Twitter Updates

    follow me on Twitter

    Sunday, July 12, 2015

    How to Upgrade Cisco MeetingPlace from version 8.4 to 8.6

    How to Upgrade Cisco MeetingPlace


    Now that MeetingPlace from Cisco is in a state of confusion due to its pending demise, it appears to be extremely hard to find information on how to upgrade it.  Conflicting information prevails and Cisco SE's can't even find information or even the Product Manager!

    Well, we did a successful upgrade today from 8.4 through multiple steps (so as to be careful since there is no clear information) and are finally at the current 8.6.2 SR1 version.  We were already virtualized and started with 8.2 initially so we are fortunate for that.  If you are upgrading from a physical version, you have a lot of reading to do...!  This may not help too much.

    Here are the several steps used to get there.  It isn't totally detailed as to all the exact steps for each different version increment but I think you'll get the picture.

    If you have questions or comments, please post them and I'll try to clear anything ambiguous up.

    First of all, here are some links to the high level documentation;


    MeetingPlace documentation Home

    To Search all MeetingPlace documentation use this link;



    Here are the TAC Recommended Upgrade Steps:

    *You will need to first get a backup as a precaution.
    *Upgrade the system to 8.5.5 . (Please follow the instructions according to your deployment if is multinode or failover)
    *Then upgrade to 8.6.1 (Please follow the instructions according to your deployment if is multinode or failover)
    *After this upgrade to 8.6.2. (Follow the same instructions)


    Snapshot Saturday evening


    Procedure:


    About Upgrading the Application Server Software
    • An upgrade keeps the database that holds the Hardware Media Server configuration information.
    • We support using Integrated Lights-Out (iLO) to install/upgrade the Application Server software. This standard only applies to the Cisco MCS 7845-H2. For information about installing, configuring, and using iLO, see http://h18000.www1.hp.com/products/servers/management/ilo/.
    • The upgrade program retains the same deployment that you currently have on your existing Cisco Unified MeetingPlace system.
    Preparing to Upgrade the Application Server Software

    Caution  Do not run any other processes or tasks on your systems during an upgrade.


    Note Be sure the Application Server node is in maintenance mode. Sign in to the Administration Center. Select Maintenance > Maintenance Configuration, then Start Maintenance Mode Now.

    • Do not uninstall the Application Server software before the upgrade.
    • The Cisco Unified MeetingPlace system must be running when you perform an upgrade. Do not turn off the Cisco Unified MeetingPlace services.
    • If you have automatic backups/archives enabled, then turn this off when you upgrade the Application Server software.
    • Make sure your system is functional before starting the upgrade (the Operational Status of each node is green)
    Determining Which Procedure to Follow
    Depending on the configuration of your Application Server, follow one of these steps:
    Upgrading the Application Server by Using the Console
    Before You Begin

    Note Be sure the Application Server node is in maintenance mode, or the upgrade program will terminate.

    Procedure

    Step 1 Go to Cisco.com and find the upgrade binary: http://www.cisco.com/cisco/software/navigator.html and select Products > Voice and Unified Communications > Unified Communications Applications > Conferencing > Cisco Unified MeetingPlace > Cisco Unified MeetingPlace 8.6 > Unified MeetingPlace Application Server. The naming convention will be similar to CUMP_AppServerUpgrade_< version >.bin, where < version> is the version number to which you are upgrading.
    Step 2 Save the file to a convenient location.
    Step 3 Enter md5sum CUMP_AppServerUpgrade_< version >.bin to determine the checksum of the file that you downloaded. Compare this value to the checksum value of the file that is posted on the download page on Cisco.com.
    Step 4 Sign in to the Application Server command-line interface as the root user.
    Step 5 Transfer the CUMP_AppServerUpgrade_< version >.bin file to the Application Server to the /tmp folder.
    We recommend saving the file to the /partB directory, as it has a lot of free space. (You can do this by using the mv command: mv /tmp/CUMP_AppServerUpgrade_.bin /partB.)
    Step 6 Enter sh./ CUMP_AppServerUpgrade_< version >.bin to execute the file.
    Q. How to become 'root'?
    • A. Login to SSH as mpxadmin, then change to 'root' user:
    $ su -
    NOTE: Enter 'root' password when prompted

    Q. How to change file permissions?
    • A. Use 'chmod' command. For the use with MP hotfixes '755' permissions are used:
    To change permissions of file.bin to '755', run: $ chmod 755 file.bin

    Q. How to move or copy a file?
    • A. Use 'mv' or 'cp' command:
    To move file.bin to mpx-record: $ mv file.bin /mpx-record


    • Backup MP File 8.5.2.8 which was the main upgrade at installation.  First installation was a 7.x version and then was upgraded to this version.
    The upgrade program checks to see if there are any previous versions of the Application Server software installed. If there is at least one previous version, the upgrade program displays a message listing the previous version found on the system.

