Guest

Cisco PACE Portal and Components

Release Notes for Cisco PACE Portal and Components, 2.0-VC

Table Of Contents

Release Notes for Cisco PACE Portal and Components, 2.0-VC

Cisco PACE Overview

Benefits of the Cisco PACE Portal

Caveats

Known Limitations and Problems

Accessing the Cisco PACE 2.0-VC Documentation Set

Obtaining Documentation, Obtaining Support, and Security Guidelines

Notices

OpenSSL/Open SSL Project

License Issues


Release Notes for Cisco PACE Portal and Components, 2.0-VC


Revised: March, 2010, OL-21017-01

These release notes include important information regarding Cisco Proactive Automation of Change Execution (PACE) Portal and Components 2.0 for EMC VoyenceControl, referred to as Cisco PACE, 2.0-VC.

This document contains the following:

Cisco PACE Overview

Benefits of the Cisco PACE Portal

Caveats

Known Limitations and Problems

Accessing the Cisco PACE 2.0-VC Documentation Set

Obtaining Documentation, Obtaining Support, and Security Guidelines

Notices


Note All documentation, including this document, the online help, and any or all of the parts of the Cisco PACE documentation set, might be upgraded over time. Therefore, we recommend you access the Cisco PACE documentation set using the Cisco.com URL: http://www.cisco.com/en/US/partner/products/ps10519/tsd_products_support_series_home.html


Cisco PACE Overview

The Cisco PACE solution combines products that accelerate operational success by helping IT organizations to securely automate and control changes and configuration in their networks. Cisco PACE helps enterprises meet compliance requirements, ensure business continuity, and increase user productivity.

Cisco PACE, 2.0-VC solution is made up of the following:

Cisco PACE Portal—offers a common portal framework to improve usability and interoperability of configuration and change management functionality. The portal allows for a more seamless and integrated environment when using a Voyence Control (VC) Server.

With the Cisco PACE Portal you can view important VC Server statistics and details in a single window instead of navigating through several windows to view the required data.

Cisco PACE Components—provides the Cisco PACE Syslog Analyzer that is promoted through integration with the Cisco PACE Portal.

Benefits of the Cisco PACE Portal

The benefits of the Cisco PACE Portal include:

Easy access to information —You can view the important features of all the installed applications on a VC Server. To do this you can click the corresponding views in Cisco PACE Portal, instead of launching each applications separately.

Lightweight GUI—Eliminates the need to install any plug-ins to launch the application.

Multi-server support—Lists all the portlets based on the applications installed on remote servers.

Pseudo SSO—Eliminates the need for entering user credentials for every application when launched from PACE Portal.

Portlets—Summary reporting windows that provide high-level views into configuration and change management functionality. A portlet can be used as a launch point to drill down on detailed application level capabilities. Canned portlets already setup to populate the portal are provided and you also have the ability to add custom portlets.

The following are some of the portlets supported by Cisco PACE 2.0-VC:

Change Report

Credential Report

Device Change Report

Device Communication Report

Device Inventory Report

Device Problem Report

Duplicate IP Address

IP Address Report

Job Task Report

OS Version Report

Compliance Status Report

Model Vendor Report

Policy Detail Report

Standard Detail Report

Syslog Analyzer and Reporting—provides the ability to report on multi-vendor syslog messages. syslogs provide a wealth of information for troubleshooting and monitoring potential network device related problems. Once syslogs are forwarded to the VC Server, they are subsequently captured in a database for near real-time reporting. Some of the reports provided include:

Syslog Report

Syslog Severity Report

24 Hour Syslog Report

Syslog Configuration Change Report

Caveats

Please read the following before using Cisco PACE, 2.0-VC.


CSCsr81715—Pseudo SSO fails sometimes if the user does not accept SSL Certs quickly

Description: Pseudo SSO fails sometimes if you do not accept the SSL Certificate quickly. This happens because the Pseudo SSO times out and launches the portal page.

Workaround: Either accept the SSL certificate warning as soon as prompted by the browser or add the SSL Certificate to the Certificate store in the client machine. This avoids the SSL certificate warning prompt every time you log in to the PACE portal.


CSCsr81738—Pseudo SSO won't happen for newly reg/unreg applications in current login session

Description: When applications are registered with Cisco PACE, the new applications are not auto logged in the current session. When application is unregistered, Cisco PACE does not auto logout.

Workaround: To enable auto login for newly registered applications, log out of PACE Portal and log in again.


CSCsr81767—Applications registered with PACE won't timeout according to PACE session

Description: Applications registered with Cisco PACE will not timeout according to the PACE session idle timeout.

Workaround: None at this time.


CSCsu18075—Multiple Security Alert screens are prompted

Description: You might be prompted up to five times for the Security Certificate: one time before you enter your username and password, and up to four times after entering your username and password.

Workaround: You can avoid this issue by accepting the SSL security certificate when prompted for it the first time.


CSCta62078—Internet Explorer 8 browser incorrectly recognized as supported browser

Description: Launch the Cisco PACE Portal from an Microsoft Internet Explorer 8 browser. Although the Cisco PACE Portal does not support Microsoft Internet Explorer 8, the login page the left panel incorrectly displays the current browser as supported.

Workaround: Use on of the browsers supported by the Cisco PACE Portal:

Microsoft Internet Explorer 6

Microsoft Internet Explorer 7

Firefox 2.0


CSCtb00594—Pace Portal daemon manager goes down if second interface is shutdown

Description: The Cisco PACE Portal daemon manager goes down if the second interface is shutdown.

Workaround: Do the following:

Disable the second interface.

Stop the Daemon Manager.

Enable the second NIC.

Start the Daemon Manager.


CSCtd53929—VC: installer can not connect to DB with hostname not being localhost

Description: PACE components can connect to the VC database only using the db config details specified in the config file.

WorkAround: Do the following:

1. Navigate to C:\VoyenceControl\db\controldb\data\postgresql.conf

2. Look for the line

listen_addresses =

3. The right side of the '=' will specify the hostnames that you can use to connect to. If the localhost is specified then you can connect using localhost. If it is not specified, then you cannot connect.

In the example below you can use either the localhost or IP address shown

listen_addresses = 'localhost,172.20.115.106'


CSCtd70723—Incorrect Session has timed out pop-up message displays

Description: When you have an application registered with PACE and you have logged in and out of Cisco PACE, a pop-up with following message displays: Your session has timed out. Please close this window and launch CiscoWorks in a new window.

WorkAround: None at this time You can safely ignore this message.


CSCtd80993—Fixing RA application registration

Description: The Cisco PACE Portal is installed over VC which is a combo VC server without Report Advisor (RA) locally installed. VC pointed to the remote RA. Non-existing RA must not be registered during Pace Portal install.

For CS with RA installed remotely—The Cisco PACE Portal installer will automatically register the local IP address for RA.

Workaround: Unregister the local RA from the Application Registration page and register the remote RA.

For AS with RA installed remotely—The Cisco PACE Portal installer will not be able to register the associated remote RA automatically.

WorkAround: Register the remote RA from the Application Registration page manually.


CSCte01066—Authentication error logging Pace Portal and VC

Description: By default on a VC Server, the maximum number of times the wrong username/password can be entered is three. After 3 attempts to log in, the user account will be locked.

WorkAround: Do the following.

1. Log in to the VC Server with System Admin privileges and navigate Tools  >System Administration.

2. In the displayed window, navigate Global  >User Management  >Authentication Servers.

3. Select the Authentication Server (Native Registry by default).

4. In the displayed screen uncheck Lock Users to avoid locking, or increase the value for Number of consecutive fails allowed from 3 to a value <1000.

In order to unlock a user whose user account is locked, do the following:

1. Login to the VC Server with System Admin privileges and navigate Tools >System Administration >Global >User Management >System Users.

2. Select the locked user, who can be identified with Lock symbol in the Lock column. Click Edit and uncheck the Lock User option.


CSCte15983—User is created in VC, but not in Pace Portal

Description: When a specific user is created on a VC server with a user name containing four characters or less, the corresponding user is not seen on the Cisco Pace Portal. This is because the Cisco PACE Portal only recognizes user names that contain more than four characters while this is allowed in VC.

Workaround: Create user names which contain more than four characters on all the servers registered with Cisco PACE 2.0-VC.


CSCte58698—Page cannot be displayed

Description: When you click on Getting Started with Cisco PACE Portal, the Contents window shows a Page cannot be displayed error.

WorkAround:- Click on the link on Getting Started with Cisco PACE Portal once and wait for the page to refresh. Sometimes you might have to wait a while for the page to refresh.


CSCte86656—More link page display empty table also table with title zero records.

Description: Login to the Cisco Pace Portal and click on the More link of any portlet. The resulting page is displayed with the correct table, title, and number of records. Leave the system logged in without any UI activity for sometime. Clicking the More link now displays an empty table, title, and zero records. Sometimes the correct table is displayed, but with the title as zero records.

WorkAround: Click the Refresh button on the portlets before clicking on the More link in each portlet.


CSCte87084—Pace Portal does not come up after backup/restore

Description: The Cisco Pace Portal stops working after backup and restore. Nothing comes up on the UI after entering login credentials.

WorkAround: Do the following:

Backup:

cd "C:\Program Files\CSCOpx\bin\"

perl.exe C:\Progra~1\CSCOpx\bin\backup.pl C:\pace\ppbackup

Restore:

net stop crmdmgtd

cd "C:\Program Files\CSCOpx\bin\"

perl.exe C:\Progra~1\CSCOpx\bin\restorebackup.pl -d C:\pace\ppbackup

net start crmdmgtd


CSCte91036—Error connecting when syslog server & client timestamp out of sync

Description: Error occurs when connecting to a database with an empty table.This has been seen for custom reports as well reports like Duplicate IP Address.

WorkAround: The timestamp of the devices sending syslogs and the Cisco PACE server should be synchronized. Incorrect or false timestamps will create this issue.


CSCtf11906—UI slows down almost to hang for 2 users.

Description: With a single user logged in to Cisco PACE, 2.0-VC, the CPU and other resource utilization responds appropriately. As the number of simultaneous users logged in increases, the UI slows down considerably.

WorkAround: To fix this issue, do the following:

1. Edit the following file:

C:\Program Files\CSCOpx\pace\config\paceconfig.properties

2. Change:

LOGLEVEL=INFO

to

LOGLEVEL=WARNING

3. Restart the Cisco PACE Portal and login to PACE portal. The problem will be resolved.


Known Limitations and Problems

This section contains information about the limitations and problems known to exist in Cisco PACE, 2.0-VC.

Cisco PACE Components Stop Working After Changing Server Hostname

Ensure that hostnames of the associated PACE servers are changed before installing the Cisco PACE Portal and PACE Components. If you change the hostnames after installing the Cisco PACE Portal and Components, you will need to reinstall Cisco PACE Portal and Components.

Cancelling Cisco PACE install/uninstall Leaves Server Unstable

Be aware that cancelling the Cisco PACE Portal installation or uninstallation before it is complete might leave your server unstable.

For RSS Portlets to Work in Cisco PACE Portal, You Need to Append the RSS Link

For RSS portlets to work in Cisco PACE Portal, you need to append the RSS link with the following:

http://<Proxy Server IP Address>:8080/-_-

For example, for the RSS link:

http://feeds.marketwatch.com/marketwatch/topstories/

to be able to work in Cisco PACE Portal, it must be modified to:

http://proxy-sjc-1:8080/-_-http://feeds.marketwatch.com/marketwatch/topstories/

Users and View Tabs Need to be Properly Associated

When a user with the proper privileges adds, edits, or deletes a portlet in the Cisco PACE Portal, the changes are visible to all other users.We recommend that you avoid adding portlets with sensitive data.

Accessing the Cisco PACE 2.0-VC Documentation Set

You can access the entire Cisco PACE, 2.0-VC documentation set from the following Cisco.com URL:

http://www.cisco.com/en/US/partner/products/ps10519/tsd_products_support_series_home.html

From here you can navigate to any documentation for Cisco PACE, 2.0-VC you will need. The documentation includes:

Documentation Guide for Cisco PACE Portal and Components 2.0-VC

Installation Guide for Cisco PACE Portal 2.0-VC

User Guide for Cisco PACE Portal 2.0-VC

Installation Guide for Cisco PACE Components 2.0-VC

User Guide for Cisco PACE Components 2.0-VC

In addition, the Cisco PACE Portal includes context-sensitive online help.


