Monday, October 22, 2018

Firepower 9000/4000 Cisco Bug CSCvm81014 or why cloud Licensing is great

BUG ID: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvm81014

Symptom:
Smart licensing may fail to register (as seen in chassis manager) indicating that there was a failure when trying to authenticate the server. Specifically the failure reason will state:

"Failed to authenticate server"

Conditions:
This is caused by a change in the CA certificate used to sign the certificates for some of Cisco's external sites, namely tools.cisco.com. The root CA was changed to be "QuoVadis Root CA 2".

Workaround:
In order to restore Smart Licensing functionality, you must manually import the root CA into the chassis' trust store. This can be done from the CLI

Status:
Fixed

Severity:
1 Catastrophic

This is a really fun bug and makes me do love cloud inventory/license management even more!

It is also nice, that cisco did not publish a Field Notice for this and nothing on the appliance or in the smart license Manager told me that there is a failure.

The only thing that got me on this is, is a tiny little syslog message,

%CALLHOME-2-EVENT: SAM_SLA_NORMAL

Now tell me that message indicates something that represents a Severity 1 Bug. It looks like one of the many retarded error Messages that Cisco started to push with NXOS, that are pure cosmetical.

The icing on the cake, is that the fixed version is not even available for download but atleast importing the certificate fixes it for now.



No comments:

Post a Comment