    Note If the upgrade program does not find any previous versions of the Application Server software, the upgrade program displays an error message and you must quit the upgrade.

    Step 7 Select Enter after reading the Introduction.
    Step 8 Select Enter to confirm your existing system.
    Step 9 Select Enter to confirm the pre-installation summary.
    Values include the product name and the amount of disk space required and available for the installation target.
    Step 10 Select Enter to start the upgrade.
    The upgrade program upgrades all the required components associated with the Application Server software.
    The upgrade program displays a message stating that the upgrade is complete.
    Step 11 Select 1 to restart the system.
    Step 12 As required, upgrade the other Application Server nodes in your multinode system.
    Step 13 Synchronize the Hardware Media Server and meeting types.
    Step 14 Put the Audio Blade back online.



    ====================================================================================



     Upgrade Cisco MeetingPlace from 8.5.4.22 to 8.6MR2
    ----------------------------------------------


    Pre-upgrade task:

    1) MP back up of db and server                                 7/12 - morning before upgrade
    2) snapshot                                                                        7/11 Saturday night
    3) WebEx Cloud server integration details            7/10 - screenshot details
    4) turn off automatic backups/archive                    7/12 - morning, before upgrade
    5) check if the MP server is active, no alerts          

    Upgrade Tasks:  7/12 @ 9:00 am
    -------------

    Step I:

    a) upgrade MP from 8.5.4.22 to 8.5.5   --- done
    b) Apply latest path for 8.5.5 (8.5.5 SR10) (MP85MR3_PA9_Security_8552.bin.gz)

    c) WebEx cloud integration

    d) CUCM integration

    e)  MP config check (region etc)

    f)Testing

    ==================================================================

    Dependencies
    ============
    Initial 8.5.5.2 (8.5MR3FCS) installation required.
    Installation instructions
    =========================
    These are general installation instructions. For details about each step, please see http://docwiki.cisco.com/wiki/Cisco_Unified_MeetingPlace_-_Application_Server_hotfix_installation_FAQ
    All CLI commands should be executed as root.
    For multi-node deployments, apply the patch on all nodes in the following order:
        a. Leaf nodes first
        b. Secondary MBD
        c. Primary MBD
          
    1.  Copy the patch file to the MP Application server
    2.  Put the patch in /mpx-record and gunzip it.

    Q. How to gunzip the file?
    • A. Use 'gunzip' command:
    To gunzip file.bin.gz, run: $ gunzip file.bin.gz
    Extracted file will be 'file.bin'



    3.  Check cksum of gunzipped patch:
        If the the checksum value matches values above, you can proceed with running the patch
        If the checksum value doesn't match, the file is corrupted, please, contact Cisco TAC to get the file republished.
    4.  Set the appropriate (755) permissions on the extracted .bin file and run it.
    5.  Answer the confirm/continue prompts if any.
    6.  The patch installer will install the files.
    7.  Repeat the steps for the standby server (failover deployment), or other nodes (multi-node deployment).
    The patch can not be rolled back.


    ===============================================================================
    Upgrade Cisco MeetingPlace from 8.5.5 to 8.6.1

    Step II:

    a) upgrade MP from 8.5.5 to 8.6MR1
    b) Apply latest patch for 8.6.1 SR8 patch 9 (MP86_PA3_Security_8612.bin.gz)

    c) WebEx cloud integration

    d) CUCM integration

    e)  MP config check (region etc)

    f)Testing

    First Step:  upgrade MP from 8.5.5 to 8.6MR1
    Preparing to Upgrade the Application Server Software

    Caution  Do not run any other processes or tasks on your systems during an upgrade.


    Note Be sure the Application Server node is in maintenance mode. Sign in to the Administration Center. Select Maintenance > Maintenance Configuration, then Start Maintenance Mode Now.

    • Do not uninstall the Application Server software before the upgrade.
    • The Cisco Unified MeetingPlace system must be running when you perform an upgrade. Do not turn off the Cisco Unified MeetingPlace services.
    • If you have automatic backups/archives enabled, then turn this off when you upgrade the Application Server software.
    • Make sure your system is functional before starting the upgrade (the Operational Status of each node is green)
    Determining Which Procedure to Follow
    Depending on the configuration of your Application Server, follow one of these steps:
    Upgrading the Application Server by Using the Console
    Before You Begin

    Note Be sure the Application Server node is in maintenance mode, or the upgrade program will terminate.

    Procedure

    Step 1 Go to Cisco.com and find the upgrade binary: http://www.cisco.com/cisco/software/navigator.html and select Products > Voice and Unified Communications > Unified Communications Applications > Conferencing > Cisco Unified MeetingPlace > Cisco Unified MeetingPlace 8.6 > Unified MeetingPlace Application Server. The naming convention will be similar to CUMP_AppServerUpgrade_< version >.bin, where < version> is the version number to which you are upgrading.
    Step 2 Save the file to a convenient location.
    Step 3 Enter md5sum CUMP_AppServerUpgrade_< version >.bin to determine the checksum of the file that you downloaded. Compare this value to the checksum value of the file that is posted on the download page on Cisco.com.
    Step 4 Sign in to the Application Server command-line interface as the root user.
    Step 5 Transfer the CUMP_AppServerUpgrade_< version >.bin file to the Application Server to the /tmp folder.
    We recommend saving the file to the /partB directory, as it has a lot of free space. (You can do this by using the mv command: mv /tmp/CUMP_AppServerUpgrade_.bin /partB.)
    Step 6 Enter sh./ CUMP_AppServerUpgrade_< version >.bin to execute the file.
    The upgrade program checks to see if there are any previous versions of the Application Server software installed. If there is at least one previous version, the upgrade program displays a message listing the previous version found on the system.

    Note If the upgrade program does not find any previous versions of the Application Server software, the upgrade program displays an error message and you must quit the upgrade.

    Step 7 Select Enter after reading the Introduction.
    Step 8 Select Enter to confirm your existing system.
    Step 9 Select Enter to confirm the pre-installation summary.
    Values include the product name and the amount of disk space required and available for the installation target.
    Step 10 Select Enter to start the upgrade.
    The upgrade program upgrades all the required components associated with the Application Server software.
    The upgrade program displays a message stating that the upgrade is complete.
    Step 11 Select 1 to restart the system.
    Step 12 As required, upgrade the other Application Server nodes in your multinode system.
    Step 13 Synchronize the Hardware Media Server and meeting types.
    Step 14 Put the Audio Blade back online.




    Cisco MeetingPlace Patch to 8.6.1 Patch 9

    Dependencies
    ============
    Initial 8.6.1.2 (8.6FCS) installation required.
    Installation instructions
    =========================
    These are general installation instructions. For details about each step, please see http://docwiki.cisco.com/wiki/Cisco_Unified_MeetingPlace_-_Application_Server_hotfix_installation_FAQ
    All CLI commands should be executed as root.
    For multi-node deployments, apply the patch on all nodes in the following order:
        a. Leaf nodes first
        b. Secondary MBD
        c. Primary MBD

          
    1.  Login as mpxadmin.   Escalate to root privilege user and then Copy the patch file to the MP Application server
    2.  Put the patch in /mpx-record and gunzip it.
    3.  Check cksum of gunzipped patch:
        If the the checksum value matches values above, you can proceed with running the patch
        If the checksum value doesn't match, the file is corrupted, please, contact Cisco TAC to get the file republished.
    4.  Set the appropriate (755) permissions on the extracted .bin file and run it.
    Sh ./MP86_PA8_Security_8612.bin
    5.  Answer the confirm/continue prompts if any.
    6.  The patch installer will install the files.
    7.  Repeat the steps for the standby server (failover deployment), or other nodes (multi-node deployment).
    The patch can not be rolled back.



    Upgrade from MeetingPlace 8.6.1 to 8.6.2


    Preparing to Upgrade the Application Server Software

    Caution  Do not run any other processes or tasks on your systems during an upgrade.


    Note Be sure the Application Server node is in maintenance mode. Sign in to the Administration Center. Select Maintenance > Maintenance Configuration, then Start Maintenance Mode Now.

    • Do not uninstall the Application Server software before the upgrade.
    • The Cisco Unified MeetingPlace system must be running when you perform an upgrade. Do not turn off the Cisco Unified MeetingPlace services.
    • If you have automatic backups/archives enabled, then turn this off when you upgrade the Application Server software.
    • Make sure your system is functional before starting the upgrade (the Operational Status of each node is green)
    Determining Which Procedure to Follow
    Depending on the configuration of your Application Server, follow one of these steps:
    Upgrading the Application Server by Using the Console
    Before You Begin

    Note Be sure the Application Server node is in maintenance mode, or the upgrade program will terminate.

