With security of public servers becoming more important by the day, quickly applying security updates for software packages utilized by n-Command MSP has become a need. To address this issue, ADTRAN has developed a security repository for n-Command MSP to allow ADTRAN to distribute tested security updates for n-Command MSP that do not require a complete server upgrade. This feature will make n-Command MSP maintenance more flexible in a security-concerned enterprise.
Sections Included in This Document
Hardware and Software Requirements
Security Update Considerations
The Security Updates feature requires MSP version 8.1.1 or higher. If you are attempting to upgrade to a version of MSP that is above 8.1.1, you must upgrade to MSP version 8.1.1 and run the security updates before continuing to upgrade to the desired version.
With security vulnerabilities in packages used by n-Command MSP's underlying packages and operating system, the ability to quickly update these few packages without upgrading MSP has become necessary. The Security Update feature allows a user to download updates from.ADTRAN's security repository that have been tested with n-Command MSP versions without having to upgrade the underlying MSP software.
ADTRAN plans on releasing a package of security updates quarterly. However, if more critical vulnerabilities are found in between the planned update periods, ADTRAN may release updates for single packages. This will help network administrators keep security concerns at a minimum with n-Command MSP.
Note: Although the Security Updates feature helps keep n-Command MSP's packages up to date, it is still important to properly secure your server. For more information, please see the guide
Due to the more critical nature of Security Updates in the server, the ability to apply security updates is only available inside the MSP admin dashboard, accessible by adding "/msp" to the ip address or hostname of the server address and logging in with admin credentials.
Note: If you see the error message "WARNING: Security updates must be installed from the server page on all cluster nodes before upgrading", you must apply security updates using this document and then upgrade firmware.
n-Command MSP will automatically query an ADTRAN repository for a Security Updates package once per day. If a package is found, it will not be automatically downloaded; instead the admin dashboard user will be alerted that there are security packages available. In turn, a notice will be posted on the ADTRAN Support forum as well for customers with a n-Command server without an internet connection.
To download this package, log into the admin dashboard of n-Command MSP by typing the following the URL bar of your browser:
<ip address of hostname of server>/msp
Log in with the administrator credentials and then navigate to Settings->Security Updates. The available update should show up on the resulting screen. Press Download Only to download the updates. Once the download is completed, click Install to install the updates. A console window will pop up and guide you through the install as well as give information about the updates as they are installed.
Note: This is an invasive server process. Make sure no users try to attempt to log in and use the server during the installation of security updates.
If your n-Command MSP unit cannot reach the internet to check the repository, the packages must be manually uploaded and installed.
To download this package, log into the admin dashboard of n-Command MSP by typing the following the URL bar of your browser:
<ip address of hostname of server>/msp
Log in with the administrator credentials and then navigate to Settings->Security Updates. On the resulting popup, click the Manual Updates tab. On the new tab, there will be a link named Patch File Link which links to the specific repository for your version and hardware associated with n-Command MSP.
Using the link, download the selected file to a local computer and then manually upload the package on the same screen. Once the files are uploaded, click the Install button to install them.