Re: [pca] Patch download fails

2015-03-27 Thread Martin Paul
I don't think that Oracle will (soon) fix the problem on their side, so 
I pushed out a new stable version of PCA with the previously mentioned 
changes.


If you are using /usr/sfw/bin/wget from stock Solaris, SSL certs will 
not be verified as of now. Depending on how paranoid you are, install 
and use a local version of wget > 1.12 to avoid this.


Martin.



Re: [pca] Patch download fails

2015-03-25 Thread Martin Paul
I'm now in contact with Don O'Malley from Oracle and sent him details 
about the issue. I will delay the publishing of a new stable version of 
PCA until I know if and what Oracle will do about it.


Until then, feel free to use the development version of PCA and report 
any problems you should have with that.


Martin.



Re: [pca] Patch download fails

2015-03-24 Thread Martin Paul

Am 24.03.2015 um 14:52 schrieb Glen Gunselman:

I do not remember whether the listserv allows attachments but I ran the current 
dev pca on x86 Solaris 10 (so I used 151616) - the output is attached.


Thanks Glen!

So the development version of PCA works on a Solaris 10 with the stock 
wget command again. It doesn't verify all certificates anymore, but this 
can't be fixed without the help of Oracle. Paranoid users should install 
and use a local version of wget > 1.12, which would be more secure.


I'll wait till tomorrow, but if I don't get any reports of the 
development version of PCA *not* working on somebodies system, I'll push 
out a new stable version.


Martin.



Re: [pca] Patch download fails

2015-03-24 Thread Martin Paul

Am 24.03.2015 um 11:31 schrieb Chuck Floyd:

The wget version is 1.12 with patch 125215-05 on Solaris 10 SPARC.  No joy.


Thanks for taking a look. I kind of expected that :-/

So Oracle should either change the certificate or provide an updated 
version of wget. The first option would be better, as everything would 
immediately work again on all systems. The second option would require 
an install of a new wget patch on all systems to make it work again. We 
probably will see neither of these solutions.


Martin.



Re: [pca] Patch download fails

2015-03-24 Thread Glen Gunselman
Martin,

I do not remember whether the listserv allows attachments but I ran the current 
dev pca on x86 Solaris 10 (so I used 151616) - the output is attached.

Thanks,
Glen

-Original Message-
From: pca [mailto:[email protected]] On Behalf Of Martin Paul
Sent: Tuesday, March 24, 2015 2:59 AM
To: PCA (Patch Check Advanced) Discussion
Subject: Re: [pca] Patch download fails

Thanks Jan for the detailed analysis, that makes perfect sense!

I have made two changes to the development version of PCA:

   http://www.par.univie.ac.at/solaris/pca/develop/pca

   - Add the GeoTrust CA cert
   - Use --no-check-certificate with wget versions <= 1.12

The bug with recognizing alternative names in certs seems to be fixed in 
wget 1.13.1 onwards.

For wget versions <= 1.12 I have no choice but turning off certificate 
checks. That's ugly, but if Oracle doesn't change the certificate, there 
is no other choice.

Can somebody please check whether the latest wget patches for Solaris 
(125215-05 and 125216-05) provide a version of wget newer than 1.12, and 
if so, whether patch downloads work with the current development version 
of PCA?

I'd also like to encourage anybody to test the new version with other 
versions of wget, and see whether it works in all environments. If patch 
downloads fail, please post output of "pca --debug -d 151615-01".

Best,
Martin.

sudo ~/pcatest --debug -d 151616-01 --xrefdir="/var/tmp/pcatmp" 
--patchdir="/var/tmp/pcatmp"
Option download: 1
Option xrefdir: /var/tmp/pcatmp
Option patchdir: /var/tmp/pcatmp
Option debug: 1
Command: /home/gunselmg/pcatest
ARGV: 151616-01
Version: 20150324-01
CWD: /home/gunselmg
Found /usr/sfw/bin/wget (1.12, 11200, https)
Using /usr/sfw/bin/wget
Found /usr/bin/uname
Prerequisites for threads not met, setting threads to 0
Never update
Expanded patch list: 151616-01
xref mtime: Mon Mar 23 21:51:05 2015
xref now  : Tue Mar 24 08:46:39 2015
xref ctime: Tue Mar 24 08:40:53 2015
xref age  : 346
Local file /var/tmp/pcatmp/patchdiag.xref is up to date
osname from uname: SunOS
Reading from /usr/bin/showrev -p  2>/dev/null
patchdiag.xref size: 2319110
Using /var/tmp/pcatmp/patchdiag.xref from Mar/23/15
All operands are fully qualified patch IDs plus revisions
Host: beaker (SunOS 5.10/Generic_150401-17/i386/i86pc)
List: 151616-01 (1/0)

Patch  IR   CR RSB Age Synopsis
-- -- - -- --- --- ---
151616 -- < 01 R--  10 SunOS 5.10_x86: fcp patch

Looking for 151616-01 (1/1)
Trying Oracle

Please enter My Oracle Support Account User: x
Please enter My Oracle Support Account Password:

Trying https://getupdates.oracle.com/ (1/1)
src: oracle, srcurl:
Adding to /tmp/pca.834122: header=Authorization: Basic 
/usr/sfw/bin/wget --progress=dot:binary --ca-certificate=/home/gunselmg/pcatest 
--no-check-certificate --secure-protocol=TLSv1 -O /var/tmp/pcatmp/151616-01.zip 
"https://getupdates.oracle.com/all_unsigned/151616-01.zip";
--2015-03-24 08:47:22--  
https://getupdates.oracle.com/all_unsigned/151616-01.zip
Resolving getupdates.oracle.com... 141.146.44.51
Connecting to getupdates.oracle.com|141.146.44.51|:443... connected.
HTTP request sent, awaiting response... 301 Moved Permanently
Cookie coming from updates.oracle.com attempted to set domain to 
updates.oracle.com
Location: 
https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login?site2pstoretoken=v1.2~E4066BF0~7973EDCCC7676D5131DC3CB89FC703B8A50E56110A28E6BEC73AB9FC226E462809BE21F38034C504C5E78D7AA68B6D81CC011E23F2DC5C9971A1C3C8D329C9AA94242F320573B7C536D11AE8BF4D2061B4B42C5B5391182F29DC70BA0174C9B88A9A466F75967FDA9CCC2C57D5D133512D8FA53EC9249B64AC0734929B373A9AF3227FD8587F658080C80DEF7EA311C4D06B8C3C1E41E73696179CB467D9B74D3FA35273D87844223DD24CF11C2DB9E451CF8D4C11D4ACC1FBFF63A3A94D7759
 [following]
--2015-03-24 08:47:23--  
https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login?site2pstoretoken=v1.2~E4066BF0~7973EDCCC7676D5131DC3CB89FC703B8A50E56110A28E6BEC73AB9FC226E462809BE21F38034C504C5E78D7AA68B6D81CC011E23F2DC5C9971A1C3C8D329C9AA94242F320573B7C536D11AE8BF4D2061B4B42C5B5391182F29DC70BA0174C9B88A9A466F75967FDA9CCC2C57D5D133512D8FA53EC9249B64AC0734929B373A9AF3227FD8587F658080C80DEF7EA311C4D06B8C3C1E41E73696179CB467D9B74D3FA35273D87844223DD24CF11C2DB9E451CF8D4C11D4ACC1FBFF63A3A94D7759
Resolving login.oracle.com... 209.17.4.8
Connecting to login.oracle.com|209.17.4.8|:443... connected.
HTTP request sent, awaiting response... 302 Moved Temporarily
Location: 
https://updates.oracle.com/osso_login_success?urlc=v1.2%7ED9C6954E588E6E09A9829821A9844A75D18EBC3C9458252234D4E895B9C754E09A510205ED1727EC7FD19F36EB74088BFBE45850CE107E46D884FC4D5D1C494FA2825B599B3E58396EFBED0CBD92E255F095D4BB5653841DAEFB19FC38

Re: [pca] Patch download fails

2015-03-24 Thread Chuck Floyd
The wget version is 1.12 with patch 125215-05 on Solaris 10 SPARC.  No joy.

On Tue, Mar 24, 2015 at 3:59 AM, Martin Paul 
wrote:

> Thanks Jan for the detailed analysis, that makes perfect sense!
>
> I have made two changes to the development version of PCA:
>
>   http://www.par.univie.ac.at/solaris/pca/develop/pca
>
>   - Add the GeoTrust CA cert
>   - Use --no-check-certificate with wget versions <= 1.12
>
> The bug with recognizing alternative names in certs seems to be fixed in
> wget 1.13.1 onwards.
>
> For wget versions <= 1.12 I have no choice but turning off certificate
> checks. That's ugly, but if Oracle doesn't change the certificate, there is
> no other choice.
>
> Can somebody please check whether the latest wget patches for Solaris
> (125215-05 and 125216-05) provide a version of wget newer than 1.12, and if
> so, whether patch downloads work with the current development version of
> PCA?
>
> I'd also like to encourage anybody to test the new version with other
> versions of wget, and see whether it works in all environments. If patch
> downloads fail, please post output of "pca --debug -d 151615-01".
>
> Best,
> Martin.
>
>


Re: [pca] Patch download fails

2015-03-24 Thread Martin Paul

Thanks Jan for the detailed analysis, that makes perfect sense!

I have made two changes to the development version of PCA:

  http://www.par.univie.ac.at/solaris/pca/develop/pca

  - Add the GeoTrust CA cert
  - Use --no-check-certificate with wget versions <= 1.12

The bug with recognizing alternative names in certs seems to be fixed in 
wget 1.13.1 onwards.


For wget versions <= 1.12 I have no choice but turning off certificate 
checks. That's ugly, but if Oracle doesn't change the certificate, there 
is no other choice.


Can somebody please check whether the latest wget patches for Solaris 
(125215-05 and 125216-05) provide a version of wget newer than 1.12, and 
if so, whether patch downloads work with the current development version 
of PCA?


I'd also like to encourage anybody to test the new version with other 
versions of wget, and see whether it works in all environments. If patch 
downloads fail, please post output of "pca --debug -d 151615-01".


Best,
Martin.



Re: [pca] Patch download fails

2015-03-23 Thread Ken Herold
Solved mine, too.  Thanks!!

On Mon, Mar 23, 2015 at 2:27 PM, Jan Holzhüter  wrote:

> Hi,
>
> Am 23.03.15 um 17:23 schrieb Chuck Floyd:
> > same result with 1.16.3 from opencsw
>
> one peace is missing in the pca script. The root Certifitcate from Geo
> Trust. Matrin only added the intermediate one
>
> https://de.ssl-tools.net/certificates/casgk1-geotrust-global-ca
>
> If you add
>
> -BEGIN CERTIFICATE-
> MIIDVDCCAjygAwIBAgIDAjRWMA0GCSqGSIb3DQEBBQUAMEIxCzAJBgNVBAYT
> AlVTMRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMRswGQYDVQQDExJHZW9UcnVz
> dCBHbG9iYWwgQ0EwHhcNMDIwNTIxMDQwMDAwWhcNMjIwNTIxMDQwMDAwWjBC
> MQswCQYDVQQGEwJVUzEWMBQGA1UEChMNR2VvVHJ1c3QgSW5jLjEbMBkGA1UE
> AxMSR2VvVHJ1c3QgR2xvYmFsIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
> MIIBCgKCAQEA2swYYzD99BcjGlZ+W988bDjkcbd4kdS8odhM+KhDtgPpTSEH
> CIjaWC9mOSm9BXiLnTjoBbdqfnGk5sRgprDvgOSJKA+eJdbtg/OtppHHmMlC
> GDUUna2YRpIuT8rxh0PBFpVXLVDviS2Aelet8u5fa9IAjbkU+BQVNdnARqN7
> csiRv8lVK83Qlz6cJmTM386DGXHKTubU1XupGc1V3sjs0l44U+VcT4wt/lAj
> Nvxm5suOpDkZALeVAjmRCw7+OC7RHQWa9k0+bw8HHa8sHo9gOeL6NlMTOdRe
> JivbPagUvTLrGAMoUgRx5aszPeE4uwc2hGKceeoWMPRfwCvocWvk+QIDAQAB
> o1MwUTAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTAephojYn7qwVkDBF9
> qn1luMrMTjAfBgNVHSMEGDAWgBTAephojYn7qwVkDBF9qn1luMrMTjANBgkq
> hkiG9w0BAQUFAAOCAQEANeMpauUvXVSOKVCUn5kaFOSPeCpilKInZ57Qzxpe
> R+nBsqTP3UEaBU6bS+5Kb1VSsyShNwrrZHYqLizz/Tt1kL/6cdjHPTfStQWV
> Yrmm3ok9Nns4d0iXrKYgjy6myQzCsplFAMfOEVEiIuCl6rYVSAlk6l5PdPcF
> PseKUgzbFbS9bZvlxrFUaKnjaZC2mqUPuLk/IH2uSrW4nOQdtqvmlKXBx4Ot
> 2/Unhw4EbNX/3aBd7YdStysVAq45pmp06drE57xNNB6pXE0zX5IJL4hmXXeX
> xx12E6nV5fEWCRE11azbJHFwLJhWC9kXtNHjUStedejV0NxPNO3CBWaAocvm
> Mw==
> -END CERTIFICATE-
>
> at the end of the script it does work (with the latest Version wget
> Version from opencsw. (The Oracle Provided on in /usr/sfw/bin/ still
> suffers the SAN Problem as it seems)
>
>
> Hope that helps.
>
> Greetings
> Jan
>
>
>
>
>


-- 
Ken Herold
Director, Library Information Systems
Hamilton College
198 College Hill Road
Clinton, NY 13323
315-859-4487
[email protected]


Re: [pca] Patch download fails

2015-03-23 Thread Chuck Floyd
This works with wget vers 1.15 from my Linux desktop with the additional
cert.

On Mon, Mar 23, 2015 at 2:27 PM, Jan Holzhüter  wrote:

> Hi,
>
> Am 23.03.15 um 17:23 schrieb Chuck Floyd:
> > same result with 1.16.3 from opencsw
>
> one peace is missing in the pca script. The root Certifitcate from Geo
> Trust. Matrin only added the intermediate one
>
> https://de.ssl-tools.net/certificates/casgk1-geotrust-global-ca
>
> If you add
>
> -BEGIN CERTIFICATE-
> MIIDVDCCAjygAwIBAgIDAjRWMA0GCSqGSIb3DQEBBQUAMEIxCzAJBgNVBAYT
> AlVTMRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMRswGQYDVQQDExJHZW9UcnVz
> dCBHbG9iYWwgQ0EwHhcNMDIwNTIxMDQwMDAwWhcNMjIwNTIxMDQwMDAwWjBC
> MQswCQYDVQQGEwJVUzEWMBQGA1UEChMNR2VvVHJ1c3QgSW5jLjEbMBkGA1UE
> AxMSR2VvVHJ1c3QgR2xvYmFsIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
> MIIBCgKCAQEA2swYYzD99BcjGlZ+W988bDjkcbd4kdS8odhM+KhDtgPpTSEH
> CIjaWC9mOSm9BXiLnTjoBbdqfnGk5sRgprDvgOSJKA+eJdbtg/OtppHHmMlC
> GDUUna2YRpIuT8rxh0PBFpVXLVDviS2Aelet8u5fa9IAjbkU+BQVNdnARqN7
> csiRv8lVK83Qlz6cJmTM386DGXHKTubU1XupGc1V3sjs0l44U+VcT4wt/lAj
> Nvxm5suOpDkZALeVAjmRCw7+OC7RHQWa9k0+bw8HHa8sHo9gOeL6NlMTOdRe
> JivbPagUvTLrGAMoUgRx5aszPeE4uwc2hGKceeoWMPRfwCvocWvk+QIDAQAB
> o1MwUTAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTAephojYn7qwVkDBF9
> qn1luMrMTjAfBgNVHSMEGDAWgBTAephojYn7qwVkDBF9qn1luMrMTjANBgkq
> hkiG9w0BAQUFAAOCAQEANeMpauUvXVSOKVCUn5kaFOSPeCpilKInZ57Qzxpe
> R+nBsqTP3UEaBU6bS+5Kb1VSsyShNwrrZHYqLizz/Tt1kL/6cdjHPTfStQWV
> Yrmm3ok9Nns4d0iXrKYgjy6myQzCsplFAMfOEVEiIuCl6rYVSAlk6l5PdPcF
> PseKUgzbFbS9bZvlxrFUaKnjaZC2mqUPuLk/IH2uSrW4nOQdtqvmlKXBx4Ot
> 2/Unhw4EbNX/3aBd7YdStysVAq45pmp06drE57xNNB6pXE0zX5IJL4hmXXeX
> xx12E6nV5fEWCRE11azbJHFwLJhWC9kXtNHjUStedejV0NxPNO3CBWaAocvm
> Mw==
> -END CERTIFICATE-
>
> at the end of the script it does work (with the latest Version wget
> Version from opencsw. (The Oracle Provided on in /usr/sfw/bin/ still
> suffers the SAN Problem as it seems)
>
>
> Hope that helps.
>
> Greetings
> Jan
>
>
>
>
>


Re: [pca] Patch download fails

2015-03-23 Thread Jan Holzhüter
Hi,

Am 23.03.15 um 17:23 schrieb Chuck Floyd:
> same result with 1.16.3 from opencsw

one peace is missing in the pca script. The root Certifitcate from Geo
Trust. Matrin only added the intermediate one

https://de.ssl-tools.net/certificates/casgk1-geotrust-global-ca

If you add

-BEGIN CERTIFICATE-
MIIDVDCCAjygAwIBAgIDAjRWMA0GCSqGSIb3DQEBBQUAMEIxCzAJBgNVBAYT
AlVTMRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMRswGQYDVQQDExJHZW9UcnVz
dCBHbG9iYWwgQ0EwHhcNMDIwNTIxMDQwMDAwWhcNMjIwNTIxMDQwMDAwWjBC
MQswCQYDVQQGEwJVUzEWMBQGA1UEChMNR2VvVHJ1c3QgSW5jLjEbMBkGA1UE
AxMSR2VvVHJ1c3QgR2xvYmFsIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEA2swYYzD99BcjGlZ+W988bDjkcbd4kdS8odhM+KhDtgPpTSEH
CIjaWC9mOSm9BXiLnTjoBbdqfnGk5sRgprDvgOSJKA+eJdbtg/OtppHHmMlC
GDUUna2YRpIuT8rxh0PBFpVXLVDviS2Aelet8u5fa9IAjbkU+BQVNdnARqN7
csiRv8lVK83Qlz6cJmTM386DGXHKTubU1XupGc1V3sjs0l44U+VcT4wt/lAj
Nvxm5suOpDkZALeVAjmRCw7+OC7RHQWa9k0+bw8HHa8sHo9gOeL6NlMTOdRe
JivbPagUvTLrGAMoUgRx5aszPeE4uwc2hGKceeoWMPRfwCvocWvk+QIDAQAB
o1MwUTAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTAephojYn7qwVkDBF9
qn1luMrMTjAfBgNVHSMEGDAWgBTAephojYn7qwVkDBF9qn1luMrMTjANBgkq
hkiG9w0BAQUFAAOCAQEANeMpauUvXVSOKVCUn5kaFOSPeCpilKInZ57Qzxpe
R+nBsqTP3UEaBU6bS+5Kb1VSsyShNwrrZHYqLizz/Tt1kL/6cdjHPTfStQWV
Yrmm3ok9Nns4d0iXrKYgjy6myQzCsplFAMfOEVEiIuCl6rYVSAlk6l5PdPcF
PseKUgzbFbS9bZvlxrFUaKnjaZC2mqUPuLk/IH2uSrW4nOQdtqvmlKXBx4Ot
2/Unhw4EbNX/3aBd7YdStysVAq45pmp06drE57xNNB6pXE0zX5IJL4hmXXeX
xx12E6nV5fEWCRE11azbJHFwLJhWC9kXtNHjUStedejV0NxPNO3CBWaAocvm
Mw==
-END CERTIFICATE-

at the end of the script it does work (with the latest Version wget
Version from opencsw. (The Oracle Provided on in /usr/sfw/bin/ still
suffers the SAN Problem as it seems)


Hope that helps.

Greetings
Jan






signature.asc
Description: OpenPGP digital signature


Re: [pca] Patch download fails

2015-03-23 Thread Chuck Floyd
same result with 1.16.3 from opencsw

On Mon, Mar 23, 2015 at 11:37 AM, Ken Herold  wrote:

> Upgraded to GNU Wget 1.15 built on solaris2.10
>
> getting same errors.
>
> On Mon, Mar 23, 2015 at 10:41 AM, Jan Holzhueter 
> wrote:
>
>> Hi,
>>
>> Am 23.03.15 um 14:55 schrieb Martin Paul:
>> > Am 23.03.2015 um 14:27 schrieb Ken Herold:
>> >> I get for example:
>> >>
>> >> Resolving aru-akam-secure.oracle.com... 104.64.51.207
>> >> Connecting to aru-akam-secure.oracle.com|104.64.51.207|:443...
>> connected.
>> >> ERROR: cannot verify aru-akam-secure.oracle.com's certificate, issued
>> by
>> >> `/C=US/O=GeoTrust, Inc./CN=GeoTrust SSL CA':
>> >>Unable to locally verify the issuer's authority.
>> >
>> > Thanks!
>> >
>> >> ERROR: certificate common name `download-secure.oracle.com' doesn't
>> match
>> >> requested host name `aru-akam-secure.oracle.com'.
>> >
>> > I'm not sure whether this a problem with the certificate itself or with
>> > wget. Anybody?
>>
>> the cert looks ok it does have a Common name and a few Alternatives
>> Names: (SAN)
>>
>> Common namesdownload-secure.oracle.com
>> Alternative names   epd-akam-intl-secure.oracle.com
>> epd-akam-us-secure.oracle.com dev-epd-akam-intl-secure.oracle.com
>> dev-epd-akam-us-secure.oracle.com aru-akam-secure.oracle.com
>> failover-aru-akam-secure.oracle.com dev-aru-akam-secure.oracle.com
>> failover-dev-aru-akam-secure.oracle.com download-secure.oracle.com
>>
>> https://www.ssllabs.com/ssltest/analyze.html?d=aru-akam-secure.oracle.com
>>
>> Checking here: https://bugzilla.redhat.com/show_bug.cgi?id=674186
>>
>> Looks like older wget dosn't work with SAN certificates.
>>
>> so either update wget or use --no-check-certificate (which of cause is
>> not nice)
>>
>> Greetings
>> Jan
>>
>>
>>
>>
>>
>>
>> --
>> Jan Holzhüter   Baltic Online Computer GmbH
>> Firmensitz: Koppelberg 4-6, 24159 Kiel
>> http://www.baltic-online.deTel.: +49 (0)431 54003-0
>> Geschäftsführer:Erik Cickovskis, Amtsgericht Kiel, HRB 3756
>>
>>
>
>
> --
> Ken Herold
> Director, Library Information Systems
> Hamilton College
> 198 College Hill Road
> Clinton, NY 13323
> 315-859-4487
> [email protected]
>


Re: [pca] Patch download fails

2015-03-23 Thread Ken Herold
Upgraded to GNU Wget 1.15 built on solaris2.10

getting same errors.

On Mon, Mar 23, 2015 at 10:41 AM, Jan Holzhueter 
wrote:

> Hi,
>
> Am 23.03.15 um 14:55 schrieb Martin Paul:
> > Am 23.03.2015 um 14:27 schrieb Ken Herold:
> >> I get for example:
> >>
> >> Resolving aru-akam-secure.oracle.com... 104.64.51.207
> >> Connecting to aru-akam-secure.oracle.com|104.64.51.207|:443...
> connected.
> >> ERROR: cannot verify aru-akam-secure.oracle.com's certificate, issued
> by
> >> `/C=US/O=GeoTrust, Inc./CN=GeoTrust SSL CA':
> >>Unable to locally verify the issuer's authority.
> >
> > Thanks!
> >
> >> ERROR: certificate common name `download-secure.oracle.com' doesn't
> match
> >> requested host name `aru-akam-secure.oracle.com'.
> >
> > I'm not sure whether this a problem with the certificate itself or with
> > wget. Anybody?
>
> the cert looks ok it does have a Common name and a few Alternatives
> Names: (SAN)
>
> Common namesdownload-secure.oracle.com
> Alternative names   epd-akam-intl-secure.oracle.com
> epd-akam-us-secure.oracle.com dev-epd-akam-intl-secure.oracle.com
> dev-epd-akam-us-secure.oracle.com aru-akam-secure.oracle.com
> failover-aru-akam-secure.oracle.com dev-aru-akam-secure.oracle.com
> failover-dev-aru-akam-secure.oracle.com download-secure.oracle.com
>
> https://www.ssllabs.com/ssltest/analyze.html?d=aru-akam-secure.oracle.com
>
> Checking here: https://bugzilla.redhat.com/show_bug.cgi?id=674186
>
> Looks like older wget dosn't work with SAN certificates.
>
> so either update wget or use --no-check-certificate (which of cause is
> not nice)
>
> Greetings
> Jan
>
>
>
>
>
>
> --
> Jan Holzhüter   Baltic Online Computer GmbH
> Firmensitz: Koppelberg 4-6, 24159 Kiel
> http://www.baltic-online.deTel.: +49 (0)431 54003-0
> Geschäftsführer:Erik Cickovskis, Amtsgericht Kiel, HRB 3756
>
>


-- 
Ken Herold
Director, Library Information Systems
Hamilton College
198 College Hill Road
Clinton, NY 13323
315-859-4487
[email protected]


Re: [pca] Patch download fails

2015-03-23 Thread Jan Holzhueter
Hi,

Am 23.03.15 um 14:55 schrieb Martin Paul:
> Am 23.03.2015 um 14:27 schrieb Ken Herold:
>> I get for example:
>>
>> Resolving aru-akam-secure.oracle.com... 104.64.51.207
>> Connecting to aru-akam-secure.oracle.com|104.64.51.207|:443... connected.
>> ERROR: cannot verify aru-akam-secure.oracle.com's certificate, issued by
>> `/C=US/O=GeoTrust, Inc./CN=GeoTrust SSL CA':
>>Unable to locally verify the issuer's authority.
> 
> Thanks!
> 
>> ERROR: certificate common name `download-secure.oracle.com' doesn't match
>> requested host name `aru-akam-secure.oracle.com'.
> 
> I'm not sure whether this a problem with the certificate itself or with
> wget. Anybody?

the cert looks ok it does have a Common name and a few Alternatives
Names: (SAN)

Common namesdownload-secure.oracle.com
Alternative names   epd-akam-intl-secure.oracle.com
epd-akam-us-secure.oracle.com dev-epd-akam-intl-secure.oracle.com
dev-epd-akam-us-secure.oracle.com aru-akam-secure.oracle.com
failover-aru-akam-secure.oracle.com dev-aru-akam-secure.oracle.com
failover-dev-aru-akam-secure.oracle.com download-secure.oracle.com

https://www.ssllabs.com/ssltest/analyze.html?d=aru-akam-secure.oracle.com

Checking here: https://bugzilla.redhat.com/show_bug.cgi?id=674186

Looks like older wget dosn't work with SAN certificates.

so either update wget or use --no-check-certificate (which of cause is
not nice)

Greetings
Jan






-- 
Jan Holzhüter   Baltic Online Computer GmbH
Firmensitz: Koppelberg 4-6, 24159 Kiel
http://www.baltic-online.deTel.: +49 (0)431 54003-0
Geschäftsführer:Erik Cickovskis, Amtsgericht Kiel, HRB 3756



Re: [pca] Patch download fails

2015-03-23 Thread Martin Paul

Am 23.03.2015 um 14:27 schrieb Ken Herold:

I get for example:

Resolving aru-akam-secure.oracle.com... 104.64.51.207
Connecting to aru-akam-secure.oracle.com|104.64.51.207|:443... connected.
ERROR: cannot verify aru-akam-secure.oracle.com's certificate, issued by
`/C=US/O=GeoTrust, Inc./CN=GeoTrust SSL CA':
   Unable to locally verify the issuer's authority.


Thanks!


ERROR: certificate common name `download-secure.oracle.com' doesn't match
requested host name `aru-akam-secure.oracle.com'.


I'm not sure whether this a problem with the certificate itself or with 
wget. Anybody?


I've forwarded the problem to Don O'Malley, too. Hope he still works for 
Oracle in this area.


Best,
Martin.



Re: [pca] Patch download fails

2015-03-23 Thread Ken Herold
I get for example:

Resolving aru-akam-secure.oracle.com... 104.64.51.207
Connecting to aru-akam-secure.oracle.com|104.64.51.207|:443... connected.
ERROR: cannot verify aru-akam-secure.oracle.com's certificate, issued by
`/C=US/O=GeoTrust, Inc./CN=GeoTrust SSL CA':
  Unable to locally verify the issuer's authority.
ERROR: certificate common name `download-secure.oracle.com' doesn't match
requested host name `aru-akam-secure.oracle.com'.
To connect to aru-akam-secure.oracle.com insecurely, use
`--no-check-certificate'.
Removing /tmp/pca.412347
Failed (Unknown Error)
Failed (patch not found)



On Mon, Mar 23, 2015 at 9:06 AM, Martin Paul 
wrote:

> Thanks for providing the docs, Daniel!
>
> Doesn't look as if they were updated. Doc ID 1199543.1 (Patch download
> automation for Sun products using wget) was last updated 11-Feb-2014 and it
> does only mention the known certificates. Just to be sure - could
> you/somebody download and post getupdates.pem mentioned in that doc?
>
> BTW - Bernd Senf said that "--wgetopt=--secure-protocol=TLSv1" was
> required for patch downloads to work as well - are you using a local copy
> of wget or the one provided with Solaris? See this note in the above
> document:
>
> IMPORTANT:
>
> "https://getupdates.oracle.com web server does not fully support TLS 1.2.
> Only OpenSSL versions from branch 1.0.0 will work - Oracle Solaris does not
> deliver higher versions at this time. Customers who are trying to access
> the URL using latest wget/OpenSSL (ie. from www.opencsw.org) version with
> TLS 1.2 support may get connection failures."
>
> Best,
> Martin.
>
>
>


-- 
Ken Herold
Director, Library Information Systems
Hamilton College
198 College Hill Road
Clinton, NY 13323
315-859-4487
[email protected]


Re: [pca] Patch download fails

2015-03-23 Thread Martin Paul

Thanks for providing the docs, Daniel!

Doesn't look as if they were updated. Doc ID 1199543.1 (Patch download 
automation for Sun products using wget) was last updated 11-Feb-2014 and 
it does only mention the known certificates. Just to be sure - could 
you/somebody download and post getupdates.pem mentioned in that doc?


BTW - Bernd Senf said that "--wgetopt=--secure-protocol=TLSv1" was 
required for patch downloads to work as well - are you using a local 
copy of wget or the one provided with Solaris? See this note in the 
above document:


IMPORTANT:

"https://getupdates.oracle.com web server does not fully support TLS 
1.2. Only OpenSSL versions from branch 1.0.0 will work - Oracle Solaris 
does not deliver higher versions at this time. Customers who are trying 
to access the URL using latest wget/OpenSSL (ie. from www.opencsw.org) 
version with TLS 1.2 support may get connection failures."


Best,
Martin.




Re: [pca] Patch download fails

2015-03-23 Thread Martin Paul
Seems as if a new server is involved during patch downloads, which PCA 
doesn't know about. I have now added the new SSL certificates to the 
development verson of PCA:


  http://www.par.univie.ac.at/solaris/pca/develop/pca

Unfortunately I do not have a MOS account anymore, so I cannot do any 
patch download tests myself. Could somebody please try the development 
version of PCA and tell me if patch downloads work again?


If it doesn't work, please post debug output of the attempt to the list.

It would also be great if somebody could check whether these documents 
were updated recently (I can't even look at those without a MOS account):


- Solaris 10 patch access
https://supporthtml.oracle.com/ep/faces/secure/km/DocumentDisplay.jspx?id=1006630.1&h=Y

- Patch download automation for Sun products using wget
https://supporthtml.oracle.com/ep/faces/secure/km/DocumentDisplay.jspx?id=1199543.1&h=Y

Best,
Martin.



Re: [pca] patch download

2015-02-19 Thread Martin Paul

Am 19.02.2015 um 01:31 schrieb Tim Hosfelt:

Is there a way to download a list of patches.  Due to security/firewalls I
can only set up one server to point to oracle and I would like to use that
server to download all the needed patches in the environment.  My hope is
to run the "pca --list missing" on all servers in my environment and then
create a list of unique patch ID's I can download to the server.  Put the
into an NFS share and patch all my servers from that share (I also can't
set up an apache server due to other security restrictions).


A local caching proxy would be the easiest solution, but you would need 
an HTTP server on the system which points to Oracle for that. 
Fortunately there are other options:


You can indeed create an NFS shared directory which you fill on the 
system which can connect to Oracle, and then share and use it on the 
clients with PCAs "--patchurl file:/nfs/pca/patches" option (use 
"xrefurl" for a central source of the patchdiag.xref file as well).


To pre-download the actually required patches on your local patch server 
it's best to use the method described under "CREATING PATCH REPORTS FOR 
REMOTE MACHINES" in the PCA docs. It allows you to run pca with all its 
options on the server with the package/patch information from the 
client. You would collect the output of uname/showrev/pkginfo from all 
clients on the server (maybe use NFS again), and then run "pca 
--fromfiles /nfs/hostA --download missing" in /nfs/pca/patches for all 
your hosts. At the end you will have a local collection of all patches 
missing on all clients.


hth,
Martin.



Re: [pca] EXTERNAL: Re: pca patch download fails with Unknown error/patch not found

2011-09-01 Thread Faulconer, Steven M
Lisa,

 

In the upper part of 'pca -V' it shows which versions of wget PCA finds, do
one of them support https?

 

The output looks similar to:

 

Found /usr/sfw/bin/wget (1.12, 11200, https)

Found /usr/local/bin/wget (1.11.4, 11104, http)

Using /usr/sfw/bin/wget

 

 

From: [email protected] [mailto:[email protected]]
On Behalf Of Becktold, Lisa M. (LARC-B7)[Chugach Federal Solutions, Inc.]
Sent: Thursday, September 01, 2011 4:39 PM
To: PCA (Patch Check Advanced) Discussion
Subject: EXTERNAL: Re: [pca] pca patch download fails with Unknown
error/patch not found

 

I ran a pca "pretend" install with the verbal option.  This may be a problem
with my server or firewall entry - I'm seeing "Unable to establish SSL
connection".

 

Here's output of "pca.perl -I missingrs -V":

 

Host: eris (SunOS 5.10/Generic_139555-08/sparc/sun4v)

List: missingrs (167/51444)

 

Patch  IR   CR RSB Age Synopsis

-- -- - -- --- ---
---

119254 65 < 81 RS- 134 SunOS 5.10: Install and Patch Utilities Patch

 

Looking for 119254-81 (1/167)

Trying Oracle

 

Please enter My Oracle Support Account User: [email protected]

Please enter My Oracle Support Account Password:

 

Trying https://getupdates.oracle.com/ (zip) (1/1)

Adding to /tmp/pca.980150: header=Authorization: Basic 

/usr/local/bin/wget --progress=dot:binary
"https://getupdates.oracle.com/all_unsigned/119254-81.zip";
--ca-certificate=./pca.perl -O /usr/local/bin/./119254-81.tmp

--2011-09-01 16:28:01--
https://getupdates.oracle.com/all_unsigned/119254-81.zip

idn_decode failed (9): `System iconv failed'

Resolving getupdates.oracle.com... 141.146.44.51

idn_decode failed (9): `System iconv failed'

Connecting to getupdates.oracle.com|141.146.44.51|:443... connected.

GnuTLS: ASN1 parser: Element was not found.

Unable to establish SSL connection.

Removing /tmp/pca.980150

Failed (Unknown Error)

Trying https://getupdates.oracle.com/ (tar.Z) (1/1)

Adding to /tmp/pca.776928: header=Authorization: Basic 

/usr/local/bin/wget --progress=dot:binary
"https://getupdates.oracle.com/all_unsigned/119254-81.tar.Z";
--ca-certificate=./pca.perl -O /usr/local/bin/./119254-81.tmp

--2011-09-01 16:28:02--
https://getupdates.oracle.com/all_unsigned/119254-81.tar.Z

idn_decode failed (9): `System iconv failed'

Resolving getupdates.oracle.com... 141.146.44.51

idn_decode failed (9): `System iconv failed'

Connecting to getupdates.oracle.com|141.146.44.51|:443... connected.

GnuTLS: ASN1 parser: Element was not found.

Unable to establish SSL connection.

Removing /tmp/pca.776928

Failed (Unknown Error)

Failed (patch not found)

 

Installing 119254-81 (1/167)

patchxdir: /tmp/pca.519035

Failed - missing patch file (16:28:02/00:00:00/00:01:05, 1/167, 0/0/1)


--

118666 18 < 32 RS-  87 JavaSE 5.0: update 30 patch (equivalent to JDK
5.0u30)

 

Looking for 118666-32 (2/167)

Trying Oracle

Trying https://getupdates.oracle.com/ (zip) (1/1)

Adding to /tmp/pca.912339: header=Authorization: Basic 

/usr/local/bin/wget --progress=dot:binary
"https://getupdates.oracle.com/all_unsigned/118666-32.zip";
--ca-certificate=./pca.perl -O /usr/local/bin/./118666-32.tmp

--2011-09-01 16:28:02--
https://getupdates.oracle.com/all_unsigned/118666-32.zip

idn_decode failed (9): `System iconv failed'

Resolving getupdates.oracle.com... 141.146.44.51

idn_decode failed (9): `System iconv failed'

Connecting to getupdates.oracle.com|141.146.44.51|:443... connected.

GnuTLS: ASN1 parser: Element was not found.

Unable to establish SSL connection.

Removing /tmp/pca.912339

Failed (Unknown Error)

Trying https://getupdates.oracle.com/ (tar.Z) (1/1)

Adding to /tmp/pca.678821: header=Authorization: Basic 

/usr/local/bin/wget --progress=dot:binary
"https://getupdates.oracle.com/all_unsigned/118666-32.tar.Z";
--ca-certificate=./pca.perl -O /usr/local/bin/./118666-32.tmp

--2011-09-01 16:28:03--
https://getupdates.oracle.com/all_unsigned/118666-32.tar.Z

idn_decode failed (9): `System iconv failed'

Resolving getupdates.oracle.com... 141.146.44.51

idn_decode failed (9): `System iconv failed'

Connecting to getupdates.oracle.com|141.146.44.51|:443... connected.

GnuTLS: ASN1 parser: Element was not found.

Unable to establish SSL connection.

Removing /tmp/pca.678821

Failed (Unknown Error)

Failed (patch not found)

 

^C

ERROR: Caught a SIGINT

Cleanup

Removing /tmp/pca.746942

Removing /usr/local/bin/./118718-06.tmp

Removing /usr/local/bin/./.pcaLock.download.118718-06

 

Lisa

 

 

From: [email protected] [mailto:[email protected]]
On Behalf Of Becktold, Lisa M. (LARC-B7)[Chugach Federal Solutions, Inc.]
Sent: Thursday, September 01, 2011 4:20 PM
To: [email protected]
Subject: [pca] pca patch download fails with Unknown error/patch not found

 

Hi,

 

I'm trying to download patches from http://getu

Re: [pca] Patch Download issues this morning

2009-11-18 Thread Jan Holzhueter
Hi,
yes seems to be back to normal.

Thx



Don O'Malley schrieb:
> Hi,
> 
> The issue was in one of the boundary systems SunSolve uses.
> It should be resolved now.
> 
> My testing indicated that all is healthy again now.
> 
> Please let me know if you are continuing to experience issues.
> 
> Sorry for any inconvenience.
> 
> Best.
> -Don
> 
> Jan Holzhueter wrote:
>> Looks like Network issues in general,
>> I even have problems browsing sunsolve.
>>
>> Jan
>>
>> Martin Paul schrieb:
>>   
>>> Hi Don,
>>>
>>> 
 There seems to be issues with the patch download service again this
 morning.

 I'm seeing patch downloads via wget taking 15 minutes.
   
>>> These have changed to continous "403 Forbidden" replies in the last two
>>> hours for me.
>>>
>>> Martin.
>>>
>>> 
>>
>>
>>
>>
>>



signature.asc
Description: OpenPGP digital signature


Re: [pca] Patch Download issues this morning

2009-11-18 Thread Don O'Malley




Hi,

The issue was in one of the boundary systems SunSolve uses.
It should be resolved now.

My testing indicated that all is healthy again now.

Please let me know if you are continuing to experience issues.

Sorry for any inconvenience.

Best.
-Don

Jan Holzhueter wrote:

  Looks like Network issues in general,
I even have problems browsing sunsolve.

Jan

Martin Paul schrieb:
  
  
Hi Don,



  There seems to be issues with the patch download service again this
morning.

I'm seeing patch downloads via wget taking 15 minutes.
  

These have changed to continous "403 Forbidden" replies in the last two
hours for me.

Martin.


  
  



  






Re: [pca] Patch Download issues this morning

2009-11-18 Thread Jan Holzhueter
Looks like Network issues in general,
I even have problems browsing sunsolve.

Jan

Martin Paul schrieb:
> Hi Don,
> 
>> There seems to be issues with the patch download service again this
>> morning.
>>
>> I'm seeing patch downloads via wget taking 15 minutes.
> 
> These have changed to continous "403 Forbidden" replies in the last two
> hours for me.
> 
> Martin.
> 






signature.asc
Description: OpenPGP digital signature


Re: [pca] Patch Download issues this morning

2009-11-18 Thread Martin Paul

Hi Don,

There seems to be issues with the patch download service again this 
morning.


I'm seeing patch downloads via wget taking 15 minutes.


These have changed to continous "403 Forbidden" replies in the last two 
hours for me.


Martin.



Re: [pca] Patch download issues today?

2009-06-22 Thread Richard Skelton

Hi Martin,
I had the same problem on Friday:-
--
140124 01 < 02 ---   1 SunOS 5.10_x86: kernel/drv/dnet patch

Looking for 140124-02 (22/39)
Trying http://brscs08.brs.infineon.com/pca/pca-proxy.cgi?
Failed
Failed (no Sun Online Account data)
Failed (patch not found)

Installing 140124-02 (22/39)
Failed (missing patch file)


Seem to download today fine today:-
140124 01 < 02 ---   4 SunOS 5.10_x86: kernel/drv/dnet patch

Looking for 140124-02 (2/3)
Trying http://brscs08.brs.infineon.com/pca/pca-proxy.cgi?
Done


Martin Paul wrote:

Hi,

Don O'Malley wrote:
  

All is fixed and a later version of the patchdiag is now available.



The new xref file and most patch downloads worked fine, but I have 
problems to download this one:


   140124 01 < 02 ---   1 SunOS 5.10_x86: kernel/drv/dnet patch

I get "403 Forbidden" consistently. The old patchfinder only has rev 01 
of the patch, the new patchfinder has rev 02, but says that I'm not 
authorized to download it ..


Martin.

  


--



Cheers

Richard Skelton
[email protected]
Infineon Technologies UK Ltd
Infineon House
Great Western Court
Hunts Ground Road
Stoke Gifford
Bristol
BS34 8HP
Tel +44(0)117 9528808




Re: [pca] Patch download issues today?

2009-06-19 Thread Martin Paul

Martin Paul wrote:
The new xref file and most patch downloads worked fine, but I have 
problems to download this one:


  140124 01 < 02 ---   1 SunOS 5.10_x86: kernel/drv/dnet patch


Following up on myself - downloading the patch worked fine now.

Martin.



Re: [pca] Patch download issues today?

2009-06-19 Thread Martin Paul

Hi,

Don O'Malley wrote:

All is fixed and a later version of the patchdiag is now available.


The new xref file and most patch downloads worked fine, but I have 
problems to download this one:


  140124 01 < 02 ---   1 SunOS 5.10_x86: kernel/drv/dnet patch

I get "403 Forbidden" consistently. The old patchfinder only has rev 01 
of the patch, the new patchfinder has rev 02, but says that I'm not 
authorized to download it ..


Martin.



Re: [pca] Patch download issues today?

2009-06-18 Thread Don O'Malley

Hi,

I just found out there was an outage last night that caused some of the 
later patch download issues and impacted the updating of the patchdiag file.


All is fixed and a later version of the patchdiag is now available.

Best,
-Don

Don O'Malley wrote:

Hi Martin/All,

I'll look into this and get the patchdiag updated asap.

I did log some service requests yesterday wrt the SunSolve download 
issues and they were fixed.


Apologies for the ongoing inconvenience that people are sporadically 
hitting with the download problems.


Best,
-Don

Martin Paul wrote:

Myers, Mike wrote:
There's definitely something up at Sun...again. 


Seems as if no new patchdiag.xref has been published today neither. I 
still get "## PATCHDIAG TOOL CROSS-REFERENCE FILE AS OF Jun/16/09 ##" 
as of today.


Martin.







Re: [pca] Patch download issues today?

2009-06-18 Thread Don O'Malley

Hi Martin/All,

I'll look into this and get the patchdiag updated asap.

I did log some service requests yesterday wrt the SunSolve download 
issues and they were fixed.


Apologies for the ongoing inconvenience that people are sporadically 
hitting with the download problems.


Best,
-Don

Martin Paul wrote:

Myers, Mike wrote:
There's definitely something up at Sun...again. 


Seems as if no new patchdiag.xref has been published today neither. I 
still get "## PATCHDIAG TOOL CROSS-REFERENCE FILE AS OF Jun/16/09 ##" 
as of today.


Martin.





Re: [pca] Patch download issues today?

2009-06-17 Thread Martin Paul

Myers, Mike wrote:
There's definitely something up at Sun...again. 


Seems as if no new patchdiag.xref has been published today neither. I 
still get "## PATCHDIAG TOOL CROSS-REFERENCE FILE AS OF Jun/16/09 ##" as 
of today.


Martin.



Re: [pca] Patch download issues today?

2009-06-17 Thread Myers, Mike
There's definitely something up at Sun...again.  Trying to download 139439-03 I 
get a file named 139439-03.zip but inside is HTML that says (HTML stripped):

--
An FTP authentication failure occurred
while trying to retrieve the URL:
ftp://[email protected]/patchroot/all/9/139439-03.zip

Squid sent the following FTP command:
PASS 
and then received this reply
Login incorrect.

Your cache administrator is webmaster
--

Sounds like someone changed the password and forgot to tell folks.

Cheers,
 - Mike.Myers  nwdc.net 


Re: [pca] Patch download issues today?

2009-06-17 Thread Jones, Dave
Worked first try!
I even tried again without it first, to be safe!
I'd seen that switch before but couldn't remember where or why..

Thanks,
Dave 

-Original Message-
From: [email protected]
[mailto:[email protected]] On Behalf Of French, David
Sent: Wednesday, June 17, 2009 4:47 PM
To: PCA (Patch Check Advanced) Discussion
Subject: Re: [pca] Patch download issues today?

I have seen a lot of the same issues when using the later pca scripts,
which default to using https to download data from sunsolve.  When
--ssprot=http is added to the pca command line, I have had much better
success.  It is like using https causes different servers to be used on
the backend at Sun, as opposed to using http.

So, my suggestion is to tell pca to use http with the above option and
try the download again.

--Dave

> -Original Message-
> From: [email protected] [mailto:pca-
> [email protected]] On Behalf Of Jones, Dave
> Sent: Wednesday, June 17, 2009 2:29 PM
> To: PCA (Patch Check Advanced) Discussion
> Subject: Re: [pca] Patch download issues today?
> 
> After multiple tries, I've got them all but one.
> I can just get that one manually if nothing else.
> 
> Thanks,
> Dave
> 
> 
> -Original Message-
> From: [email protected]
> [mailto:[email protected]] On Behalf Of Bliss, Kevin L
> Sent: Wednesday, June 17, 2009 4:11 PM
> To: 'PCA (Patch Check Advanced) Discussion'
> Subject: Re: [pca] Patch download issues today?
> 
> I was able to download the first one below, I did not try the others.
> 
> -Original Message-
> From: [email protected]
> [mailto:[email protected]] On Behalf Of Jones, Dave
> Sent: Wednesday, June 17, 2009 1:39 PM
> To: PCA (Patch Check Advanced) Discussion
> Subject: [pca] Patch download issues today?
> 
> 
> Hello all.
> 
> Is anyone else seeing issues downloading patches today?
> "pca -da" fails to find 10 patches in the xref
> 
> A couple of examples:
> 
>
---
> -
> --
> 139608 -- < 02 R--  37 SunOS 5.10: Emulex-Sun LightPulse Fibre Channel
> Adapter driver
> 
> Looking for 139608-02 (36/58)
> Trying https://sunsolve.sun.com/ (1/1)
> Failed
> Failed (patch not found)
>
---
> -
> --
> 139966 -- < 02 R--   9 SunOS 5.10: zoneinfo patch
> 
> Looking for 139966-02 (37/58)
> Trying https://sunsolve.sun.com/ (1/1)
> Failed
> Failed (patch not found)
>
---
> -
> --
> 
> I can download the patches from a browser with no problem.
> 
> Thanks,
> Dave
> 
> 
> Confidentiality Warning:  This e-mail contains information intended
> only
> for the use of the individual or entity named above.  If the reader of
> this e-mail is not the intended recipient or the employee or agent
> responsible for delivering it to the intended recipient, any
> dissemination, publication or copying of this e-mail is strictly
> prohibited.  The sender does not accept any responsibility for any
> loss,
> disruption or damage to your data or computer system that may occur
> while using data contained in, or transmitted with, this e-mail.
> If you have received this e-mail in error, please immediately notify
us
> by return e-mail.  Thank you.
> 
> 
> 
> 
> 
> 
> Confidentiality Warning:  This e-mail contains information intended
> only for the use of the individual or entity named above.  If the
> reader of this e-mail is not the intended recipient or the employee or
> agent responsible for delivering it to the intended recipient, any
> dissemination, publication or copying of this e-mail is strictly
> prohibited.  The sender does not accept any responsibility for any
> loss, disruption or damage to your data or computer system that may
> occur while using data contained in, or transmitted with, this e-mail.
> If you have received this e-mail in error, please immediately notify
us
> by return e-mail.  Thank you.
> 
> 
> 


Confidentiality Warning:  This e-mail contains information intended only for 
the use of the individual or entity named above.  If the reader of this e-mail 
is not the intended recipient or the employee or agent responsible for 
delivering it to the intended recipient, any dissemination, publication or 
copying of this e-mail is strictly prohibited.  The sender does not accept any 
responsibility for any loss, disruption or damage to your data or computer 
system that may occur while using data contained in, or transmitted with, this 
e-mail.  
If you have received this e-mail in error, please immediately notify us by 
return e-mail.  Thank you.






Re: [pca] Patch download issues today?