    Procedure

    Step 1 Go to Cisco.com and find the upgrade binary: http://www.cisco.com/cisco/software/navigator.html and select Products > Voice and Unified Communications > Unified Communications Applications > Conferencing > Cisco Unified MeetingPlace > Cisco Unified MeetingPlace 8.6 > Unified MeetingPlace Application Server. The naming convention will be similar to CUMP_AppServerUpgrade_< version >.bin, where < version> is the version number to which you are upgrading.
    Step 2 Save the file to a convenient location.
    Step 3 Enter md5sum CUMP_AppServerUpgrade_< version >.bin to determine the checksum of the file that you downloaded. Compare this value to the checksum value of the file that is posted on the download page on Cisco.com.
    Step 4 Sign in to the Application Server command-line interface as the root user.
    Step 5 Transfer the CUMP_AppServerUpgrade_< version >.bin file to the Application Server to the /tmp folder.
    We recommend saving the file to the /partB directory, as it has a lot of free space. (You can do this by using the mv command: mv /tmp/CUMP_AppServerUpgrade_.bin /partB.)
    Step 6 Enter sh./ CUMP_AppServerUpgrade_< version >.bin to execute the file.
    The upgrade program checks to see if there are any previous versions of the Application Server software installed. If there is at least one previous version, the upgrade program displays a message listing the previous version found on the system.

    Note If the upgrade program does not find any previous versions of the Application Server software, the upgrade program displays an error message and you must quit the upgrade.

    Step 7 Select Enter after reading the Introduction.
    Step 8 Select Enter to confirm your existing system.
    Step 9 Select Enter to confirm the pre-installation summary.
    Values include the product name and the amount of disk space required and available for the installation target.
    Step 10 Select Enter to start the upgrade.
    The upgrade program upgrades all the required components associated with the Application Server software.
    The upgrade program displays a message stating that the upgrade is complete.
    Step 11 Select 1 to restart the system.
    Step 12 As required, upgrade the other Application Server nodes in your multinode system.
    Step 13 Synchronize the Hardware Media Server and meeting types.
    Step 14 Put the Audio Blade back online.


    Supported Upgrades and Migrations to Release 8.6.2.10


    =============================================================



    Patch to MeetingPlace 8.6.2 SR1


    Name
    ====
    MeetingPlace Platform patch
    Version: 8.6.2.10 Patch 1
    Filename: MP86MR1_PA1_Security_86210.bin.gz
    Cksum: 3893645416 1142610 MP86MR1_PA1_Security_86210.bin
    Released: Jul 10, 2015
    Defects fixed
    =============
    CSCuu82563 - Evaluation of meetingplace for OpenSSL June 2015
    Important notes
    =============
    Once the installation is finished, verify openssl version:
        [root@server ~]# openssl version
        CiscoSSL 1.0.1p.4.13-fips
    Dependencies
    ============
    Initial 8.6.2.10 (8.6MR1) installation required.
    Installation instructions
    =========================
    These are general installation instructions. For details about each step, please see http://docwiki.cisco.com/wiki/Cisco_Unified_MeetingPlace_-_Application_Server_hotfix_installation_FAQ
    All CLI commands should be executed as root.
    For multi-node deployments, apply the patch on all nodes in the following order:
        a. Leaf nodes first
        b. Secondary MBD
        c. Primary MBD
          
    1.  Copy the patch file to the MP Application server
    2.  Put the patch in /mpx-record and gunzip it.
    3.  Check cksum of gunzipped patch:
        If the the checksum value matches values above, you can proceed with running the patch
        If the checksum value doesn't match, the file is corrupted, please, contact Cisco TAC to get the file republished.
    4.  Set the appropriate (755) permissions on the extracted .bin file and run it.
    5.  Answer the confirm/continue prompts if any.
    6.  The patch installer will install the files.
    7.  Repeat the steps for the standby server (failover deployment), or other nodes (multi-node deployment).
    The patch can not be rolled back.







    Friday, July 10, 2015

    Cisco Security Advisory: OpenSSL Alternative Chains Certificate Forgery Vulnerability (July 2015) Affecting Cisco Products

    Cisco Security Advisory: OpenSSL Alternative Chains Certificate Forgery Vulnerability

     

    Wow, this affects quite a lot of products;

     

    The following Cisco products are currently under investigation:

    Collaboration and Social Media

    ·         Cisco WebEx Meetings Server versions 1.x

    ·         Cisco WebEx Meetings Server versions 2.x

    ·         Cisco WebEx Node for MCS


    Endpoint Clients and Client Software

    ·         Cisco Agent for OpenFlow

    ·         Cisco AnyConnect Secure Mobility Client for Android

    ·         Cisco AnyConnect Secure Mobility Client for Linux

    ·         Cisco AnyConnect Secure Mobility Client for Windows

    ·         Cisco AnyConnect Secure Mobility Client for iOS

    ·         Cisco Jabber Guest 10.0(2)

