Junos OS

last person joined: yesterday 

Ask questions and share experiences about Junos OS.
  • 1.  Ex 3300 Upgrading Software verify-sig: cannot validate certs.pem

    Posted 11-24-2017 00:58

    from 12.3 upgrading 15.1 ver

     

    Model: ex3300-48t
    JUNOS Base OS boot [12.3R10.2]
    JUNOS Base OS Software Suite [12.3R10.2]
    JUNOS Kernel Software Suite [12.3R10.2]
    JUNOS Crypto Software Suite [12.3R10.2]
    JUNOS Online Documentation [12.3R10.2]
    JUNOS Enterprise Software Suite [12.3R10.2]
    JUNOS Packet Forwarding Engine Enterprise Software Suite [12.3R10.2]
    JUNOS Routing Software Suite [12.3R10.2]
    JUNOS Web Management [12.3R10.2]
    JUNOS FIPS mode utilities [12.3R10.2]

     

     

    root> ...ll-ex-3300-15.1R6.7-domestic-signed.tgz reboot

    [Dec 7 20:31:37]: Checking pending install on fpc1

    [Dec 7 20:31:39]: Validating on fpc1
    [Dec 7 20:32:11]: Done with validate on all virtual chassis members

    fpc1:
    Verify the signature of the new package
    tar: +CONTENTS: time stamp Apr 23 02:10 2017 is 11770634 s in the future
    tar: +COMMENT: time stamp Apr 23 02:10 2017 is 11770634 s in the future
    tar: +DESC: time stamp Apr 23 02:10 2017 is 11770634 s in the future
    tar: +INSTALL: time stamp Apr 23 02:10 2017 is 11770634 s in the future
    tar: jinstall-ex-3300-15.1R6.7-domestic.tgz: time stamp Apr 23 02:09 2017 is 11770585 s in the future
    tar: jinstall-ex-3300-15.1R6.7-domestic.tgz.md5: time stamp Apr 23 02:09 2017 is 11770597 s in the future
    tar: jinstall-ex-3300-15.1R6.7-domestic.tgz.sha1: time stamp Apr 23 02:09 2017 is 11770588 s in the future
    tar: jinstall-ex-3300-15.1R6.7-domestic.tgz.sig: time stamp Apr 23 02:09 2017 is 11770588 s in the future
    tar: jinstall-ex-3300-15.1R6.7-domestic.tgz.esig: time stamp Apr 23 02:09 2017 is 11770592 s in the future
    tar: certs.pem: time stamp Apr 22 22:27 2017 is 11757260 s in the future
    tar: ecerts.pem: time stamp Apr 22 22:27 2017 is 11757260 s in the future
    verify-sig: cannot validate certs.pem
    certificate is not yet valid: /C=US/ST=CA/L=Sunnyvale/O=Juniper Networks/OU=Juniper CA/CN=PackageProductionRSA_2017/emailAddress=ca@juniper.net

    ERROR: Package signature validation failed. Aborting install.

     

     



  • 2.  RE: Ex 3300 Upgrading Software verify-sig: cannot validate certs.pem
    Best Answer

    Posted 11-24-2017 01:03

    You need to configure time correctly on your EX3300 before upgrading. Otherwise the certificate used to sign the install package is not valid yet seen from the switch perspective 🙂

     

    user@srx> set date ?
    Possible completions:
    <time> New date and time (YYYYMMDDhhmm.ss)
    ntp Set system date and time using Network Time Protocol servers