Description

 

This article explains why the Signature Database update may fail in Contrail Service Orchestration (CSO) and what must be done to succeed with the update.

 

Symptoms

 

The following exception is seen on the Signature Database page:

alt

 

Solution

 

The issue is on the signatures platform. ​Recently, the server that hosts the signatures bundle, signatures.juniper.net , was moved from Apache to AWS deployment.

The new service is not accepting the URL format that is used by the signature manager due to which the signature downloads are failing.

 

 

Use the following workaround if you are using CSO version 5.1.2.

Note: If you are using an earlier version of CSO, upgrade to CSO 5.1.2 and apply the following workaround.

  1. Log in to CSO as cspadmin .

  2. To download the signature database, do the following:

    1. Select Administration > Signature Database .

The Signature Database page appears.

  1. Click Signature Download Settings .

The Signature Download Settings page appears.

  • Download URL: This specifies the location of the Juniper hosted server from which the signature database is downloaded to the CSO server. The default download URL is https://signatures.juniper.net/ . Change this to https://signatures.juniper.net (without the trailing "/" character).

    Note: To download signatures from this location, Internet connectivity must be available from CSO.

  • Signature Version: This is where you enter the signature database version (example 3324).

  1. Click OK to save the changes:

If you specified that the signature database should be downloaded immediately, a Job Tasks page appears displaying information about the signature download job. Click OK to close this page and return to the Signature Database page.

Note: Contact Support if you are on CSO 5.1.2 version and need additional information about this issue.