Release Notes PN 93000490_N Digi CM Firmware 80007059_M (Digi CM 8) 80007051_M (Digi CM 16) 80007050_M (Digi CM 32) 80007070_M (Digi CM 48) v 1.7.0 June 17th, 2005 INTRODUCTION This is the production release of firmware for the Digi CM. These devices provide console management access to various servers, devices, and systems that may be accessed by a serial cable to a console port. These devices feature console management through a console menu or web interface to allow configuration of network settings, serial settings, administration settings, and user settings. High-end features include Telnet/SSHv1/SSHv2/RawTCP protocols, Local, RADIUS, TACACS+, and LDAP authentication, Port logging through Local, NFS, and Memory cards, PCMCIA slot and configuration, custom menus, keyword monitoring and SMTP/SNMP notification, 10/100 mbps Ethernet network interface, and Digi Discovery server to allow discovery and network configuration from the Digi Discovery Applet. SUPPORTED PRODUCTS Digi CM 8 Digi CM 16 Digi CM 32 Digi CM 48 Enhancements - Added the ability to remote authenticate to CLI. - Added the ability to view the slave units Port Titles when Clustered. - Added Access list so that custom groups can be added. - Enhanced login password security. - Added Port connect/disconnect message to the system log files. - Added option to disable SNMP. - SSH v1 is disabled now by default. - Added a message to system log if a port was connected/disconnected. - The system up time is now displayed in the Web UI. - Fixed problem where Save acknowledgment message shows up in a wrong browser window. - Added the ability to detect if a device is attached to the port. - Added the ability to disable the global port escape menu. - Added the ability to set a minimum password length. - Added password aging. - Added the ability to disable SNMP via Web UI / config menu. - Added login/logout messages to the system logs when people login to the CLI. - Added SNMP and email notification if NFS server is disconnected. - Added the ability for Clustering and SSH to connect to ports via the port title. - Added the ability to issue commands via the Automated TFTP upgrade utility. - Changed the default state of Alternate IP to disabled. - Added Automated configuration backup. - Changes to Syslog facility now take effect immediately. - Added Custom PAM module support. - Upgraded the TACACS+ package. - Enhanced response time for Radius authentication. - Added option to enable/disable automatic backup of syslogs and port logs when mounted Flash Card or NFS server. - Added Digi ADDP support. Improvements - Fixed problem When using custom menus. Adding an item to execute a command failed if it requires input. - Fixed problem with disconnecting a sniff session that caused a port lock up. - IP filtering settings are now preserved when upgrading the firmware. KNOWN LIMITATIONS - Web UI, Discovery Applet, and Serial Connection Applet require Netscape 4.76 or higher or Internet Explorer 5 or higher. - The Discovery Applet and Serial Connection Applet also require the Java Runtime Environment (JRE) 1.3 or higher. - Netscape 4 on Windows: the serial port connection applet will not accept so the user cannot login through the applet. - Using cancel button when removing Custom Menus or Copying custom menus causes the page to be submitted and the menus removed or copied, respectively. To cancel without causing this effect, use the browser's Back button. - When using RealPort, the IP-Address of the Digi CM has to be entered manually. - Using SSHv2 (which is the default) with the JTA will cause noticeable latency. To resolve: Switch to SSHv1 with the JTA. - Kerberos authentication has been removed. If you require Kerberos support, download the CM utilities file (80007071) from the digi web site. Copy kinit to the /usr2 dir on the Digi CM. ADDITIONAL INFORMATION - When using the SUN Java Runtime Environment in Windows, you may need to verify the browser you are using has been enabled with the Java plug-in. To verify, use the following steps: 1. Go to Control Panel in Windows (may be accessed through My Computer or Start menu) 2. If you are using "Category View", click "Switch to Classic View". 3. Click Java Plug-In icon. (if this icon does not exist, verify JRE is correctly installed) 4. Click on the "Basic" tab. 5. Verify "Enable Java Plug-In" is checked. 6. Click on the "Browser" tab. 7. Verify appropriate browser or browsers are checked. 8. Click on the "About" tab. 9. Verify Java Plug-in version is 1.3 or later. - When upgrading releases prior to 1.3.2, Digi advises you to factory default and reconfigure the CM after upgrading the firmware. If upgrading from rev. 1.3.2 or greater, importing configs will work with the exception of the “Serial port->User access control” section. History 93000490_M: v1.6.5 01-20-2005 - The Digi CM now supports RealPort Com Port redirection. During the configuration of RealPort on the client, the IP address of the Digi CM has to be entered manually. - The SNMP capabilities have been extended. A new MIB has been released adding the ability to read and write parameters of the Digi CM using SNMP. After any parameters have been changed, they have to be saved and activated by writing to the OID: generalSaveApplyConfig. - A regular user with access rights to a port can now access the Microsoft SAC pages. - The IP filtering will be reset by factory default without factory defaulting the IP settings. - Custom port log file names now work with the SAC web page. - Fixed problem where CM would hang upon boot if bad a cable is connected to a port and using Hardware flow control. - Fixed problem with "configmenu" where the "All Ports" option would fail to set user access controls. - Fixed problem in "configmenu" where you could not export a config to the local machine. - Fixed problem with Active Detection that caused an undo amount of entries in the System logs. - Fixed problem where the routing table would not get flushed until after a reboot if the gateway was changed. - Fixed memory leak with Active Detection when the detection scripts are not present. 