    ·         Cisco Jabber Software Development Kit

    ·         Cisco Jabber for Android

    ·         Cisco Jabber for Mac

    ·         Cisco Jabber for Windows

    ·         Cisco Jabber for iOS

    ·         Cisco WebEx Meetings Client - Hosted

    ·         Cisco WebEx Meetings Client - On Premises

    ·         Cisco WebEx Meetings for Android

    ·         WebEx Meetings Server - SSL Gateway

    ·         WebEx Recording Playback Client


    Network Application, Service, and Acceleration

    ·         Cisco ACE 30 Application Control Engine Module

    ·         Cisco ACE 4710 Application Control Engine (A5)

    ·         Cisco Application and Content Networking System (ACNS)

    ·         Cisco InTracer

    ·         Cisco Network Admission Control (NAC)

    ·         Cisco Visual Quality Experience Server

    ·         Cisco Visual Quality Experience Tools Server

    ·         Cisco Wide Area Application Services (WAAS)


    Network and Content Security Devices

    ·         Cisco ASA CX and Cisco Prime Security Manager

    ·         Cisco Adaptive Security Appliance (ASA)

    ·         Cisco Clean Access Manager

    ·         Cisco Content Security Appliance Updater Servers

    ·         Cisco Content Security Management Appliance (SMA)

    ·         Cisco Email Security Appliance (ESA)

    ·         Cisco FireSIGHT System Software

    ·         Cisco IPS

    ·         Cisco Identity Services Engine (ISE)

    ·         Cisco IronPort Encryption Appliance (IEA)

    ·         Cisco NAC Guest Server

    ·         Cisco NAC Server

    ·         Cisco Physical Access Control Gateway

    ·         Cisco Secure Access Control Server (ACS)

    ·         Cisco Virtual Security Gateway for Microsoft Hyper-V

    ·         Cisco Web Security Appliance (WSA)


    Network Management and Provisioning

    ·         Cisco Application Networking Manager

    ·         Cisco Cloupia Unified Infrastructure Controller

    ·         Cisco Configuration Professional

    ·         Cisco Digital Media Manager

    ·         Cisco Multicast Manager

    ·         Cisco Netflow Collection Agent

    ·         Cisco Network Analysis Module

    ·         Cisco Packet Tracer

    ·         Cisco Prime Access Registrar

    ·         Cisco Prime Collaboration Assurance

    ·         Cisco Prime Collaboration Deployment

    ·         Cisco Prime Collaboration Provisioning

    ·         Cisco Prime Data Center Network Manager (DCNM)

    ·         Cisco Prime IP Express

    ·         Cisco Prime Infrastructure Standalone Plug and Play Gateway

    ·         Cisco Prime Infrastructure

    ·         Cisco Prime LAN Management Solution (LMS - Solaris)

    ·         Cisco Prime License Manager

    ·         Cisco Prime Network Registrar (CPNR)

    ·         Cisco Prime Network Services Controller

    ·         Cisco Prime Network

    ·         Cisco Prime Optical for SPs

    ·         Cisco Prime Performance Manager

    ·         Cisco Prime Security Manager

    ·         Cisco Security Manager

    ·         Cisco Show and Share (SnS)

    ·         Cisco UCS Central

    ·         Local Collector Appliance (LCA)


    Routing and Switching - Enterprise and Service Provider

    ·         Cisco 910 Industrial Router

    ·         Cisco ASR 5000 Series

    ·         Cisco Application Policy Infrastructure Controller (APIC)

    ·         Cisco Broadband Access Center Telco Wireless

    ·         Cisco Connected Grid Router - CGOS

    ·         Cisco IOS Software and Cisco IOS XE Software

    ·         Cisco IOS XE (WebUI feature only)

    ·         Cisco IOS XR

    ·         Cisco MDS 9000 Series Multilayer Switches

    ·         Cisco Mobile Wireless Transport Manager

    ·         Cisco Nexus 1000V InterCloud

    ·         Cisco Nexus 1000V Series Switches

    ·         Cisco Nexus 3X00 Series Switches

    ·         Cisco Nexus 4000 Series Blade Switches

    ·         Cisco Nexus 5000 Series Switches

    ·         Cisco Nexus 6000 Series Switches

    ·         Cisco Nexus 7000 Series Switches

    ·         Cisco Nexus 9000 (ACI/Fabric Switch)

    ·         Cisco Nexus 9000 Series (standalone, running NxOS)

