Balabit - Firmware versions and upgrade history (site 2)
Balabit SCB Solution · Config document · referenced from Operations, upgrades and troubleshooting
The firmware state of the site 2 cluster dc2-s-xblb001 as its support bundle of 2018-09-17 recorded it: the version files, the firmware lines of the bundle's summary, the directory of boot firmwares with its slots, and the list of upgrade logs with the date of each run. It is the only upgrade history of an SCB in my material.
| Item | Value |
|---|---|
| Cluster | dc2-s-xblb001, two SCB T-10 appliances, HA state ha |
| Firmware at the time | 5.0.6 core and boot firmware, product version 5.0 |
| Taken from | Support bundle of 2018-09-17, files info/versions.txt, info/info.txt, info/boot-firmwares.txt and the names of the files under logs/upgrade/ |
| Why the bundle was made | The bundle's folder is named after a problem with an RDP jump server of site 2; the notes keep nothing else about it |
| Dates of the upgrade runs | From the Unix time in each log file name, in UTC |
| Not in it | Which node each upgrade run belongs to; the upgrade procedure itself (the section "Upgrade process" of my operation how-to stayed TODO) |
The listing
output 67 lines
====================================================================== info/versions.txt ====================================================================== Revision: 05abe527dbd273e5e3c103a004965bd32d30d99a Technical version: 5.0.6 Product version: 5.0 NNX: 2018.4.25.731 Zorp 3.4 LTS (3.4.5) Config-Date: 2018-06-01T12:35:57+00:00 Trace: off Debug: off ADP 5.2.25 Revision: Compile-Date: May 30 2018 15:39:03 Debug: off ====================================================================== info/info.txt (host and firmware lines) ====================================================================== Host: dc2-s-xblb001.dc2-s-xblb001.adm.example.net Core firmware: Balabit Privileged Session Management 5.0.6 (revision: 05abe527dbd273e5e3c103a004965bd32d30d99a-5.0.6) Boot firmware: 5.0.6-5.0.6 Other Boot firmware: 5.0.6-5.0.6 HA state: ha ====================================================================== info/boot-firmwares.txt (ls -l of the boot firmware directory) ====================================================================== total 24 lrwxrwxrwx 1 root root 24 Jun 5 15:08 active -> scb-boot-5.0_5.0.6-5.0.6 lrwxrwxrwx 1 root root 24 Jun 5 15:08 current -> scb-boot-5.0_5.0.6-5.0.6 drwxr-xr-x 2 root root 4096 Jul 31 09:47 defaults lrwxrwxrwx 1 root root 24 Jun 5 15:08 previous -> scb-boot-5.0_5.0.6-5.0.6 drwxr-xr-x 2 root root 4096 Feb 14 2018 scb-boot-5.0_5.0.4-5.0.4 drwxr-xr-x 2 root root 4096 Apr 3 14:13 scb-boot-5.0_5.0.4b-5.0.4b drwxr-xr-x 2 root root 4096 Apr 10 08:48 scb-boot-5.0_5.0.5-5.0.5 drwxr-xr-x 2 root root 4096 May 9 11:05 scb-boot-5.0_5.0.5a-5.0.5a drwxr-xr-x 2 root root 4096 Jun 5 13:11 scb-boot-5.0_5.0.6-5.0.6 lrwxrwxrwx 1 root root 24 Feb 14 2018 slot1 -> scb-boot-5.0_5.0.4-5.0.4 lrwxrwxrwx 1 root root 26 Apr 3 14:13 slot2 -> scb-boot-5.0_5.0.4b-5.0.4b lrwxrwxrwx 1 root root 24 Apr 10 08:48 slot3 -> scb-boot-5.0_5.0.5-5.0.5 lrwxrwxrwx 1 root root 24 Jun 5 13:11 slot4 -> scb-boot-5.0_5.0.6-5.0.6 lrwxrwxrwx 1 root root 26 May 9 11:05 slot5 -> scb-boot-5.0_5.0.5a-5.0.5a ====================================================================== logs/upgrade/ (one log per upgrade run; date of the run from the file name, UTC) ====================================================================== 2018-01-16 logs/upgrade/5.0_5.0.0/upgrade.1516091428.log 2018-01-16 logs/upgrade/5.0_5.0.1/upgrade.1516093112.log 2018-01-16 logs/upgrade/5.0_5.0.2/upgrade.1516098218.log 2018-01-17 logs/upgrade/5.0_5.0.3/upgrade.1516194437.log 2018-01-17 logs/upgrade/5.0_5.0.3a/upgrade.1516196536.log 2018-01-17 logs/upgrade/5.0_5.0.3b/upgrade.1516196842.log 2018-01-17 logs/upgrade/5.0_5.0.3b/upgrade.1516198270.log 