Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Deep Security Agent (DSA) remote upgrade failure on Solaris 10 and 11 SPARC

    • Updated:
    • 21 Nov 2016
    • Product/Version:
    • Deep Security 9.0
    • Deep Security 9.5
    • Deep Security 9.6
    • Platform:
    • Oracle Solaris 11 SPARC
    • Oracle Solaris 11 x86
    • Unix - Solaris (Sun) version 10 (SunOS 5.10)
Summary

When upgrading DSA from the Deep Security Manager (DSM) console, the following symptoms are encountered:

  • DSM console shows the "Upgrading Software (Install Program Sent)" Agent status, and then change to "Software Update: Agent Software Failed (Upgrade failed)".

    Upgrading Agent

    Upgrade Failed

  • DSA Services and Agent side shows "Maintenance" when checked using the command "# svcs -a |grep ds".

    DSA Service Status

The issue happens because the DSA process is not shutdown properly during upgrade procedure.

Details
Public

As a workaround, fix the maintenance issue on DSA side and resume the update process. Do the following:

  1. Execute the commands below to fix the ds_agent (or ds_filter), and restore it from maintenance mode back to online mode.

    # svcadm clear ds_agent
    # svcadm refresh ds_agent
    # svcs -a |grep ds

    DSA Status: Online

  2. Check the DSA status on DSM console. The status will now show Managed (on-line), and Agent version will show the upgraded version (e.g. version 5344).
    DSA Status: Managed

    Version Updated

To upgrade DSA from the local machine, do the following:

 
To avoid the DSA remote upgrade failure, it is recommended to apply first the DSA HF 5390 (for Solaris 11 only) on the local Solaris machines. Once applied, remote upgrade for DSA with higher version will be successful.
  1. Copy DSA installation package to the Solaris machine with Root permission.
  2. Execute the commands below to upgrade DSA:

    For Solaris 10

    1. Create the install configuration file "ds_adm.file" with the following contents:
      mail=
      instance=overwrite
      partial=nocheck
      runlevel=quit
      idepend=nocheck
      rdepend=quit
      space=quit
      setuid=nocheck
      conflict=quit
      action=nocheck
      proxy=
      basedir=default
      
    2. Add the ds_adm.file install configuration file to the tmp folder.
    3. Execute update command: pkgadd -G -v -a /tmp/ds_adm.file -d Agent-Core-Solaris_5.10_U7-9.0.0-xxx.pkg

    For Solaris 11

    Execute the update command: pkg update -g file:///tmp/Agent-Solaris_5.11-9.0.0-xxx.p5p pkg:/security/ds-agent.

Premium
Internal
Rating:
Category:
Upgrade
Solution Id:
1115785
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support


To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.


Need More Help?

Create a technical support case if you need further support.