    ·         Cisco ONS 15454 Series Multiservice Provisioning Platforms

    ·         Cisco OnePK All-in-One VM

    ·         Cisco Service Control Operating System


    Routing and Switching - Small Business

    ·         Cisco Sx220 switches

    ·         Cisco Sx300 switches

    ·         Cisco Sx500 switches


    Unified Computing

    ·         Cisco Common Services Platform Collector

    ·         Cisco Standalone rack server CIMC

    ·         Cisco UCS Invicta Series Solid State Systems

    ·         Cisco Unified Computing System (Management software)

    ·         Cisco Unified Computing System B-Series (Blade) Servers

    ·         Cisco Virtual Security Gateway

    ·         Cisco Virtualization Experience Media Engine


    Voice and Unified Communications Devices

    ·         Cisco 190 ATA Series Analog Terminal Adaptor

    ·         Cisco 8800 Series IP Phones - VPN Feature

    ·         Cisco ATA 187 Analog Telephone Adaptor

    ·         Cisco Agent Desktop for Cisco Unified Contact Center Express

    ·         Cisco Agent Desktop

    ·         Cisco Computer Telephony Integration Object Server (CTIOS)

    ·         Cisco DX Series IP Phones

    ·         Cisco Emergency Responder

    ·         Cisco Finesse

    ·         Cisco Hosted Collaboration Mediation Fulfillment

    ·         Cisco IM and Presence Service (CUPS)

    ·         Cisco IP Interoperability and Collaboration System (IPICS)

    ·         Cisco MediaSense

    ·         Cisco MeetingPlace

    ·         Cisco Paging Server (Informacast)

    ·         Cisco Paging Server

    ·         Cisco Remote Silent Monitoring

    ·         Cisco SPA112 2-Port Phone Adapter

    ·         Cisco SPA122 ATA with Router

    ·         Cisco SPA232D Multi-Line DECT ATA

    ·         Cisco SPA30X Series IP Phones

    ·         Cisco SPA50X Series IP Phones

    ·         Cisco SPA51X Series IP Phones

    ·         Cisco SPA525G

    ·         Cisco TAPI Service Provider (TSP)

    ·         Cisco Unified 6901 IP Phones

    ·         Cisco Unified 6911 IP Phones

    ·         Cisco Unified 6921 IP Phones

    ·         Cisco Unified 6945 IP Phones

    ·         Cisco Unified 7800 Series IP Phones

    ·         Cisco Unified 8831 series IP Conference Phone

    ·         Cisco Unified 8945 IP Phone

    ·         Cisco Unified 8961 IP Phone

    ·         Cisco Unified 9951 IP Phone

    ·         Cisco Unified 9971 IP Phone

    ·         Cisco Unified Attendant Console Advanced

    ·         Cisco Unified Attendant Console Business Edition

    ·         Cisco Unified Attendant Console Department Edition

    ·         Cisco Unified Attendant Console Enterprise Edition

    ·         Cisco Unified Attendant Console Premium Edition

    ·         Cisco Unified Attendant Console Standard

    ·         Cisco Unified Communications Domain Manager

    ·         Cisco Unified Communications Manager (UCM)

    ·         Cisco Unified Communications Manager Session Management Edition (SME)

    ·         Cisco Unified Contact Center Enterprise

    ·         Cisco Unified IP Conference Phone 8831 for Third-Party Call Control

    ·         Cisco Unified IP Phone 7900 Series

    ·         Cisco Unified Intelligent Contact Management Enterprise

    ·         Cisco Unified Sip Proxy

    ·         Cisco Unified Workforce Optimization

    ·         Cisco Unity Connection (UC)

    ·         Cisco Unity Connection


    Video, Streaming, TelePresence, and Transcoding Devices

    ·         Cisco AnyRes Live (CAL)

    ·         Cisco DCM Series 9900-Digital Content Manager

    ·         Cisco Digital Media Players (DMP) 4300 Series

    ·         Cisco Digital Media Players (DMP) 4400 Series

    ·         Cisco Edge 300 Digital Media Player

    ·         Cisco Edge 340 Digital Media Player

    ·         Cisco Enterprise Content Delivery System (ECDS)

    ·         Cisco Expressway Series

    ·         Cisco Headend System Release

    ·         Cisco Internet Streamer (CDS)

    ·         Cisco Jabber Video for TelePresence (Movi)

    ·         Cisco Media Experience Engines (MXE)

    ·         Cisco Media Services Interface

    ·         Cisco Model D9485 DAVIC QPSK

    ·         Cisco TelePresence 1310

    ·         Cisco TelePresence Advanced Media Gateway Series

    ·         Cisco TelePresence Conductor

    ·         Cisco TelePresence Content Server (TCS)