93000490_L: v1.6.0 06-21-2004 - Added Automatic Device Recognition - Added support for Rackable Systems Management Controller - Added support for the Digi RPM power controller - A message is sent out if the port is closed as another user is active - Added support for automatic TFTP firmware upgrade upon boot - Added MD5 support to validate passwords longer than 8 characters - Added support for read only access to ports - Upgraded OpenSSH to V3.8.1p1 - Added support for Radius down local authentication - Added support for special characters in passwords - Added support for longer descriptions in SNMP fields 93000490_K: v1.5.0.4 06-21-2004 - Added support for new Digi CM 48 hardware revision 93000490_J: v1.5.0 04-22-2004 - Added an option to "Change Password" in the Port Access Menu. - Users may use variable names for port logging. - Added support for "Netgear FA411" PCMCIA Ethernet card. - Added modem dial-in support to "Console Port". - Turning DHCP on will now set DNS to auto. - Upgraded OpenSSH to 3.7.1p2 and OpenSSL to 0.9.6m - Users now have the option to disallow "root" access from everything except when using the CM console port. - Web UI now reconnects to login page after reboot or firmware upgrade. - Added ability to configure a secondary IP Address so "Clustering slaves" may be addressed using non routable IP address. - Added the ability to change root password through Web UI. - Added "SNMP Login trap" support to the "Dialin Modem". - Added email alert notification to serial port SNMP traps. - Removed the ability to disconnect existing users via port access menu. - Implement "Global SNMP Trap" receiver settings. - Added support for SecurID's "new Pin" and “next Token Code" mode. - Added ability to show bootloader revision during system operation. - Added notification in Web UI for port events. - Added bi-directional data logging on serial ports. - Added option to show last 10 lines of unread data when connecting to a port. - Serial ports support 45 character user names for remote authentication. - Added ability to local users to remotely authenticate to clustered ports. 93000490_I: Skipped 93000490_H: v1.4.0 12-20-2003 - Provide download utilities cron, fuser, and netstat - Updated Web UI to present configurable options only - Web UI now displays logged in web user - Improved error reporting during SAC connection failures - Added direct URL support to access the Java Telnet application - Enhanced LDAP support by adding OU to the search path - Added Japanese language support to SAC - Added Japanese language and UTF-8 support to the Java Telnet application - Added configurable escape sequence which will return user back to the custom menu - Added power management support - Added Daylight savings time support - Port title can be used as an alias for the port number when SSH or Telnet to port - Administrative users now have the ability to disconnect users from ports through the Web UI - Added the ability to use the host name for the CLI prompt instead of the IP - Added Corega LAN Card Support - Added the ability to use the DNS name of an NFS server instead of the IP - The "hosts.cnf" file is now user editable - Added port reset command to the CLI - CM will now continue sending DHCP requests if DHCP fails 93000490_G: v1.3.2 10-03-2003 - Updated SSH to correct problem specified in advisory. 93000490_F: v1.3.0 09-08-2003 - Added SNMP Trap on CTS On/Off per serial port - Added enable/disable button for the First SMTP server - Improved Configuration File Importing / Exporting - Automatic notification when initiating a sniff session. - Added SNMP support for login traps. - Added option in WEB UI to config menu that will disable telnet to the Digi CM. - Added a 'send break' option via the Digi CM telnet client. - Added the ability to view active user and reset "stuck" port from the WebUI. - Added second trap receiver for Keyword Alerts. - Added IP of the slave units in the "Port access menu". - WEB UI - User Admin - Just click on the user instead of selecting "edit". - Added configurable port break sequence. - Added visible IP address when using DHCP with a wireless card. - Added Orinoco wireless PC Card support. - Added confirmation request before killing a process with SAC command. - Added encrypted NFS. 93000490_E: v1.1.3 07-11-2003 - Added support for PC Modem Cards Multitech, Starlogic, Actiontec, and Zoom - Change Unit # on clustering connection page of Web UI from numeric character to alphabetic character. 93000490_D: NA 93000490_C: v1.1.0 05-12-2003 - Added Microsoft System Special Administration Console (SAC) support. - Added Shadow password support. - Added ability to switch directly between serial port configuration pages - Port Access Menu to access slave units in clustered scenario. - Add option to launch telnet session instead of Java applet for port connection. - Added support for Kerberos authentication. - Added remote Authentication to WebUI. - One Step Save and Apply. - Configurable escape sequence per port. - Checkbox to allow all users with port access to sniff. - Added ability for sniff users to switch between read only access and read/write access on a port. - Added an in-use and by-use comment field in serial port connection screen. - Customizable port log filename to NFS Server. - Reduce character limit of usernames down to 3. - Add secondary NFS Server option for System and Port logs. - Add Date/Time stamp option to Port logs. - Use LED graphics in the web UI instead of on/off text. - Added SNMP trap for alert. - Added prompt before sending break key to applet window. - Increased limit of sniff sessions per port to 15. - Upgraded SSH Client to current version (3.5p1) - Added the ability to disable Alt. IPs. 93000490_B1: v1.0.03.01 05-21-2003 - Port lockup with F-Secure or SSH 3.2.3 clients is fixed 93000490_A1: v1.0.03 03-06-2003 - Bug for WYSE dumb terminals support is fixed - Bug for setting the date in the bootloader is fixed - Bug for setting the system time in the bootloader is fixed 93000490_A: v1.0.02 02-26-2003 - Initial release