List of fixes for SG2.1.10.3

Report created April 29, 2004
IssueService RequestDescription
282591-4585479Intel copper gig-E driver is incompatible with Cisco WS-X6316/4412 adapters.
285591-4513313The ProxySG might send out multiple daily heartbeats if the heartbeat enable or reset command was issued multiple times.
294011-5511895If the ProxySG was configured to send a preview to the ICAP server, under certain circumstances the ProxySG would mistakenly send fewer bytes than the configured preview even though the origin server's response was greater than the preview size. This behavior had an adverse effect to the overall transaction.
29456NONESerial console generates a registry warning when deleting an NTP server.
295611-4956807Backwards compatibility with CA 4.x PAC file parsing was not maintained.
296111-4846553Access Log: Replace whitespace in usernames with "%20" characters in order to prevent confusing log analyzers.
296451-4857201, 1-4926001ICAP health checks could become queued causing client workers to max out.
297021-4826615Page fault at process "http.dll" at .text+0x3C71B while serving the final patience page
297231-5009329, 1-5021664, 1-5048801, 1-5162293The ProxySG sometimes does not forward credentials to OCS in transparent proxy mode.
29744NONEUnable to serve content to client when Patience-page and Bandwidth gain mode are simultaneously enabled.
298141-5025314Page fault at 0x48 in ce_admin.dll
298241-4679844CLI and console agent may become unresponsive due to TCP/IP workers becoming blocked while trying to read link settings.
298531-5039401, 1-5288821The ProxySG was incorrectly terminating client cookies (a LF with no CR) intended for origin servers when parsing the BCSI cookie.
299401-5206232, 1-5212071When ICAP Patience page (scan progress notification) feature is enabled on ProxySG, if ICAP server returns "NO MODIFICATION REQUIRED" response while scanning an object, ProxySG will restart.
30044NONEThe block_category condition does not refer to the allow or deny global policy set by CPL. If you are allowed, block_category will block your request if it is in one of the categories specified. If you are denied by policy then any line where your request matches on a block_category is irrelevant since you are not allowed to make a request.
30046NONEGuard against potential OpenSSH vulnerabilities described in CERT advisory CA-2003-24.
300711-4990528Provide backwards compatibility for CA4.x authentication (authenticate-407) to return explicit proxy style challenge instead of a 401 authenticate challenge.
30123NONEAfter disk re-creation, replicated/duplicated objects are placed on the new disk.
301241-4926313Prevent multiple disks from being simultaneouly re-initialized. This was done to prevent configuration loss.
303621-5057655, 1-5252211, 1-5260811, 1-5477801, 1-5486859A problem was fixed that could manifest in the following errors: SCSI fatal error 0x28007, Cache administrator fatal error 0x40012, Cache administrator write errors 0x4010E and 0x4010D, hang when writing core images.
30462NONEGuard against potential OpenSSL vulnerabilities in ASN.1 parsing.
305111-5026626For WebFTP sessions, the ProxySG was not sending the correct credentials to the OCS after receiving a 530(login incorrect) response from the FTP server.
305771-5246594, 1-5416781Page fault at 0x3A in MMS_Fileworker
305981-5211891The ProxySG was not logging (Access Log) the proxy IP for the %l symbol for transparent requests.
306331-4964605Under certain conditions, the Heatbeat email subject would read "CacheOS Summary Statistics" after upgrade.
308141-5319111, 1-5511692Page fault at 0x44 in HTTP SW when ICAP scanning an object initally loaded while running CacheOS.
308211-5316433The ProxySG is not closing SSH sockets when no data is received
309311-5338670Page fault 0x8 in "af.dll" at .text+0xA773 while loading forwarding config
310091-5143881, 1-5385498After modifying the weights in an ICAP cluster, the ProxySG would start to return HTTP 503 responses to the client.
311341-5385838, 1-5406758, 1-5571401Small OCS responses (<1000 bytes) that do not contain a content length or are not closed may not return immediately to the client. This may occur for web "streaming" applications, such as stock tickers. The bypass_cache() trigger is modified to ensure responses are not buffered and served immediately to the client. Use bypass_cache() judiciously, as it may affect ASX rewrites.
311741-5329763Page fault "CAG_Worker" in "shared_dll.dll" at .text+0x32EB
312541-5427782ICP queries were recorded in the access log as TUNNEL instead of ICP_QUERY.
312561-5324473The file name for configuration uploads is now configurable.
313361-5444157ICAP performance decreases when adding ICAP clusters.
313751-5048625The ProxySG was sending "502 Bad response" to the FTP client when the OCS returned a "500 command not understood" response for the PASS command. In this case, the password information was missing from the requested Web FTP URL (for example: ftp://user@site/path). For such URLs, the ProxySG sent the "PASS" command with an empty password string, as many FTP servers support empty passwords or ignore passwords for anonymous users. But an empty PASS command triggers Solaris (v2.8) servers to return a "500 command not understood" instead of a "530 login failure" response. This was causing the ProxySG to send a 502 error message instead of a 401 auth required, which would have allowed the user to supply a password.
313981-5479411ICAP's mechanism to parse HTTP headers to determine response data type was mistakenly using the "Content-Transfer-Encoding" header (if present) over the "Transfer-Encoding" header. This caused erroneous decoding and a premature termination of the connection to the ICAP server.
316201-5518172Restart: SWE=0x4001c in "ce_admin.dll" at .text+0x7F8D
318411-5622680Page fault at 0x79 when issuing "virtual-ip address no" command.
321971-5458514Pagefault restart in Process " HTTP WRK00349::FDE93F84 CW " in "transformer_dll.dll" at .text+0x6F34 while normalizing URL for asx transform.
32812NONEApply fixes for OpenSSL vulnerability CAN-2004-0079.
41936NONEApply fixes for OpenSSL vulnerability CAN-2004-0081.
419661-6010459Access logging cannot be enabled through the Management Console with some instances of JRE 1.4.x.
42504NONEResolve TCP Vulnerability CAN-2004-0230.