    ·         Cisco TelePresence EX Series

    ·         Cisco TelePresence ISDN GW 3241

    ·         Cisco TelePresence ISDN GW MSE 8321

    ·         Cisco TelePresence ISDN Link

    ·         Cisco TelePresence MCU (8510, 8420, 4200, 4500, and 5300)

    ·         Cisco TelePresence MX Series

    ·         Cisco TelePresence Profile Series

    ·         Cisco TelePresence SX Series

    ·         Cisco TelePresence Serial Gateway Series

    ·         Cisco TelePresence Server 8710, 7010

    ·         Cisco TelePresence Server on Multiparty Media 310, 320

    ·         Cisco TelePresence Server on Virtual Machine

    ·         Cisco TelePresence Supervisor MSE 8050

    ·         Cisco TelePresence System 1000

    ·         Cisco TelePresence System 1100

    ·         Cisco TelePresence System 1300

    ·         Cisco TelePresence System 3000 Series

    ·         Cisco TelePresence System 500-32

    ·         Cisco TelePresence System 500-37

    ·         Cisco TelePresence TX 9000 Series

    ·         Cisco TelePresence Video Communication Server (VCS)

    ·         Cisco Telepresence Integrator C Series

    ·         Cisco VDS Service Broker

    ·         Cisco VEN501 Wireless Access Point

    ·         Cisco Video Surveillance 3000 Series IP Cameras

    ·         Cisco Video Surveillance 4000 Series High-Definition IP Cameras

    ·         Cisco Video Surveillance 4300E/4500E High-Definition IP Cameras

    ·         Cisco Video Surveillance 6000 Series IP Cameras

    ·         Cisco Video Surveillance 7000 Series IP Cameras

    ·         Cisco Video Surveillance Media Server

    ·         Cisco Video Surveillance PTZ IP Cameras

    ·         Cisco Videoscape Control Suite

    ·         Cloud Object Store (COS)

    ·         Tandberg Codian ISDN GW 3210/3220/3240

    ·         Tandberg Codian MSE 8320 model


    Wireless

    ·         Cisco Aironet 2700 Series Access Point

    ·         Cisco Mobility Services Engine (MSE)

    ·         Cisco Wireless LAN Controller (WLC)


    Cisco Hosted Services

    ·         Cisco Cloud Web Security

    ·         Cisco Connected Analytics For Collaboration

    ·         Cisco Intelligent Automation for Cloud

    ·         Cisco Proactive Network Operations Center

    ·         Cisco Registered Envelope Service (CRES)

    ·         Cisco Unified Services Delivery Platform (CUSDP)

    ·         Cisco Universal Small Cell 5000 Series running V3.4.2.x software

    ·         Cisco Universal Small Cell 7000 Series running V3.4.2.x software

    ·         Cisco WebEx Messenger Service

    ·         Connected Analytics for Network Deployment (CAND)

    ·         Network Performance Analytics (NPA)

    ·         Partner Supporting Service (PSS) 1.x

    ·         Serial Number Assessment Service (SNAS)

    ·         Services Analytic Platform

     

     Vulnerable Products

    Cisco is currently investigating its product line to determine which products may be affected by this vulnerability and the impact on each affected product.

    Products Confirmed Not Vulnerable

    Cisco has confirmed that the following products are not vulnerable to the vulnerability announced by the OpenSSL Project on July 9, 2015:

    Endpoint Clients and Client Software

    · Cisco IP Communicator

    · Cisco NAC Agent for Mac

    · Cisco NAC Agent for Web

    · Cisco NAC Agent for Windows

    · Cisco UC Integration for Microsoft Lync

    · Cisco Unified Personal Communicator

    · Cisco WebEx Meetings for BlackBerry

    · Cisco WebEx Productivity Tools


    Network Application, Service, and Acceleration

    · Cisco Extensible Network Controller (XNC)

    · Cisco Nexus Data Broker (NDB)


    Network and Content Security Devices

    · Cisco ASA Content Security and Control (CSC) Security Services Module

    · Cisco Adaptive Security Device Manager

    · Cisco Physical Access Manager


    Network Management and Provisioning

    · Cisco Connected Grid Device Manager

    · Cisco Connected Grid Network Management System

    · Cisco Insight Reporter

    · Cisco Linear Stream Manager

    · Cisco MGC Node Manager (CMNM)

    · Cisco Prime Analytics

    · Cisco Prime Cable Provisioning

    · Cisco Prime Central for SPs

    · Cisco Prime Collaboration Manager

    · Cisco Prime Home

    · Cisco Prime Provisioning for SPs

    · Cisco Prime Provisioning

    · Cisco Unified Provisioning Manager (CUPM)