2018-01-25 logs/upgrade/5.0_5.0.3b/upgrade.1516890338.log 2018-01-25 logs/upgrade/5.0_5.0.3b/upgrade.1516892159.log 2018-01-26 logs/upgrade/5.0_5.0.3b/upgrade.1516958916.log 2018-02-05 logs/upgrade/5.0_5.0.3b/upgrade.1517836831.log 2018-02-14 logs/upgrade/5.0_5.0.4/upgrade.1518615995.log 2018-04-03 logs/upgrade/5.0_5.0.4b/upgrade.1522761833.log 2018-04-10 logs/upgrade/5.0_5.0.5/upgrade.1523343368.log 2018-05-09 logs/upgrade/5.0_5.0.5a/upgrade.1525860774.log 2018-06-05 logs/upgrade/5.0_5.0.6/upgrade.1528204633.log 2018-07-24 logs/upgrade/5.0_5.0.6/upgrade.1532441998.log
| Part | What it says |
|---|---|
Technical version: 5.0.6, Product version: 5.0 | A maintenance release of 5 LTS; the design notes that the second digit of an LTS release is 0 and that its maintenance releases contain only bug fixes and security updates |
Zorp 3.4 LTS (3.4.5), ADP 5.2.25 | Components inside the core firmware with their own versions: Zorp, which as I understand it carries the proxied connections, and ADP, whose name also appears in the Desktop Player's warning about an unverified certificate. |
Host: dc2-s-xblb001.dc2-s-xblb001.adm.example.net | The cluster name twice: as I read it, the host name field was filled with the cluster name and the domain field built the rest. Nothing in the bundle shows that it caused a problem |
Core firmware: Balabit Privileged Session Management 5.0.6 | The core firmware calls itself "Balabit Privileged Session Management"; my documents all say Shell Control Box, and the material does not explain the difference |
Boot firmware and Other Boot firmware | As I read it, the boot firmware of this node and of the other node, both 5.0.6 |
slot1 … slot5 | Five boot firmwares kept side by side, from 5.0.4 (14 February) to 5.0.6 (5 June). Slot 5 (5.0.5a, 9 May) is older than slot 4 (5.0.6, 5 June); as I read it, slot 4 was reused for 5.0.6, and what it held before is not recorded. Nothing older than 5.0.4 is kept, although the upgrade logs go back to 5.0.0 |
active, current, previous | All three point to 5.0.6, so previous offered no older boot firmware to return to. The links carry the date of 5 June, not that of the second 5.0.6 run on 24 July |
defaults | A directory changed on 31 July, a week after the last upgrade run; the bundle does not show what is in it |
| Upgrade logs | Seventeen runs from 2018-01-16 to 2018-07-24: 5.0.0, 5.0.1 and 5.0.2 on one day, 5.0.3 to 5.0.3b the next, then 5.0.3b four more times until 5 February, and one or two runs per later release. The file names do not say which node ran them, and the logs themselves are not in my selection |
Read together with the design, which shows the site 1 cluster at 5.0.3 (boot firmware 5.0.3-5.0.3, built 2017-11-11) in December 2017, the site 2 cluster was brought from 5.0.0 to the then current release in one week of January 2018 (its own CA certificate is dated 6 March 2018, so the initial configuration may be later), and from then on followed the maintenance releases within one to two months of each other. That is my reading of the dates; the material holds no plan or change record for it.
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
| Balabit SCB 5.0.6, core firmware already named "Balabit Privileged Session Management" | The product is One Identity Safeguard for Privileged Sessions; 5.0.x LTS was supported from 2017-04-05 and discontinued on 2020-05-28 |
| Maintenance releases 5.0.0 to 5.0.6 within 5 LTS | The LTS policy reads as in the design (three years, or one year after the next LTS); the current LTS is 8.0 (8.0.2.1 LTS, June 2026), the newest release 9.0 |
| Upgrade within 5 LTS | To leave 5 LTS: the latest 5.0.x first, then 6.0 LTS, 7.0 LTS, 8.0 LTS and 9.0; a downgrade is not possible |
| T-10 appliances | T-Series End of Support 2024-07-31; SPS 8.0 is not supported on T-Series hardware |