group

Bug 6310566 - When you attempt to simultaneously delete multiple sets from a consistency group, the primary set is deleted; however, the secondary set may not be deleted, resulting in a partial set.

Workaround - Repeat the operation.

Simultaneously Deleting Multiple Sets From the Summary Page

Bug 6311056 - When you simultaneously delete multiple sets from the Replication Set Summary page, an invalid error message may appear.

Workaround - Delete each replication set individually.

Documentation

Management Portal Online Help

The following bug pertains to the Management Portal online help.

Incorrect Help References to Collection State and Refresh All Feeds

Bug 6311569 - The Management Portal online help for Information Source Polling Interval for the Storage News and Information portlet refers to two options that do not exist: Collection State and Refresh All Feeds.

Data Replication Manager Online Help

The following bug descriptions include amendments to the Data Replication Manager online help. This section replaces the existing sections in the help.

Creating Snapshots

Bug 6308995 - The procedure to create snapshots on a secondary volume is incorrect in the Data Replication Manager online help. The correct procedure follows:

This procedure describes creating a snapshot on the primary volume. From the Replication Set Details page or the Group Details page, do one of the following:

Select one of the snapshot options to automatically create snapshots of either volumes in replication sets or consistency groups during a synchronization operation (for additional details see About Replication Set Properties in the online help). You can also manually create a snapshot of the secondary volume in a replication set or consistency group. In all cases, you must first allocate adequate snapshot reserve space on the applicable Sun StorEdge 6920 storage system to enable the snapshot.

To manually create a snapshot of the secondary volume in a replication set or consistency group:

1. Click one of the following, depending on whether the secondary volume for which you are creating a snapshot is in a replication set or consistency group:

The Replication Sets Summary or Consistency Groups Summary page is displayed.

2. Select the check box for the replication set or consistency group for which you want to create the snapshot.

3. Select Snapshot from the Set Operations or Group Operations list.

Definition of Synchronizing Status

Bug 6312920 - The definition for Synchronizing (n%), which is one of the status options for the Synchronization Progress field, is incorrect. The definition should be as follows:

The Synchronization Progress field appears on the Consistency Groups Summary Page, the Replication Sets Details Page, and the Replication Sets Summary Page.


Enabling and Disabling HTTPS/SSL for the Portal Server

This section describes enabling and disabling the secure protocol HTTPS/SSL. To render your Management Portal secure, you should follow this procedure. You must have root access privileges to perform these tasks.

These instructions assume that you will use a shell editor to copy and paste information from this document to the command line or a script.



Note - Once you have enabled HTTPS, you cannot reinstall the product until you first disable HTTPS using the procedure cited in Disabling HTTPS.



Prerequisites to Enabling HTTPS

Please note the following information:



Note - The following copy-and-paste syntax assumes you are using the Korn shell (KSH) in a terminal window.




/bin/ksh
DEPLOY_INSTANCE=`grep DEPLOY_INSTANCE=
/etc/opt/SUNWps/PSConfig.properties | sed -e "s/DEPLOY_INSTANCE=//"`
typeset -l HOST_DOMAIN=`echo $DEPLOY_INSTANCE`
TMPFILE=/tmp/$$

Enabling HTTPS

To change the default server list entry from HTTP to HTTPS, use the following procedure. You must follow the steps exactly as instructed.



caution icon

Caution - Once the first step has been performed, you must not stop the portal servers until after all of the steps have been completed.



Substitute $DEPLOY-INSTANCE with the actual value of echo $DEPLOY-INSTANCE.

1. To use the amconsole browser interface (http://$DEPLOY-INSTANCE/amconsole) to change the Server List in the Management Portal from HTTP to HTTPS:

a. Log in to amconsole as amAdmin.

The typical password used is adminadmin, but yours might be different.

b. Click the Service Configuration tab.

c. In the left pane, scroll down and select Platform; click the arrow to the right of the word Platform.

d. In the right pane, select the server in the Server List.

e. Click the Remove button.

f. Change http to https in the server URL listed below the Server list; leave the port number as 80|01.

g. Click the Add button.

List one server entry only.

h. Click the Save button at the top or bottom of the page.

2. To create the SSL certificate for the web server:

a. Copy and paste the following boxed text to create the certificate database.

You are prompted to enter a password to encrypt the keys. Be sure to write this password down so you can supply it when prompted in the following steps.


/opt/SUNWwbsvr/bin/https/admin/bin/certutil -N -d /opt/SUNWwbsvr/alias 

b. Copy and paste the following boxed text to remove any preexisting or old certificates.


/opt/SUNWwbsvr/bin/https/admin/bin/certutil -D -d /opt/SUNWwbsvr/alias -n $HOST-DOMAIN 



Note - If no certificates are found, you will get an error message declaring "bad database." This is normal, and you should proceed.



c. Copy and paste the following boxed text to create your instance certificate database.



Note - Do not omit the "-" at the end of the -P argument string.




/opt/SUNWwbsvr/bin/https/admin/bin/certutil -N -d /opt/SUNWwbsvr/alias -P "https-$HOST-DOMAIN -"

d. Copy and paste the following boxed text to create your instance certificate password file.


echo "password" >/opt/SUNWwbsvr/https-$DEPLOY-INSTANCE/config/.ctpass
 
chown -R webservd:webservd /opt/SUNWwbsvr/https-$DEPLOY-INSTANCE/config/.ctpass

e. Copy and paste the following boxed text to create your instance certificate and insert it into the database.


/opt/SUNWwbsvr/bin/https/admin/bin/certutil -S -k rsa -s "CN=$HOST-DOMAIN" -n $HOST-DOMAIN -x -t "C,C,C" -m $$ -v 24 -f /opt/SUNWwbsvr/https-$DEPLOY-INSTANCE/config/.ctpass -d  /opt/SUNWwbsvr/alias -z /usr/bin/ls 

f. Copy and paste the following boxed text to verify your instance certificate is in the database.


/opt/SUNWwbsvr/bin/https/admin/bin/certutil -L -d /opt/SUNWwbsvr/alias

You should see output similar to the following:

$HOST-DOMAIN Cu,Cu,Cu

g. Copy and paste the following boxed text to back up Java Virtual Machine (Java VM) certificates for the Java VM used by Java Enterprise Systems (Java ES) (your location may vary).


cp /usr/jdk/entsys-j2se/jre/lib/security/cacerts /usr/jdk/entsys-j2se/jre/lib/security/cacerts.backup 

h. Copy and paste the following boxed text to export the certificate.

For $TMPFILE, substitute the name of a temporary file to which you want to export the certificate. This file should prevent overwriting of an existing file.


/opt/SUNWwbsvr/bin/https/admin/bin/certutil -L -d /opt/SUNWwbsvr/alias -n $HOST-DOMAIN -a >$TMPFILE

i. If you are changing an existing HTTPS configuration, copy and paste the following boxed text to delete the certificate from the Java ES Java VM trust store.



Note - This next step does not apply the first time you configure HTTPS.




/usr/jdk/entsys-j2se/bin/keytool -delete -alias "$HOST-DOMAIN" -keystore /usr/jdk/entsys-j2se/jre/lib/security/cacerts -keypass changeit -v

j. Copy and paste the following boxed text to import the certificate into the Java ES Java VM trust store.

When prompted for the password, use the default key store password, changeit. $TMPFILE is the filename you exported the certificate to in step h.


/usr/jdk/entsys-j2se/bin/keytool -import -alias "$HOST-DOMAIN" -file $TMPFILE -trustcacerts -keystore /usr/jdk/entsys-j2se/jre/lib/security/cacerts -keypass changeit -v

When prompted to trust the certificate, type yes.

If you see the following error message, either your key store password has been changed or you will need to remove the cacerts file and attempt to import the certificate again:

keytool error: java.io.IOException: Keystore was tampered with, or password was incorrect

Use the following command if you need to remove the cacerts file:


rm /usr/jdk/entsys-j2se/jre/lib/security/cacerts

3. In /etc/opt/SUNWps/PSConfig.properties, change all references from http to https in the following property keys:

LOAD_BALANCER_URL

PS_PROTOCOL

4. In /etc/opt/SUNWam/config/AMConfig.properties, change all references from http to https except for the following:

com.iplanet.am.admin.cli.certdb.prefix=

5. In /opt/SUNWwbsvr/https-$DEPLOY-INSTANCE/config/magnus.conf, change Security off to Security on.

Make sure there are no trailing spaces after changing off to on.

