TSM for VE broken after today's MS patch

2017-10-10 Thread Tom Alverson
I have 8 TSM for VE installations in one of our data centers all running TSM4VE 7.1.4.0 on windows server 2008R2. One of the servers was a mess after patching (the rest are OK). When I logged on the CPU's were pegged and there were hundreds of CMD.EXE processes starting and stopping. I found

Re: Magic Decoder Ring needed

2017-10-10 Thread Zoltan Forray
Thank you for the info. We have started running AUDIT's but with 30TB+ in this disk stgpool, it will take a while. I am very interested in additional details on the RAID firmware issue you mentioned - any specifics would be very helpful. AFAIK, we are up-to-date on all Dell firmware (we patch

Re: Magic Decoder Ring needed

2017-10-10 Thread Skylar Thompson
Hi Zoltan, We ran into this recently, and it was caused by a firmware bug in a RAID adapter that caused it not to fail and obviously-failing disk in our disk spool. We followed the procedure here: https://www.ibm.com/support/knowledgecenter/en/SSGSG7_7.1.6/tshoot/r_pdg_1330_1331_msg.html It did

Magic Decoder Ring needed

2017-10-10 Thread Zoltan Forray
Recently we started seeing these errors on one of our servers: 10/10/2017 13:35:51 ANR1330E The server has detected possible corruption in an object that is being restored or moved. The actual values for the incorrect frame are: magic 53454652 hdr

Re: 7.1.8/8.1.3 Security Upgrade Install Issues

2017-10-10 Thread Zoltan Forray
That is probably due to: SSLACCEPTCERTFROMSERV - The default value Yes enables the client to automatically accept a self-signed public certificate from the server, and to automatically configure the client to use that certificate when the client connects to a V8.1.2 or later server. On Tue, Oct

Re: 7.1.8/8.1.3 Security Upgrade Install Issues

2017-10-10 Thread Sergio O. Fuentes
My digicert signed certs are loaded into the server cert.kdb using the gsk8apicmd functions. That's working. My question was getting those non-existent root and intermediate CA certs loaded into the client. Normally, in order to get SSL working, you need the whole signing chain on the client

Re: 7.1.8/8.1.3 Security Upgrade Install Issues

2017-10-10 Thread Loon, Eric van (ITOPT3) - KLM
Hi guys! I read all the discussions with interest and I'm getting more and more confused. I tend to shy away from installing the latest codes on my server and clients after seeing all the issues you can get from them. Let's assume I don't care about the tighter security and I only care about a

Re: 7.1.8/8.1.3 Security Upgrade Install Issues

2017-10-10 Thread Zoltan Forray
As I read it, "vendor-acquired certificates" need to be loaded/added to the server using the gsk8capicmd function. This link, while it's for 7.1.1, talks about it: https://www.ibm.com/support/knowledgecenter/en/SSGSG7_7.1.1/com.ibm.itsm.tshoot.doc/r_pdg_ssl_comm.html On Tue, Oct 10, 2017 at

DP4VE on Spectrum Protect Server?

2017-10-10 Thread Rick Adamson
Just built a new source/target set of Spectrum servers to be used for DP4VE. Is there any reason they can't coexist on the same system ? The install guide implies the vStorage backup server and SP server be separate system's but doesn't seem to explicitly state one way or the other. (unless I

Re: 7.1.8/8.1.3 Security Upgrade Install Issues

2017-10-10 Thread Sergio O. Fuentes
I have one other question for any IBMers or people who may have had experience with this: If 8.1.2 clients can negotiate certificates with a 8.1.3 TSM server, does this mean that for users who use third-party signed certificates (not loaded by default in the TSM client) that the certificate chain