Configuring Software Signature Verification

The Software Signature Verification feature enforces that only IBM-signed upgrade files can be used as part of the upgrade procedure.

About this task

Validity of the signature is verified by both the IBM Cloud Object Storage Manager™ upon upload and by each device as it upgrades. Upgrades will fail if the signature is not valid.
Note: All devices as well as the IBM Cloud Object Storage Manager™ must be upgraded to ClevOS 3.15.7 or later to use the Software Signature Verification feature.
  • If you receive a message that Software Signature Verification failed and you have never enabled this feature, you can still proceed to upgrade each device.
  • If Software Signature Verification was never enabled, you can still upgrade each device.
  • If Software Signature Verification was never enabled and has not been permanently disabled, then you can still upgrade each device.
  • If Software Signature Verification was enabled and subsequently disabled, you must permanently disable it using this procedure before performing a device upgrade.

Procedure

  1. Navigate to Settings > Operations > Software Signature Verification
    The Software Signature Verification page appears and displays whether Software Signature Verification is enabled or not.
  2. Toggle the button to Enable or Disable Software Signature Verification.
    Once enabled, devices will begin to verify an embedded signature in uploaded upgrade files as part of the upgrade procedure. If the feature is disabled, a warning message will appear that indicates that the following steps are required for permanent disablement. These steps must be performed on each device in addition to the IBM Cloud Object Storage Manager™.
    1. ssh into the target device as a user with root access.
    2. Execute this command: disable-signature-verification.
  3. Click Save.