About this Document


This document provides installation instructions for ICM10.5(2) ES22. It also contains a list of ICM issues resolved by this engineering special. Please review all sections in this document pertaining to installation before installing the product. Failure to install this engineering special as described may result in inconsistent ICM behavior.

This document contains these sections:

Signup to Receive Email Notification of New Field Notices


The Product Alert Tool offers you the ability to set up one or more profiles that will enable you to receive email notification of new Field Notices, Product Alerts or End of Sale information for the products that you have selected.

The Product Alert Tool is available at http://www.cisco.com/cgi-bin/Support/FieldNoticeTool/field-notice

About Cisco ICM (and ICM Engineering Specials)


ICM Compatibility and Support Specifications


ICM Version Support

ICM 10.5(2)

ICM Component Support

Supported ICM Components

ICM10.5(2) ES22 is compatible with and should be installed on these ICM components:

Unsupported ICM Components

Do not install this engineering special on any components other than:

ICM Engineering Special Installation Planning


Installing ICM10.5(2) ES22


Installing ICM10.5(2) ES22

Installation of this patch requires all the ICM components (Router, Logger, Peripheral gateway, Distributor) to be shut down during the entire period of installation. It is always recommended to install this ES22 during a scheduled downtime. On a fully Duplex setup, the downtime could be minimized by applying this ES22 first on the inactive side and start it only after shutting down the active side where ES22 has to be applied next. This would be a case of manual failover where the inactive side would go active with the new ES22 patch.

·        Using the ICM Service Control, Stop the all processes (Router, Logger, Peripheral gateway, Distributor) on which you intend to install this patch.

·        Launch the Installer provided for ES22 and following the instructions on the screen.

·        Using the ICM Service Control, Start the processes on which you have installed this patch.

After installing this ES, do the following steps:

Generating SHA256-Certificates for Diagnostics Portico:

·        Open command prompt.

·        Set current path up to c:\icm\serviceability\diagnostics\bin.

·        Run command ‘DiagFwCertMgr.exe /task:CreateAndBindCert ’.

·        Launch Diagnostic portico framework and the certificate should be sha256.

Generating SHA256-Certificates for Web Setup, CCE Admin, and Internet Script Editor:

·        Open Cisco Unified CCE Tools and launch SSL encryption utility.

·        Go to the Certificate Administration tab and click on “Uninstall” to uninstall the existing certificate, which is currently sha1.

·        Click on “Install” to install certificate which is sha256.

·        Go to Configuration tab, Select ALL INSTANCES listed in the “Select Instance” list box and make sure “Enable Encryption” box is checked for the respective components such as WebSetup or ISE. Click on “Apply” to enable the SSL.

·        If there are other instances in the “Select Instance” list box other than ALL INSTANCES, repeat the above step to enable SSL for the components available for that instance.

·        Launch Web Setup and the certificate should be sha256.

Uninstall Directions for ICM10.5(2) ES22


To uninstall this patch, go to Control Panel. Select "Add or Remove Programs". Find the installed patch in the list and select "Remove".

Note: Patches have to be removed in the reverse order in which they were installed. For example, if you had installed patches 3, then 5, then 10 for a product, you will need to uninstall patches 10, 5 and 3 in that order to remove all patches for that product.

Removing this patch requires the all the ICM component (Router, Logger, Peripheral gateway, AW, Distributor) to be shutdown. It is always recommended to remove this ES during a scheduled downtime.

·        Using the ICM Service Control, Stop the all the process on the ICM machine where you intend to remove this patch.

·        From the system Control Panel, choose Add or Remove Programs to launch the Installer for ES and following the instructions on the screen to remove this patch.

·        Using the ICM Service Control, Start all the components in the ICM machine on which you have removed this patch.

 

Resolved Caveats in this Engineering Special


This section provides a list of significant ICM defects resolved by this engineering special. It contains these subsections:


Resolved Caveats in ICM10.5(2) ES22

This section lists caveats specifically resolved by ICM10.5(2) ES22.