6. Make the following changes to /opt/SUNWwbsvr/https-$DEPLOY-INSTANCE/config/server.xml:

a. Change the <LS> entry to read as follows:


<LS id="ls1" port="80" servername="$DEPLOY-INSTANCE" defaultvs="https-$DEPLOY-INSTANCE" ip="any" security="false" acceptorthreads="1" blocking="false"/>

b. Change the <LS> tag so that the value of security= is "true"; the tag must be altered to contain additional body content and a closing tag. Be sure to remove carriage returns <CR> when adding the <LS> tag.


<LS id="ls1" port="80" servername="$DEPLOY-INSTANCE" defaultvs="https-$DEPLOY-INSTANCE" ip="any" security="true" acceptorthreads="1" blocking="false">
            <SSLPARAMS servercertnickname="$HOST-DOMAIN" ssl2="off" ssl2ciphers="-rc4,-rc 4export,-rc2,-rc2export,-desede3,-des" ssl3="on" tls="on" ssl3tlsciphers="-rsa_rc4_128_sha,+rsa_rc4_128_md5,-rsa_rc4_56_sha,-rsa_rc4_40_md5,+rsa_3des_sha,+rsa_des_sha,-rsa_des_56_sha,-rsa_rc2_40_md5,-rsa_null_md5,-fortezza,-fortezza_rc4_128_sha,-fortezza_null,+fips_3des_sha,-fips_des_sha" tlsrollback="on" clientauth="off"/>
        </LS> 

c. Add a second <LS> tag to use the default secure port 443. The first <LS> tag has an id value of ls1; the second <LS> tag has an id value of ls2.


 <LS id="ls2" port="443" servername="$DEPLOY-INSTANCE" defaultvs="https-$DEPLOY-INSTANCE" ip="any" security="true" acceptorthreads="1" blocking="false">
            <SSLPARAMS servercertnickname="$HOST-DOMAIN" ssl2="off" ssl2ciphers="-rc4,-rc 4export,-rc2,-rc2export,-desede3,-des" ssl3="on" tls="on" ssl3tlsciphers="-rsa_rc4_128_sha,+rsa_rc4_128_md5,-rsa_rc4_56_sha,-rsa_rc4_40_md5,+rsa_3des_sha,+rsa_des_sha,-rsa_des_56_sha,-rsa_rc2_40_md5,-rsa_null_md5,-fortezza,-fortezza_rc4_128_sha,-fortezza_null,+fips_3des_sha,-fips_des_sha" tlsrollback="on" clientauth="off"/>
        </LS>

7. To create a web server password file and thereby avoid prompting when the web server starts, enter the commands as they appear below.



Note - After creating password.conf, you should change the permissions so that only the web server user can access it (webservd).




 echo "internal: password" >/opt/SUNWwbsvr/https-$DEPLOY-INSTANCE/config/password.conf
    chown -R webservd:webservd /opt/SUNWwbsvr/https-$DEPLOY-INSTANCE//config/password.conf 

8. Stop and restart the Management Portal web server:


/opt/SUNWwbsvr/https-$DEPLOY-INSTANCE/stop 
/opt/SUNWwbsvr/https-$DEPLOY-INSTANCE/start

The Management Portal web server should start up in secure mode. If the web server reports any errors, resolve them and attempt to start the web server again. For verification, log in to the secure portal as user seadmin https://$DEPLOY-INSTANCE/portal/dt.

Disabling HTTPS

All of the step numbers in this procedure refer to the steps in Enabling HTTPS.

1. Undo the change from HTTP to HTTPS in Step 1.

2. Undo the changes from Step 3, Step 4, and Step 5.

3. Change security=true in server.xml to security=false for ports 80 and 443.

4. Restart the web servers, as described in Step 8.


Release Documentation

This section lists all documents in the information set.


Subject

Title

Part Number

Installation and configuration information

Sun StorEdge Enterprise Storage Manager Base Applications Getting Started Guide, Release 4.0, Pre-installed

819-4895-10

Late-breaking information not included in the information set

Sun StorEdge Enterprise Storage Manager Base Applications Release Notes, Release 4.0, Pre-installed

819-4896-10

Contents of the DVD

Sun StorEdge Enterprise Storage Manager Base Applications DVD, Release 4.0, Pre-installed

818-7749-10

Read Me First

Sun StorEdge Enterprise Storage Manager Base Applications Read Me First, Release 4.0, Pre-installed

819-4897-10


The Sun StorEdge ESM Base Applications software also includes online help.


Service Contact Information

If you need help installing or using this product, go to:

http://www.sun.com/service/contacting