2009-06-17 Thread French, David
I have seen a lot of the same issues when using the later pca scripts, which 
default to using https to download data from sunsolve.  When --ssprot=http is 
added to the pca command line, I have had much better success.  It is like 
using https causes different servers to be used on the backend at Sun, as 
opposed to using http.

So, my suggestion is to tell pca to use http with the above option and try the 
download again.

--Dave

> -Original Message-
> From: [email protected] [mailto:pca-
> [email protected]] On Behalf Of Jones, Dave
> Sent: Wednesday, June 17, 2009 2:29 PM
> To: PCA (Patch Check Advanced) Discussion
> Subject: Re: [pca] Patch download issues today?
> 
> After multiple tries, I've got them all but one.
> I can just get that one manually if nothing else.
> 
> Thanks,
> Dave
> 
> 
> -Original Message-
> From: [email protected]
> [mailto:[email protected]] On Behalf Of Bliss, Kevin L
> Sent: Wednesday, June 17, 2009 4:11 PM
> To: 'PCA (Patch Check Advanced) Discussion'
> Subject: Re: [pca] Patch download issues today?
> 
> I was able to download the first one below, I did not try the others.
> 
> -Original Message-
> From: [email protected]
> [mailto:[email protected]] On Behalf Of Jones, Dave
> Sent: Wednesday, June 17, 2009 1:39 PM
> To: PCA (Patch Check Advanced) Discussion
> Subject: [pca] Patch download issues today?
> 
> 
> Hello all.
> 
> Is anyone else seeing issues downloading patches today?
> "pca -da" fails to find 10 patches in the xref
> 
> A couple of examples:
> 
> ---
> -
> --
> 139608 -- < 02 R--  37 SunOS 5.10: Emulex-Sun LightPulse Fibre Channel
> Adapter driver
> 
> Looking for 139608-02 (36/58)
> Trying https://sunsolve.sun.com/ (1/1)
> Failed
> Failed (patch not found)
> ---
> -
> --
> 139966 -- < 02 R--   9 SunOS 5.10: zoneinfo patch
> 
> Looking for 139966-02 (37/58)
> Trying https://sunsolve.sun.com/ (1/1)
> Failed
> Failed (patch not found)
> ---
> -
> --
> 
> I can download the patches from a browser with no problem.
> 
> Thanks,
> Dave
> 
> 
> Confidentiality Warning:  This e-mail contains information intended
> only
> for the use of the individual or entity named above.  If the reader of
> this e-mail is not the intended recipient or the employee or agent
> responsible for delivering it to the intended recipient, any
> dissemination, publication or copying of this e-mail is strictly
> prohibited.  The sender does not accept any responsibility for any
> loss,
> disruption or damage to your data or computer system that may occur
> while using data contained in, or transmitted with, this e-mail.
> If you have received this e-mail in error, please immediately notify us
> by return e-mail.  Thank you.
> 
> 
> 
> 
> 
> 
> Confidentiality Warning:  This e-mail contains information intended
> only for the use of the individual or entity named above.  If the
> reader of this e-mail is not the intended recipient or the employee or
> agent responsible for delivering it to the intended recipient, any
> dissemination, publication or copying of this e-mail is strictly
> prohibited.  The sender does not accept any responsibility for any
> loss, disruption or damage to your data or computer system that may
> occur while using data contained in, or transmitted with, this e-mail.
> If you have received this e-mail in error, please immediately notify us
> by return e-mail.  Thank you.
> 
> 
> 



Re: [pca] Patch download issues today?

2009-06-17 Thread Jones, Dave
After multiple tries, I've got them all but one.
I can just get that one manually if nothing else.

Thanks,
Dave


-Original Message-
From: [email protected]
[mailto:[email protected]] On Behalf Of Bliss, Kevin L
Sent: Wednesday, June 17, 2009 4:11 PM
To: 'PCA (Patch Check Advanced) Discussion'
Subject: Re: [pca] Patch download issues today?

I was able to download the first one below, I did not try the others. 

-Original Message-
From: [email protected]
[mailto:[email protected]] On Behalf Of Jones, Dave
Sent: Wednesday, June 17, 2009 1:39 PM
To: PCA (Patch Check Advanced) Discussion
Subject: [pca] Patch download issues today?


Hello all.

Is anyone else seeing issues downloading patches today?
"pca -da" fails to find 10 patches in the xref

A couple of examples:


--
139608 -- < 02 R--  37 SunOS 5.10: Emulex-Sun LightPulse Fibre Channel
Adapter driver

Looking for 139608-02 (36/58)
Trying https://sunsolve.sun.com/ (1/1)
Failed
Failed (patch not found)

--
139966 -- < 02 R--   9 SunOS 5.10: zoneinfo patch

Looking for 139966-02 (37/58)
Trying https://sunsolve.sun.com/ (1/1)
Failed
Failed (patch not found)

--

I can download the patches from a browser with no problem.

Thanks,
Dave


Confidentiality Warning:  This e-mail contains information intended only
for the use of the individual or entity named above.  If the reader of
this e-mail is not the intended recipient or the employee or agent
responsible for delivering it to the intended recipient, any
dissemination, publication or copying of this e-mail is strictly
prohibited.  The sender does not accept any responsibility for any loss,
disruption or damage to your data or computer system that may occur
while using data contained in, or transmitted with, this e-mail.  
If you have received this e-mail in error, please immediately notify us
by return e-mail.  Thank you.






Confidentiality Warning:  This e-mail contains information intended only for 
the use of the individual or entity named above.  If the reader of this e-mail 
is not the intended recipient or the employee or agent responsible for 
delivering it to the intended recipient, any dissemination, publication or 
copying of this e-mail is strictly prohibited.  The sender does not accept any 
responsibility for any loss, disruption or damage to your data or computer 
system that may occur while using data contained in, or transmitted with, this 
e-mail.  
If you have received this e-mail in error, please immediately notify us by 
return e-mail.  Thank you.






Re: [pca] Patch download issues today?

2009-06-17 Thread Bliss, Kevin L
I was able to download the first one below, I did not try the others. 

-Original Message-
From: [email protected] [mailto:[email protected]] On 
Behalf Of Jones, Dave
Sent: Wednesday, June 17, 2009 1:39 PM
To: PCA (Patch Check Advanced) Discussion
Subject: [pca] Patch download issues today?


Hello all.

Is anyone else seeing issues downloading patches today?
"pca -da" fails to find 10 patches in the xref

A couple of examples:


--
139608 -- < 02 R--  37 SunOS 5.10: Emulex-Sun LightPulse Fibre Channel
Adapter driver

Looking for 139608-02 (36/58)
Trying https://sunsolve.sun.com/ (1/1)
Failed
Failed (patch not found)

--
139966 -- < 02 R--   9 SunOS 5.10: zoneinfo patch

Looking for 139966-02 (37/58)
Trying https://sunsolve.sun.com/ (1/1)
Failed
Failed (patch not found)

--

I can download the patches from a browser with no problem.

Thanks,
Dave


Confidentiality Warning:  This e-mail contains information intended only for 
the use of the individual or entity named above.  If the reader of this e-mail 
is not the intended recipient or the employee or agent responsible for 
delivering it to the intended recipient, any dissemination, publication or 
copying of this e-mail is strictly prohibited.  The sender does not accept any 
responsibility for any loss, disruption or damage to your data or computer 
system that may occur while using data contained in, or transmitted with, this 
e-mail.  
If you have received this e-mail in error, please immediately notify us by 
return e-mail.  Thank you.