Firmware Management

Manage all aspects of installing a new firmware for the StoredSafe appliance

  • Show current firmware version

  • Validate and install new firmware

  • Select primary and secondary boot image

  • Delete boot images

  • View or install StoredSafe public PGP key used to sign new firmware and system features

The appliance keeps two boot images at a time — primary and secondary — plus whatever other images you haven’t deleted yet. Installing a new image does not overwrite anything; it only becomes active once you explicitly select it as primary and reboot. This gives you a straightforward rollback path: if a new firmware version misbehaves, reboot and select the previous image as primary again, or the appliance will already have the old image as secondary depending on how you set it up. All images are signed, and the console refuses to install one that fails PGP signature verification against the installed StoredSafe signing key (item 5, “Install StoredSafe PGP signing key”, below).

Note

This page covers the low-level mechanics of installing an image. For the full step-by-step upgrade procedure per assurance level (including HA pairs), see Upgrading StoredSafe.

┌────────────────────────────────────────────────────────────────────────────┐
│                  Firmware on node1 (Version X.X.X build XXXX)              │
└────────────────────────────────────────────────────────────────────────────┘

┌─┬──────────────────────────────────────────────────────────────────────────┐
│1│Show current firmware                                                     │
│2│Validate and Install new firmware                                         │
│3│Select boot image                                                         │
│4│Delete boot image                                                         │
│5│Install StoredSafe PGP signing key                                        │
│6│View installed PGP keys                                                   │
└─┴──────────────────────────────────────────────────────────────────────────┘

Move the cursor or enter a it's corresponding number (Q to Quit)

Main> System Settings> Firmware>

Show current firmware

Active firmware

Primary image:   StoredSafe-2.0.2-build5771 (storedsafe-primary.iso) 349622Kb
Secondary image: StoredSafe 2.0.0-rc1-build5681 (storedsafe-secondary.iso) 388929Kb

System is booted from StoredSafe-2.0.2-build5771

Press any key to continue

Validate and Install new firmware

Active firmware

Primary image:   StoredSafe-2.0.2-build5769 (storedsafe-primary.iso) 349622Kb
Secondary image: StoredSafe 2.0.0-rc1-build5682 (storedsafe-secondary.iso) 358656Kb

System is booted from StoredSafe-2.0.2-build5769

Insert a USB disk and press enter when ready. Ready? (<Y>/n): y

Available files in /mnt/usb:

StoredSafe-2.0.2-build5770.iso
StoredSafe-2.0.2-build5770.iso.sign

Enter filename of new firmware? (Q to Quit) <StoredSafe-2.0.2-build5770.iso>:
Good PGP signature by "StoredSafe ISO signing key (www.storedsafe.com) <build@storedsafe.com>" using RSA key ID 31A59B90

Install "StoredSafe-2.0.2-build5770.iso" in "/isodevice/boot/images/"? (<Y>/n): y
New firwmare installed successfully.

Activate "StoredSafe-2.0.2-build5770.iso" for next reboot? (<Y>/n): y
New firwmare activated successfully. Reboot the appliance at a convenient time.

Press any key to continue

Select boot image

Active firmware

Primary image:   StoredSafe-2.0.2-build5771 (storedsafe-primary.iso) 349622Kb
Secondary image: StoredSafe 2.0.0-rc1-build5681 (storedsafe-secondary.iso) 388929Kb

System is booted from StoredSafe-2.0.2-build5771

Available images in /isodevice/boot/images/:

Storedsafe-2.0.0-rc1-build5681.iso [Secondary boot image]
Storedsafe-2.0.0-rc1-build5682.iso
StoredSafe-2.0.0-rc1-build5687.iso
StoredSafe-2.0.0-rc1-build5688.iso
StoredSafe-2.0.2-build5771.iso [Primary boot image] (* Active image)

Primary boot image? (Q to Quit) <StoredSafe-2.0.2-build5771.iso>:
Selecting "StoredSafe-2.0.2-build5771.iso" as the primary boot image
Secondary boot image? (Q to Quit) <StoredSafe-2.0.2-build5771.iso>: Storedsafe-2.0.0-rc1-build5682.iso
Selecting "Storedsafe-2.0.0-rc1-build5682.iso" as the secondary boot image
Activate changes? (<Y>/n):
New primary firwmare set successfully
New secondary firwmare set successfully

Press any key to continue

Delete boot image

The currently-booted image cannot be deleted. Deleting an older image that you would otherwise have used as a rollback target removes that rollback option — keep at least the previous known-good image around until you’ve verified the new one in production.

Active firmware

Primary image:   StoredSafe-2.0.2-build5771 (storedsafe-primary.iso) 349622Kb
Secondary image: StoredSafe 2.0.0-rc1-build5682 (storedsafe-secondary.iso) 358656Kb

System is booted from StoredSafe-2.0.2-build5771

Available images in /isodevice/boot/images/:

Storedsafe-2.0.0-rc1-build5681.iso
Storedsafe-2.0.0-rc1-build5682.iso [Secondary boot image]
StoredSafe-2.0.0-rc1-build5687.iso
StoredSafe-2.0.0-rc1-build5688.iso
StoredSafe-2.0.2-build5771.iso [Primary boot image] (* Active image)

Remove image? (Q to Quit) <StoredSafe-2.0.2-build5771.iso>: StoredSafe-2.0.0-rc1-build5687.iso
Ok to remove "StoredSafe-2.0.0-rc1-build5687.iso"? (<Y>/n):
Are you sure? (<Y>/n):
"StoredSafe-2.0.0-rc1-build5687.iso" removed successfully

Press any key to continue

Install StoredSafe PGP signing key #################################-

Import StoredSafe PGP Signing Key

StoredSafe PGP signing key with RSA key ID 31A59B90 imported successfully.

Press any key to continue

View installed PGP keys

Show PGP Public Keys

pub   4096R/0B030231 2014-12-28
      Key fingerprint = C80C E6E6 8F60 DF12 9849  0917 F6A2 DDF5 0B03 0231
uid                  Backup User #1 <backup.user.one@corp.com>
sub   4096R/8631C269 2014-12-28

pub   4096R/3055099F 2014-12-28
      Key fingerprint = 7190 E05A B514 0868 8980  307F 90DB 5539 3055 099F
uid                  Backup User #2 <backup.user.two@corp.com>
sub   4096R/4D56DF61 2014-12-28

pub   4096R/31A59B90 2014-05-14
      Key fingerprint = 5B0A D38D EED0 37A3 D11B  DF07 2EA9 5E6F 31A5 9B90
uid                  StoredSafe ISO signing key (www.storedsafe.com) <build@storedsafe.com>
sub   4096R/6C03E333 2014-05-14


Press any key to continue