    · CiscoWorks Network Compliance Manager


    Routing and Switching - Enterprise and Service Provider

    · Cisco IOS XE (SSL VPN feature)


    Voice and Unified Communications Devices

    · Cisco Billing and Measurements Server

    · Cisco Packaged Contact Center Enterprise

    · Cisco SPA8000 8-port IP Telephony Gateway

    · Cisco SPA8800 IP Telephony Gateway with 4 FXS and 4 FXO Ports

    · Cisco USC8088

    · Cisco Unified 3900 series IP Phones

    · Cisco Unified Client Services Framework

    · Cisco Unified E-Mail Interaction Manager

    · Cisco Unified Integration for IBM Sametime

    · Cisco Unified Operations Manager (CUOM)

    · Cisco Unified Web Interaction Manager

    · Cisco Virtual PGW 2200 Softswitch

    · Cisco Voice Portal (CVP)

    · xony VIM/CCDM/CCMP


    Video, Streaming, TelePresence, and Transcoding Devices

    · Cisco AnyRes VOD (CAL)

    · Cisco D9824 Advanced Multi Decryption Receiver

    · Cisco D9854/D9854-I Advanced Program Receiver

    · Cisco D9858 Advanced Receiver Transcoder

    · Cisco D9859 Advanced Receiver Transcoder

    · Cisco D9865 Satellite Receiver

    · Cisco TelePresence Exchange System (CTX)

    · Cisco TelePresence Management Suite (TMS)

    · Cisco TelePresence Management Suite Analytics Extension (TMSAE)

    · Cisco TelePresence Management Suite Extension (TMSXE)

    · Cisco TelePresence Management Suite Extension for IBM

    · Cisco TelePresence Management Suite Provisioning Extension


    Wireless

    · Cisco Wireless Control System (WCS)


    Cisco Hosted Services

    · Cisco SmartConnection

    · Cisco SmartReports

    · Cisco WebEx Meetings (Meeting Center, Training Center, Event Center, Support Center)

    · Communication/Collaboration Sizing Tool, Virtue Machine Placement Tool, Cisco Unified Communications Upgrade Readiness Assessment

    · Life Cycle Management Agent Manager (LCM)


    No other Cisco products are currently known to be affected by this vulnerability

     

     

    -----Original Message-----
    From: cust-security-announce [mailto:cust-security-announce-bounces@cisco.com] On Behalf Of Cisco Systems Product Security Incident Response Team
    Sent: Friday, July 10, 2015 9:04 AM
    Subject: Cisco Security Advisory: OpenSSL Alternative Chains Certificate Forgery Vulnerability (July 2015) Affecting Cisco Products

     

    -----BEGIN PGP SIGNED MESSAGE-----

    Hash: SHA1

     

    Cisco Security Advisory: OpenSSL Alternative Chains Certificate Forgery Vulnerability (July 2015) Affecting Cisco Products

     

    Advisory ID: cisco-sa-20150710-openssl

     

    Revision 1.0

     

    For Public Release 2015 July 10 16:00  UTC (GMT)

     

    +-----------------------------------------------------------------------

     

    Summary

    =======

     

    On July 9, 2015, the OpenSSL Project released a security advisory detailing a vulnerability affecting applications that verify certificates, including SSL/Transport Layer Security (TLS)/Datagram Transport Layer Security (DTLS) clients and SSL/TLS/DTLS servers using client authentication.

     

    Multiple Cisco products incorporate a version of the OpenSSL package affected by this vulnerability that could allow an unauthenticated, remote attacker to cause certain checks on untrusted certificates to be bypassed, enabling the attacker to forge "trusted" certificates that could be used to conduct man-in-the-middle attacks.

     

    This advisory will be updated as additional information becomes available.

     

    Cisco will release free software updates that address this vulnerability.

     

    Workarounds that mitigate this vulnerability may be available.

     

    This advisory is available at the following link:

     

    http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150710-openssl

     

     

    IMPORTANT NOTICE
    This e-mail, including attachments, is covered by the Electronic Communications Privacy Act, 18 U.S.C. §§ 2510-2521, may include confidential, proprietary, and legally privileged information (including, without limitation, attorney-client privilege), and may be used only by the person or entity to which it is addressed. If the reader of this e-mail is not the intended recipient or his or her authorized agent, the reader is hereby notified that any use, dissemination, distribution, printing, or copying of this e-mail is strictly prohibited. If you have received this e-mail in error, please notify the sender by replying to this message and delete this e-mail immediately.