=============================================================================== Intel(R) Server Platform Integrated BMC Firmware Release Notes =============================================================================== INTEL(R) Server Boards and Systems Intel Corporation 2111 N.E. 25th Avenue, Hillsboro, OR 97124 USA =============================================================================== DATE: 19 October 2021 TO: Intel(R) Server Board M50CYP/D50TNP/D40AMP SUBJECT: Integrated BMC(R) firmware 2.87 release notes =============================================================================== LEGAL INFORMATION =============================================================================== Information in this document is provided in connection with Intel products. No license, express or implied, by estoppel or otherwise, to any intellectual property rights is granted by this document. Except as provided in Intel's Terms and Conditions of Sale for such products, Intel assumes no liability whatsoever, and Intel disclaims any express or implied warranty, relating to sale and/or use of Intel products including liability or warranties relating to fitness for a particular purpose, merchantability, or infringement of any patent, copyright or other intellectual property right. Intel Corporation may have patents or pending patent applications, trademarks, copyrights, or other intellectual property rights that relate to the presented subject matter. The furnishing of documents and other materials and information does not provide any license, express or implied, by estoppel or otherwise, to any such patents, trademarks, copyrights, or other intellectual property rights. Intel products are not intended for use in medical, life saving, or life sustaining applications. Intel may make changes to specifications and product descriptions at any time, without notice. Intel is a registered trademark of Intel Corporation. *Other names and brands are the property of their respective owners. Copyright (c) 2021 Intel Corporation. A portion of this firmware is open source code. The OSS source code that the customer is entitled to per OSS license has been posted on the Intel support website at the following link: http://downloadcenter.intel.com/Detail_Desc.aspx?agr=Y&DwnldID=21081 This open source code falls under the GPL 2.0 license, please see the license at the following link: http://www.opensource.org/licenses/gpl-2.0.php =============================================================================== ABOUT THIS RELEASE PACKAGE =============================================================================== M50CYP Source file: CoyotePass-bmc_prod_signed_cap_2.87.be6beeae.bin D50TNP Source file: TennesseePass-bmc_prod_signed_cap_2.87.be6beeae.bin Built from git revision: be6beeae6f511e8cbb2a6e4da1d8b318203a579a REVISION INFORMATION RETURNED BY GET DEVICE ID COMMAND: Operational mode: 2.87.be6beeae CYP Product ID: 0x0098 TNP Product ID: 0x0099 AMP Product ID: 0x00AA Manufacturer ID: 0x000157 SHA1 checksum: CoyotePass-bmc_prod_signed_cap_2.87.be6beeae.bin: 6e894eb545aba87a4911d942ad5830dd9b39f111 TennesseePass-bmc_prod_signed_cap_2.87.be6beeae.bin: 2d108fb032390f3f6862209c8d26eae3c4b66a88 JAVA Certificate: from: Thu May 27 08:00:00 CST 2021 UTC/GMT+08:00 until: Sat May 28 07:59:59 CST 2022 UTC/GMT+08:00 Embeds firmware files for the following components: Power Supplies 1100ADU00201 00: 54.1.1 1100ADU00201 01: 54.1.1 1100ADU00201 02: 54.1.1 1100ADU00201 03: 54.1.1 1100ADU00201 04: 54.1.1 1100ADU00201 05: 54.1.1 1100ADU00201 S3: 54.1.1 DPS-1200TB A 00: 77.39.4 DPS-1200TB A 02: 89.40.6 DPS-750AB32A S0: 33.3.3 DPS-750XB A S4: 100.39.5 DPS-900AB-5 E 00: 13.13.0 DPS-900AB-5 E S3: 12.12.0 PSSF132202A 00: 23.5.0 PSSF132202A 01: 23.5.0 PSSF132202A 03: 25.5.0 PSSF132202A S3: 23.5.0 PSSF162202A 00: 75.9.0 PSSF162202A 01: 75.9.0 PSSF162202A 02: 75.9.0 PSSF162202A 03: 75.9.0 PSSF162202A 04: 75.9.0 PSSF162202A 05: 78.9.0 PSSF162202A 06: 78.9.0 PSSF162202A 07: 78.9.0 PSSF162202A 08: 78.9.0 PSSF162202A 09: 78.9.0 PSSF162202A 11: 78.9.0 PSSF162202A 11: 78.9.0 PSSF162205A 00: 18.4.0 PSSF162205A 01: 18.4.0 PSSF162205A 02: 18.4.0 PSSF212201A 00: 12.3.0 PSSF212201A 01: 14.3.0 PSSF212201A S3: 12.3.0 PSSF222201A S4: 33.0.0 Hot Swap Backplane V1 HSBP: 1.22 V1 HSBP: 1.33 V2 HSBP: 2.08 V2 HSBP: 2.09 TNP EDSFF: v1p7 CYP HSBP: v2p00 AMP HSBP: v1p0 CYP/TNP Astera retimer FW 1.2.0 AMP Astera retimer FW 1.7.0 BMC PFR SVN: 1 Firmware Update Tools: Sysfwupdt 14.2 Build 11 * NOTE The PSSF222201A 00A or newer identifies itself as a PSSF222201A S4 internally. Please use that firmware version when referencing that PSU. ------------------------------------------------------------------------------- =============================================================================== IMPORTANT INSTALLATION NOTES =============================================================================== The following update process must be followed to ensure a trouble free updating of your baseboard. The order is important to minimize any issues for status checking as different components are initialized. 1. BMC firmware 2. BIOS/Manageability Engine (ME) firmware (as directed in BIOS Release Notes) 3. FRU/SDR package specific to the baseboard. 4. NIC EEPROM =============================================================================== INSTALLATION PROCEDURE =============================================================================== There are two supported ways to update the BMC firmware. You may opt to use the Web UI or the legacy UEFI method. Web GUI update 1. Unzip the package onto your system 2. Log into the BMC web UI 3. Navigate to Configuration, then Firmware Update 4. Click browse, and direct the browser to the location of - CoyotePass-bmc_prod_signed_cap_2.87.be6beeae.bin or - TennesseePass-bmc_prod_signed_cap_2.87.be6beeae.bin or 5. Click upload. