cancel
Showing results for 
Search instead for 
Did you mean: 

Tech Alert: VTS16-001 ... Master Upgrade to 7.7.2

nbu123
Level 5

We are in process of upgrading our master server to v7.7.2 from 7.5.0.7.

Please share more insight about Tech Alert: VTS16-001.

Do we need to install the Hotfix immediate after the upgrade or it can be done later, also what is the process to apply this Hotfix.

18 REPLIES 18

Nicolai
Moderator
Moderator
Partner    VIP   

https://www.veritas.com/content/support/en_US/security/VTS16-001.html

Product

 Version

Solution(s)

Veritas NetBackup

 7.7.1, 7.6.1.x, 7.6.0.x,

 7.5.x.x, 7.1.x, 7.0.x

Upgrade to Veritas NetBackup 7.7.2 or apply security hotfix for 7.7, 7.6.1.2, 7.6.0.4, 7.5.0.7 as a minimum

7.7.2 is NOT affected by VTS16-001

Will_Restore
Level 6

7.7 = 7.7.1  ??

 

StefanosM
Level 6
Partner    VIP    Accredited Certified

7.7 was never a public release. It was a First availability release only.

7.7.1 was the public release.

sdo
Moderator
Moderator
Partner    VIP    Certified

Hi StefanosM - why is NetBackup v7.7 listed here then:

https://www.veritas.com/support/en_US/article.000036173

...and there appears to be GA release notes for v7.7:

https://www.veritas.com/support/en_US/article.DOC8512

VerJD
Level 4
Employee

@nbu123 ... Nicolai is correct above, regarding VTS16-001: NetBackup Remote Access Vulnerabilities

**(If you need more insight about Tech Alert: VTS16-001, please open a case with NetBackup Support.)**


Additionally, note the following references...

VTS16-001: A hotfix is now available for NetBackup, NetBackup OpsCenter, and NetBackup Appliances.
- http://www.veritas.com/docs/000108183

NetBackup and NetBackup OpsCenter:
 • 7.7.2 (for backwards compatibility)

All NetBackup and NetBackup Appliances VTS16-001 hotfix direct download links
- http://www.veritas.com/docs/000109251

Version    Description    Filename    MD5 Checksum
NetBackup 7.7.2    NetBackup 7.7.2 Hotfix for NetBackup Server/Client    NB_7.7.2_ET3871154_1.zip    4f25b719157e32ace3d7ff6b95b940af

(To apply the NetBackup hotfix EEB is fairly straight forward: extract the files, shutdown NetBackup, run the executable, possibly reboot - review the README file included for specifics. Again, if you need more insight about Tech Alert: VTS16-001, please open a case with NetBackup Support.)


Otherwise...

  • If you're upgrading everything to NetBackup 7.7.2, you don't necessarily need the compatibility binaries installed.

However...

  • If you don't plan on upgrading all of your servers to the latest version (7.7.2) yet, it might be a good idea to upgrade your master server to NetBackup 7.7.2, and then apply the EEB, for backwards compatibility with any older NetBackup servers/clients (e.g. 7.6.1.2, 7.6.0.4, 7.5.0.7), which also have the hotfix applied.

Hopefully that helps answer your inquiries and gives you a clear path to proceed with your upgrade. Good luck to ya! wink

 

JD | Veritas NetBackup Support

sdo
Moderator
Moderator
Partner    VIP    Certified

Hi VerJD,

Thanks for your post.  Whilst I think that those of us with English as a first language should be able to work out what is "implied" within the tech notes, could I ask a few scenario based questions to perhaps make things a little bit clearer for everyone.

But first a few questions re your text:

Q1a) When you say "To apply the NetBackup hotfix EEB is fairly straight forward: extract the files, shutdown NetBackup, run the executable, possibly reboot", why "possibly"?

Q1b) IMO, we either have to reboot, or we don't have to reboot.  How will we know whether we have to reboot or not?

Q2a) When you say "If you're upgrading everything to NetBackup 7.7.2, you don't necessarily need the compatibility binaries installed", again why might we not need the binaries - what I mean is, how are we supposed to know whether they are necessary or not?

Q2b) And what are these "compatibility binaries", is this the EEB itself that you are referring to?

.

My scenario based questions:

---------------------------------------

S1 - Cannot upgrade anything right now to v7.7.2:

S1) If we're unable to upgrade anything (master, media(s), client(s)) to v7.7.2 right now, then if we install the EEB on the master, then *must* we also install the EEB on all media(s) and client(s) at the same time?

.

S2 - Can upgrade master to v7.7.2, but cannot upgrade anything else right now:

S2a) If we're able to upgrade the master, but not the media(s) and not the client(s), to v7.7.2, then do we still need to apply the EEB to the master which is now v7.7.2?

S2b) If we do still need to apply the EEB to the master, then would we also need to apply the EEB to all media(s) and all client(s) at the same time?

S2c) If we do not need to apply the EEB to the master server, then do we still need to apply the EEB to all media(s) and all client(s) at the same time?

.

S3 - Can upgrade master, and can upgrade media(s), to v7.7.2 - but cannot upgrade any clients right now:

S3a) Would we still need to apply the EEB to the master, and all media(s)?

S3b) Would we still need to apply the EEB to all client(s) at the same time?

.

S4 - Master and media(s) and most clients are already at v7.7.2:

S4a) If most of an environment is already at v7.7.2, but a handful of clients are not which are running client v7.6.1.2 but cannot be upgraded to v7.7.2, then if we were to apply the EEB to the v7.6.1.2 clients (which cannot be upgraded to v7.7.2), then would we still need to apply the EEB to the v7.7.2 master and v7.7.2 media(s)?

S4b) If we do have to apply the EEB to the v7.7.2 master and v7.7.2 media(s) because we applied the EEB to the v7.6.1.2 clients, then would we also need to apply the EEB to the other clients which are already running v7.7.2 client?

.

Apologies for so many questions... It's just that sometimes the tech notes just aren't descriptive enough.

StefanosM
Level 6
Partner    VIP    Accredited Certified

Because as I'm getting older I'm starting to forget......

You are right about 7.7.   The 7.6 was never GA but only FA.

sdo
Moderator
Moderator
Partner    VIP    Certified

I thought I was going mad for a second.   hang on... I am...   :p

.

Anyway - I have another related question:

Nicolai posted this:

Veritas NetBackup

 7.7.1, 7.6.1.x, 7.6.0.x,

 7.5.x.x, 7.1.x, 7.0.x

Upgrade to Veritas NetBackup 7.7.2 or apply security hotfix for 7.7, 7.6.1.2, 7.6.0.4, 7.5.0.7 as a minimum

...but I want to know exactly what are v7.7.1 customers supposed to do?   The above implies that there is no EEB for v7.7.1, and so by implication the only course of action for v7.7.1 users is to upgrade to v7.7.2?  Is this right?

 

Will_Restore
Level 6

Which is why I asked above

7.7 = 7.7.1  ??

Maybe we're both going mad. devil

Genericus
Moderator
Moderator
   VIP   

AFAIK, the EEB must be applied to everywhere NetBackup is installed, if you are below 7.7.2, whether they are master, media server or just clients.

Aslo, the EEB is only available at specific versions, so you MUST be at one of those. 

 

Which is why I am upgrading ALL my clients to 7.6.1.2 and applying the EEB to them....

 

 

NetBackup 9.1.0.1 on Solaris 11, writing to Data Domain 9800 7.7.4.0
duplicating via SLP to LTO5 & LTO8 in SL8500 via ACSLS

sdo
Moderator
Moderator
Partner    VIP    Certified

Thanks Genericus...

...any advice on scenario 4 (from above):

S4 - Master and media(s) and most clients are already at v7.7.2:

S4a) If most of an environment is already at v7.7.2, but a handful of clients are not which are running client v7.6.1.2 but cannot be upgraded to v7.7.2, then if we were to apply the EEB to the v7.6.1.2 clients (which cannot be upgraded to v7.7.2), then would we still need to apply the EEB to the v7.7.2 master and v7.7.2 media(s)?

S4b) If we do have to apply the EEB to the v7.7.2 master and v7.7.2 media(s) because we applied the EEB to the v7.6.1.2 clients, then would we also need to apply the EEB to the other clients which are already running v7.7.2 client?

 

Will_Restore
Level 6

No EEB needed or available for 7.7.2

sdo
Moderator
Moderator
Partner    VIP    Certified

But there is an EEB for v7.7.2:

https://www.veritas.com/support/en_US/article.000109251

...and the FAQ describes when it is required:

https://www.veritas.com/support/en_US/article.000108248

Nicolai
Moderator
Moderator
Partner    VIP   

Great - confusion is now total.

I downloaded the fix and it does say 7.7.2 in the readme.

I have mailed a frind who can tell what right and wrong here laugh

sdo
Moderator
Moderator
Partner    VIP    Certified

Exactly.

The FAQ is ok, up to a point.

But, IMO, the instructions should have been much clearer... more time should have been spent preparing something that it is utterly and completely 100% unambiguous with absolutely no room for misintepretation or misunderstanding.

Maybe I'm being dense, as usual, but I'm still struggling to map the very brief topics/points of the FAQ to all of my configuration scenarios.

Nicolai
Moderator
Moderator
Partner    VIP   

This is what I got from Martin: 

Q: If I upgrade to 7.7.2, do I need to install the hotfix on all 7.7.2 systems?

A.   No. You only need to apply the 7.7.2 hotfix to 7.7.2 systems that are utilized to connect to back-level systems via the Java interface.  For 2.7.2 Appliances, the eebinstaller will update the Java console binaries and is only needed if the console is being remotely displayed.

So 7.7.2 is what you want. No need to add the 7.7.2 hotfix

Will_Restore
Level 6

What happens if we apply 7.7.2 EEB to 7.7.1 ? 

 

OK, better quit while I am behind. angry

Genericus
Moderator
Moderator
   VIP   

LOL, you cannot apply the EEB to the wrong version, it will not proceed past initial check...

 

However, for you AIX fans - A partial installation that fails due to lack of space on the client, will leave NetBackup OFF on the client, so backups will fail...

 

Thanks, Obama

NetBackup 9.1.0.1 on Solaris 11, writing to Data Domain 9800 7.7.4.0
duplicating via SLP to LTO5 & LTO8 in SL8500 via ACSLS