ProxySG SGOS 3.2.x

Release Notes


Version: SGOS 3.2.8 build 33164
Release Date: 2/5/2005
Revision: 1.6 on 3/28/2008

Introduction

SGOS 3.2.8 is a maintenance release of the Blue Coat® Systems ProxySG™ Appliance software. This release mainly provides bug fixes. Please note that since SG was NIAP certified with SG 3.2.4.8, there are no changes in the code that affect the NIAP certification.

Note: ProxySG is the name for Blue Coat secure proxy appliances.

These release notes apply to Blue Coat appliances that are currently running or will be upgraded to the SGOS 3.2.x8 release. Before starting the upgrade process, please review the Upgrade Instructions and the Limitations and Known Issues section.

For general information about Blue Coat, e-mail us at: bcsi.info@bluecoat.com.
Direct support questions regarding this release to Blue Coat Technical Support. For more information, visit http://www.bluecoat.com/support/contact.html.

Features in this Release

All new features are documented in the Blue Coat ProxySG Configuration and Management Guide that accompanies SGOS 3.2. See the Documentation section for information on how to access the documents for the release. For changes, including the SurfControl commands, see also Changes in this Version in this document.

Changes in this Version

SG 3.2.8.6 (build 33164)
  • Added new hard drive support for the 73GB Segate model ST373455LC on 8000 series.
SG 3.2.8.2 (build 28032)
  • Daylight Savings Time change (DST). The appliance software has been modified to include new rules for DST. Additionally, all timestamps, which are recorded in Coordinated Universal Time (UTC), are processed differently so that local time displays correctly. The Management Console has been modified to include a more comprehensive time zone selection. To enable flexibility, time zone selection can be associated with an open source time zone database that can be updated at the user’s discretion. The time zone database is not required to set the appliance to UTC.
  • Fixed issue where systems running Smartfilter content filtering on SG report 100% CPU load (B#77889, 2-43253771, 2-43359726, 2-43514436).
  • Fixed restart in Process MSN IM Worker 5D678374 in im.dll at .text+0x2AF71 (B#76801, 2-42429541).
SG 3.2.8.1 (build 27635)
SG 3.2.7.9 (build 27146)
  • Fix for security vulnerability with OpenSSL: RSA Signature Forgery (CVE-2006-4339).
  • Fix for security vulnerability with Netscape's SSLv3 implementation (a client can negotiate a weaker cipher when resuming an SSL session).
  • Added support for SSL 5825 Falcon card on 400, 800 and 8000 platforms.
  • Issues fixed in this release
SG 3.2.7.3 (build 26263)
SG 3.2.7.2 (build 25417)
  • Resolves a problem where objects may not be refreshed or deleted when expected (B#57767).
  • Page Fault in HTTP CW" in "shared_dll.dll" at .text+0x13D50 - Set_user_agent_str() (B#58535, 2-23524054, 2-23946427).
  • SNMP SysUptime is resetting every 49.7 days (B#57025, 2-19205781).
SG 3.2.7.1 (build 25006)
SG 3.2.6.7 (build 24028)
SG 3.2.6.1 (build 23700)
SG 3.2.5.5 (build 23247)
SG 3.2.5.2 (build 23058)
SG 3.2.5.1 (build 23013)
SG 3.2.4.8 (build 22001)

New features in SGOS 3.2.4 include:

For more information on patience page functionality, go to ICAP

Note: In this release, only Cerberian supports categorization review.

SG 3.2.3.16 (build 22277)
SG 3.2.3.3 (build 21579)

New features in SGOS 3.2.3.3 include:

Deprecated Substitutions      Replacement Substitutions
subst_embedded                       rewrite_url_substring
subst_prefix                              rewrite_url_prefix
caseless                                    no replacement needed

Also deprecated:

SG 3.2.2.1 (build 21395)
SG 3.2.1.2 (build 21246)

New features in SG 3.2.1.2 include:

SG 3.2.1.1 (build 21179)

New features in SG 3.2.1.1 include:

System Requirements

Hardware Requirements

Blue Coat appliance models SG400-x, SG800-x, 6xx (except 610), SG6xxx, 7xx, 7xxx, and 8000-x can be upgraded to SGOS 3.2.x.

Older Blue Coat appliance models 610, 5xx, 3xxx, 5xxx, 2xxx, 1xxx, and 1xx cannot be upgraded to this release. Contact your local reseller or Blue Coat Sales (at sales@bluecoat.com) to upgrade your hardware to a newer model.

Before upgrading to SGOS 3.2.7, Blue Coat recommends evaluating the current CPU usage on installed systems. For example, if a SGOS 2.x system is already running between 70-80% CPU utilization under average load patterns, contact your local Blue Coat sales team to discuss load balancing and hardware upgrade options to ensure sufficient headroom to handle both average and transient/peak loads after the upgrade to SGOS 3.2.7.