Index of Resolved Caveats

Caveats in this section are ordered by ICM component, severity, and then identifier.

Identifier

Severity

Component

Headline

CSCux86640

6

security

SHA-256 security update for Diag Framework, Web Setup and ISE

Detailed list of Resolved Caveats in This Engineering Special

Caveats are ordered by severity then defect number.


Defect Number: CSCux86640

Component: security

Severity: 6

Headline: SHA-256 security update for Diag Framework, Web Setup and ISE

Symptom: The SHA certficate in use for Diag Framework, Web Setup and Internet Script Editor is SHA-1 currently, which needs to be updated to SHA-256 so that the software estate is protected from penetration and information disclosure.

Conditions:
Open Diag Framework, Web Setup,CCE Admin and Internet Script Editor .

Workaround: None

Further Problem Description:


Caveats resolved earlier and included as part of ICM10.5(2) ES22

 

There are no caveats resolved earlier to ICM10.5(2) ES22 and automatically included as part of the deliverables under this ES

Obtaining Documentation


The following sections provide sources for obtaining documentation from Cisco Systems.

World Wide Web

You can access the most current Cisco documentation on the World Wide Web at the following sites:

Documentation CD-ROM

Cisco documentation and additional literature are available in a CD-ROM package, which ships with your product. The Documentation CD-ROM is updated monthly and may be more current than printed documentation. The CD-ROM package is available as a single unit or as an annual subscription.

Ordering Documentation

Cisco documentation is available in the following ways:

Documentation Feedback

If you are reading Cisco product documentation on the World Wide Web, you can submit technical comments electronically. Click Feedback in the toolbar and select Documentation. After you complete the form, click Submit to send it to Cisco.

You can e-mail your comments to bug-doc@cisco.com.

To submit your comments by mail, use the response card behind the front cover of your document, or write to the following address:

Attn Document Resource Connection
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134-9883

We appreciate your comments.

Obtaining Technical Assistance


Cisco provides Cisco.com as a starting point for all technical assistance. Customers and partners can obtain documentation, troubleshooting tips, and sample configurations from online tools. For Cisco.com registered users, additional troubleshooting tools are available from the TAC website.

Cisco.com

Cisco.com is the foundation of a suite of interactive, networked services that provides immediate, open access to Cisco information and resources at anytime, from anywhere in the world. This highly integrated Internet application is a powerful, easy-to-use tool for doing business with Cisco.

Cisco.com provides a broad range of features and services to help customers and partners streamline business processes and improve productivity. Through Cisco.com, you can find information about Cisco and our networking solutions, services, and programs. In addition, you can resolve technical issues with online technical support, download and test software packages, and order Cisco learning materials and merchandise. Valuable online skill assessment, training, and certification programs are also available.

Customers and partners can self-register on Cisco.com to obtain additional personalized information and services. Registered users can order products, check on the status of an order, access technical support, and view benefits specific to their relationships with Cisco.

To access Cisco.com, go to: http://www.cisco.com

Technical Assistance Center

The Cisco TAC website is available to all customers who need technical assistance with a Cisco product or technology that is under warranty or covered by a maintenance contract.

Contacting TAC by Using the Cisco TAC Website

If you have a priority level 3 (P3) or priority level 4 (P4) problem, contact TAC by going to the TAC website: http://www.cisco.com/tac

P3 and P4 level problems are defined as follows:

In each of the above cases, use the Cisco TAC website to quickly find answers to your questions.

To register for Cisco.com, go to the following website: http://www.cisco.com/register/

If you cannot resolve your technical issue by using the TAC online resources, Cisco.com registered users can open a case online by using the TAC Case Open tool at the following website: http://www.cisco.com/tac/caseopen

Contacting TAC by Telephone

If you have a priority level 1(P1) or priority level 2 (P2) problem, contact TAC by telephone and immediately open a case. To obtain a directory of toll-free numbers for your country, go to the following website: http://www.cisco.com/warp/public/687/Directory/DirTAC.shtml

P1 and P2 level problems are defined as follows: