LINUXOR.SK ... open source notes ...

Balabit - Firmware versions and upgrade history (site 2)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Operations, upgrades and troubleshooting

The firmware state of the site 2 cluster dc2-s-xblb001 as its support bundle of 2018-09-17 recorded it: the version files, the firmware lines of the bundle's summary, the directory of boot firmwares with its slots, and the list of upgrade logs with the date of each run. It is the only upgrade history of an SCB in my material.

ItemValue
Clusterdc2-s-xblb001, two SCB T-10 appliances, HA state ha
Firmware at the time5.0.6 core and boot firmware, product version 5.0
Taken fromSupport bundle of 2018-09-17, files info/versions.txt, info/info.txt, info/boot-firmwares.txt and the names of the files under logs/upgrade/
Why the bundle was madeThe bundle's folder is named after a problem with an RDP jump server of site 2; the notes keep nothing else about it
Dates of the upgrade runsFrom the Unix time in each log file name, in UTC
Not in itWhich node each upgrade run belongs to; the upgrade procedure itself (the section "Upgrade process" of my operation how-to stayed TODO)

The listing

output 67 lines
======================================================================
 info/versions.txt
======================================================================
Revision:          05abe527dbd273e5e3c103a004965bd32d30d99a
Technical version: 5.0.6
Product version:   5.0
NNX:               2018.4.25.731

Zorp 3.4 LTS (3.4.5)
Config-Date: 2018-06-01T12:35:57+00:00
Trace: off
Debug: off
ADP 5.2.25
Revision: 
Compile-Date: May 30 2018 15:39:03
Debug: off

======================================================================
 info/info.txt (host and firmware lines)
======================================================================
Host: dc2-s-xblb001.dc2-s-xblb001.adm.example.net
Core firmware: Balabit Privileged Session Management 5.0.6
 (revision: 05abe527dbd273e5e3c103a004965bd32d30d99a-5.0.6)
Boot firmware: 5.0.6-5.0.6
Other Boot firmware: 5.0.6-5.0.6

HA state: ha

======================================================================
 info/boot-firmwares.txt (ls -l of the boot firmware directory)
======================================================================
total 24
lrwxrwxrwx 1 root root   24 Jun  5 15:08 active -> scb-boot-5.0_5.0.6-5.0.6
lrwxrwxrwx 1 root root   24 Jun  5 15:08 current -> scb-boot-5.0_5.0.6-5.0.6
drwxr-xr-x 2 root root 4096 Jul 31 09:47 defaults
lrwxrwxrwx 1 root root   24 Jun  5 15:08 previous -> scb-boot-5.0_5.0.6-5.0.6
drwxr-xr-x 2 root root 4096 Feb 14  2018 scb-boot-5.0_5.0.4-5.0.4
drwxr-xr-x 2 root root 4096 Apr  3 14:13 scb-boot-5.0_5.0.4b-5.0.4b
drwxr-xr-x 2 root root 4096 Apr 10 08:48 scb-boot-5.0_5.0.5-5.0.5
drwxr-xr-x 2 root root 4096 May  9 11:05 scb-boot-5.0_5.0.5a-5.0.5a
drwxr-xr-x 2 root root 4096 Jun  5 13:11 scb-boot-5.0_5.0.6-5.0.6
lrwxrwxrwx 1 root root   24 Feb 14  2018 slot1 -> scb-boot-5.0_5.0.4-5.0.4
lrwxrwxrwx 1 root root   26 Apr  3 14:13 slot2 -> scb-boot-5.0_5.0.4b-5.0.4b
lrwxrwxrwx 1 root root   24 Apr 10 08:48 slot3 -> scb-boot-5.0_5.0.5-5.0.5
lrwxrwxrwx 1 root root   24 Jun  5 13:11 slot4 -> scb-boot-5.0_5.0.6-5.0.6
lrwxrwxrwx 1 root root   26 May  9 11:05 slot5 -> scb-boot-5.0_5.0.5a-5.0.5a

======================================================================
 logs/upgrade/ (one log per upgrade run; date of the run from the file name, UTC)
======================================================================
2018-01-16  logs/upgrade/5.0_5.0.0/upgrade.1516091428.log
2018-01-16  logs/upgrade/5.0_5.0.1/upgrade.1516093112.log
2018-01-16  logs/upgrade/5.0_5.0.2/upgrade.1516098218.log
2018-01-17  logs/upgrade/5.0_5.0.3/upgrade.1516194437.log
2018-01-17  logs/upgrade/5.0_5.0.3a/upgrade.1516196536.log
2018-01-17  logs/upgrade/5.0_5.0.3b/upgrade.1516196842.log
2018-01-17  logs/upgrade/5.0_5.0.3b/upgrade.1516198270.log
2018-01-25  logs/upgrade/5.0_5.0.3b/upgrade.1516890338.log
2018-01-25  logs/upgrade/5.0_5.0.3b/upgrade.1516892159.log
2018-01-26  logs/upgrade/5.0_5.0.3b/upgrade.1516958916.log
2018-02-05  logs/upgrade/5.0_5.0.3b/upgrade.1517836831.log
2018-02-14  logs/upgrade/5.0_5.0.4/upgrade.1518615995.log
2018-04-03  logs/upgrade/5.0_5.0.4b/upgrade.1522761833.log
2018-04-10  logs/upgrade/5.0_5.0.5/upgrade.1523343368.log
2018-05-09  logs/upgrade/5.0_5.0.5a/upgrade.1525860774.log
2018-06-05  logs/upgrade/5.0_5.0.6/upgrade.1528204633.log
2018-07-24  logs/upgrade/5.0_5.0.6/upgrade.1532441998.log
PartWhat it says
Technical version: 5.0.6, Product version: 5.0A maintenance release of 5 LTS; the design notes that the second digit of an LTS release is 0 and that its maintenance releases contain only bug fixes and security updates
Zorp 3.4 LTS (3.4.5), ADP 5.2.25Components inside the core firmware with their own versions: Zorp, which as I understand it carries the proxied connections, and ADP, whose name also appears in the Desktop Player's warning about an unverified certificate.
Host: dc2-s-xblb001.dc2-s-xblb001.adm.example.netThe cluster name twice: as I read it, the host name field was filled with the cluster name and the domain field built the rest. Nothing in the bundle shows that it caused a problem
Core firmware: Balabit Privileged Session Management 5.0.6The core firmware calls itself "Balabit Privileged Session Management"; my documents all say Shell Control Box, and the material does not explain the difference
Boot firmware and Other Boot firmwareAs I read it, the boot firmware of this node and of the other node, both 5.0.6
slot1 … slot5Five boot firmwares kept side by side, from 5.0.4 (14 February) to 5.0.6 (5 June). Slot 5 (5.0.5a, 9 May) is older than slot 4 (5.0.6, 5 June); as I read it, slot 4 was reused for 5.0.6, and what it held before is not recorded. Nothing older than 5.0.4 is kept, although the upgrade logs go back to 5.0.0
active, current, previousAll three point to 5.0.6, so previous offered no older boot firmware to return to. The links carry the date of 5 June, not that of the second 5.0.6 run on 24 July
defaultsA directory changed on 31 July, a week after the last upgrade run; the bundle does not show what is in it
Upgrade logsSeventeen runs from 2018-01-16 to 2018-07-24: 5.0.0, 5.0.1 and 5.0.2 on one day, 5.0.3 to 5.0.3b the next, then 5.0.3b four more times until 5 February, and one or two runs per later release. The file names do not say which node ran them, and the logs themselves are not in my selection

Read together with the design, which shows the site 1 cluster at 5.0.3 (boot firmware 5.0.3-5.0.3, built 2017-11-11) in December 2017, the site 2 cluster was brought from 5.0.0 to the then current release in one week of January 2018 (its own CA certificate is dated 6 March 2018, so the initial configuration may be later), and from then on followed the maintenance releases within one to two months of each other. That is my reading of the dates; the material holds no plan or change record for it.

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
Balabit SCB 5.0.6, core firmware already named "Balabit Privileged Session Management"The product is One Identity Safeguard for Privileged Sessions; 5.0.x LTS was supported from 2017-04-05 and discontinued on 2020-05-28
Maintenance releases 5.0.0 to 5.0.6 within 5 LTSThe LTS policy reads as in the design (three years, or one year after the next LTS); the current LTS is 8.0 (8.0.2.1 LTS, June 2026), the newest release 9.0
Upgrade within 5 LTSTo leave 5 LTS: the latest 5.0.x first, then 6.0 LTS, 7.0 LTS, 8.0 LTS and 9.0; a downgrade is not possible
T-10 appliancesT-Series End of Support 2024-07-31; SPS 8.0 is not supported on T-Series hardware
← solutionz