Note All documentation, including this document, the online help, and any or all of the parts of the Cisco PACE documentation set, might be upgraded over time. Therefore, we recommend you access the Cisco PACE documentation set using the Cisco.com URL: http://www.cisco.com/en/US/partner/products/ps10519/tsd_products_support_series_home.html


Obtaining Documentation, Obtaining Support, and Security Guidelines

For information on obtaining documentation, obtaining support, providing documentation feedback, security guidelines, and also recommended aliases and general Cisco documents, see the monthly What's New in Cisco Product Documentation, which also lists all new and revised Cisco technical documentation, at:

http://www.cisco.com/en/US/docs/general/whatsnew/whatsnew.html

Notices

The following notices pertain to this software license.

OpenSSL/Open SSL Project

This product includes software developed by the OpenSSL Project for use in the OpenSSL Toolkit (http://www.openssl.org/).

This product includes cryptographic software written by Eric Young (eay@cryptsoft.com).

This product includes software written by Tim Hudson (tjh@cryptsoft.com).

License Issues

The OpenSSL toolkit stays under a dual license, i.e. both the conditions of the OpenSSL License and the original SSLeay license apply to the toolkit. See below for the actual license texts. Actually both licenses are BSD-style Open Source licenses. In case of any license issues related to OpenSSL please contact openssl-core@openssl.org.

OpenSSL License:

Copyright © 1998-2007 The OpenSSL Project. All rights reserved.

Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:

1. Redistributions of source code must retain the copyright notice, this list of conditions and the following disclaimer.

2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions, and the following disclaimer in the documentation and/or other materials provided with the distribution.

3. All advertising materials mentioning features or use of this software must display the following acknowledgment: "This product includes software developed by the OpenSSL Project for use in the OpenSSL Toolkit (http://www.openssl.org/)".

4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to endorse or promote products derived from this software without prior written permission. For written permission, please contact openssl-core@openssl.org.

5. Products derived from this software may not be called "OpenSSL" nor may "OpenSSL" appear in their names without prior written permission of the OpenSSL Project.

6. Redistributions of any form whatsoever must retain the following acknowledgment:

"This product includes software developed by the OpenSSL Project for use in the OpenSSL Toolkit (http://www.openssl.org/)".

THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT "AS IS"' AND ANY EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.

This product includes cryptographic software written by Eric Young (eay@cryptsoft.com). This product includes software written by Tim Hudson (tjh@cryptsoft.com).

Original SSLeay License:

Copyright © 1995-1998 Eric Young (eay@cryptsoft.com). All rights reserved.

This package is an SSL implementation written by Eric Young (eay@cryptsoft.com).

The implementation was written so as to conform with Netscapes SSL.

This library is free for commercial and non-commercial use as long as the following conditions are adhered to. The following conditions apply to all code found in this distribution, be it the RC4, RSA, lhash, DES, etc., code; not just the SSL code. The SSL documentation included with this distribution is covered by the same copyright terms except that the holder is Tim Hudson (tjh@cryptsoft.com).

Copyright remains Eric Young's, and as such any Copyright notices in the code are not to be removed. If this package is used in a product, Eric Young should be given attribution as the author of the parts of the library used. This can be in the form of a textual message at program startup or in documentation (online or textual) provided with the package.

Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:

1. Redistributions of source code must retain the copyright notice, this list of conditions and the following disclaimer.

2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution.

3. All advertising materials mentioning features or use of this software must display the following acknowledgement:

"This product includes cryptographic software written by Eric Young (eay@cryptsoft.com)".

The word `cryptographic' can be left out if the routines from the library being used are not cryptography-related.

4. If you include any Windows specific code (or a derivative thereof) from the apps directory (application code) you must include an acknowledgement: "This product includes software written by Tim Hudson (tjh@cryptsoft.com)".

THIS SOFTWARE IS PROVIDED BY ERIC YOUNG "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.

The license and distribution terms for any publicly available version or derivative of this code cannot be changed. i.e. this code cannot simply be copied and put under another distribution license [including the GNU Public License].