Software Requirements

To upgrade to SGOS 3.2.7, the appliance must be running specific versions of CacheOS CA/SA 4.x, SGOS 2.1.x, or SGOS 3.1.x before the upgrade. See the table in the Upgrade Instructions section below on the upgrade path you must follow to upgrade to SGOS 3.2.7.

The Web-based Management Console (MC) and the Visual Policy Manager (VPM) Java application should be used only under the following recommended combinations of OS, Browser, and Sun Java Runtime Environment (JRE) versions.

ICAP

The Blue Coat ProxySG with ProxyAV™ integration is a high-performance Web anti-virus (AV) solution. For more information, refer to the Blue Coat web site

In this release, SGOS is also certified with the following third-party vendors' implementation of ICAP:

Important: While SGOS 2.x supported ICAP v0.95 servers and services, SGOS 3.2.7 does not. Upon upgrading to SGOS 3.2.x, any configured v0.95 services become inactive.

Blue Coat WebFilter Database Updates

With the release of SG3.2.5 in July 2005, Blue Coat changed the URL for access to Blue Coat WebFilter (BCWF) database updates to list.bluecoat.com/bcwf/activity/download/bcwf.db. Effective October 24, 2005, Blue Coat retired access to BCWF database updates through the old URL located at bluecoat.downloads.cerberian.com/dbupdates/bluecoat.db. The old URL will remain active for an indefinite period of time to allow time for you to modify your configuration if necessary.

Make sure you are using the correct URL.

Upgrade Instructions

This section provides upgrade information and instructions.

Downloading Images

A ProxySG Appliance H/W Serial Number is required to download the SGOS 3.2.x software. For more information on downloading the software, go to the SGOS 3 Software Download Page.

To purchase an upgrade or renew a support contract, contact your local reseller or Blue Coat Sales (at sales@bluecoat.com.)

Upgrade Paths Supported

Please refer to the table below on the upgrade path you must follow to upgrade to SGOS 3.2.x..

Current OS (range)

Direct SGOS 3.2 Upgrade Allowed?

Next OS

CA 4.1.x, where x >= 10

No

SGOS 2.1.07

CA 4.2.x, where x >= 01

Yes

SGOS 3

SA 4.1.x, where x >= 10

Yes

SGOS 3

SGOS 2.0.00 - SG2.1.06

No

SGOS 2.1.07

SGOS 2.1.x, where x >= 07

Yes

SGOS 3

SGOS 3.1.x, where x>=0

Yes

SGOS 3.2

For example:

If you are running SGOS 2.1.06, upgrade to SGOS 2.1.07, and then to SGOS 3.

  • You cannot upgrade to a system that is:
  • If you are doing a major upgrade, you should also review the Blue Coat ProxySG SGOS 3.x Upgrade Guide, found at http://www.bluecoat.com. If you are updating from SGOS 3.1.x to SGOS 3.2.7, no special procedures are needed.

    NTLM Agent Upgrade (from CAASNT to BCAAA)

    If you use NTLM, you must use the 3.2 release of the Blue Coat Authentication and Authorization Agent (BCAAA) service with SGOS 3.2 and higher. You can also use the BCAAA service in place of the deprecated CAASNT application for SGOS 2.x and SGOS 3.1.x. You cannot use CAASNT with SGOS 3.2 and higher.

    BCAAA is distributed as a zip file or UNIX shell script, to be installed on a Microsoft® Windows® system or a Solaris™ system. The URLs to download BCAAA are posted, along with the SGOS 3.2 software images, on the SGOS 3 Software Download Page.

    Installation instructions for BCAAA on Windows are in Appendix A: "Using the Authentication/Authorization Agent" of the Blue Coat ProxySG Configuration and Management Guide that is available at the Blue Coat web site.

    To install BCAAA on Solaris, complete the following instructions. You must be root to complete installation.

      1. Download the shell script to your system.
      2. Execute the shell script:
      # sh bcaaa-version_number-SOLARIS-install.sh

      Answer the questions to install the service on your Solaris system. A sample session is shown below:

      Enter a path to a scratch directory [/tmp]:

      Install Blue Coat Systems Authentication and Authorization Agent (BCAAA)? (y/n) y

      Enter user that should own the installed files [root]
      Enter group for the installed files [root]
      /usr/local/bin/bcaaa installed
      /usr/local/bin/bcaaa-99 installed
      Libraries installed in /usr/local/lib/BlueCoatSystems/
      /usr/local/etc/bcaaa.ini installed

      If you use inetd, append the following line to /etc/services

      bcaaa 16101/tcp # Blue Coat Systems Authentication Agent

      If you use inetd, append the following line to /etc/inetd.conf, then signal inetd to re-read the configuration file. If you use something else, make the equivalent changes.

      bcaaa stream tcp nowait root /usr/local/bin/bcaaa bcaaa -c /usr/local/etc/bcaaa.ini
      Installation complete

    Accessing and Configuring the ProxySG

    Some changes related to accessing and configuring the appliance should be recognizable if you are familiar with previous SGOS releases.

    Troubleshooting Installation Issues

    When upgrading from builds prior to SGOS 3.1.x, such as 2.1.x or 3.0.x, the upgrade sometimes fails with an error message similar to:

    "Starter: No object data at offset 24,420,352 on disk 1"

    If you encounter this issue, complete the following steps:

      1. Reboot the appliance to a version on the system that supports an upgrade path (see Upgrade Paths Supported).
      2. Download the image again that you want to boot (such as SGOS 3.2.x).
      3. Do a load upgrade of the newly downloaded image, using either the CLI or the Management Console.
      4. Give the system time to flush the newly-downloaded system to disk, at least one minute.
      5. Use the restart upgrade button or command to boot the appliance to the new version.
    Troubleshooting Upgrade/Downgrade for Forwarding

    If you upgrade from SGOS 2.x to SGOS 3.2 and restore the SGOS 2.x configuration SGOS# restore-sgos2-config ), then try to delete the forwarding host ( SGOS# restore-sgos2-config ), you will receive the following message:

    % Cannot delete a host now in use by policy.

    This occurs because, on upgrade, the forwarding host is included in the default forwarding host sequence. To delete the forwarding host, you need to issue the following commands to clear the default fail-over sequence:

    SGOS#(config) forwarding
    SGOS#(config forwarding) sequence clear

    Licensing

    SGOS 3 introduces a new licensing scheme for software options on all ProxySG appliances. The licensing scheme requires an appliance hardware serial number to be linked with a set of software serial numbers (one for each saleable software option) and the creation of an appliance-specific license key. You must

    1. Register yourself as a customer
    2. Register your appliance hardware serial number with Blue Coat
    3. Link your purchased software serial numbers to your hardware serial number
    4. Generate and download a license key
    5. Install it onto the appliance
    The preceding steps must occur within 60 days of starting to use the appliance. During this 60-day period (known as the Trial Period), until you load a license key, all components on the appliance are enabled and available for you to try.



    In most cases, if you bought your ProxySG Appliance and software options together, Blue Coat automatically links your hardware and software serial numbers and pre-generates a license key. The license key can be automatically downloaded onto your appliance from Blue Coat by logging in to the Management Console and navigating to Maintenance>Licensing>Install and clicking the Request button in the License Key Automatic Installation section. You need a Blue Coat WebPower User ID/Password and a hardware serial number to automatically load the license key. Note: For SG400s, SG800s, SG8000s, and newer SG6000 models, the hardware serial number is burned into the appliance's EPROM. For other models, you must manually enter the hardware serial number from the label in the back into the Management Console by navigating to Configuration>General>Identification.

    For more information on customer registration, hardware serial number registration, and license key management, visit the Blue Coat License Configuration and Management site .

    Note: The PAK key-based licensing is no longer supported with SGOS 3. Blue Coat is contacting all customers with PAK keys and providing information on how to enable the same features under the new licensing scheme, if they are eligible to enable the features under SGOS 3.

    Netegrity SiteMinder Component

    A new licensable component, Netegrity SiteMinder, has been introduced as part of base SGOS functionality in the SGOS 3.2 release. Users who already have a valid SGOS 3.1.x license will NOT have this feature enabled until they update their license key. When viewing licensable components, they will see Netegrity SiteMinder as a component that is not yet valid. To update the license key, please login to the Blue Coat License Configuration and Management site, select hardware and go to Manage Customer Licenses Customer Information and click on Update License Key. Please note that license keys installed in SGOS 3.1.x are forward compatible with SGOS 3.2, except they do not activate the Netegrity SiteMinder feature until the license key has been updated. Users requesting a license key for the very first time (upgrading from CA/SA 4.x and SGOS 2.1.x) automatically get the Netegrity SiteMinder component included in the license key.

    Limitations and Known Issues

    A set of limitations and known issues with the release is maintained by Blue Coat Systems and updated with each dot release. Read through the issues before upgrading to this release. After upgrading, review these pages if you encounter an issue to verify it is not a known limitation or issue before contacting Blue Coat Systems.

    Review the Known Issues and Limitations You can also view a list of fixes in this release.

    Documentation

    These manuals are available in Adobe® Acrobat® PDF format on the Blue Coat web site.

    In addition to the above documents, the ProxySG Management Console contains online help in the form of a built-in HTML version of the Configuration and Management Guide that is linked to Help buttons. However, this online help is updated with every dot release. Therefore, Blue Coat recommends that you visit the Blue Coat web site for the most up-to-date documentation.

    Doc Errata

    SmartFilter: Two commands--download license and download server--are listed as available for use in SGOS 3.2.8. These commands are only available in SGOS 4.1 or higher.

    Support

    Support questions regarding this release should be directed to Blue Coat Technical Support.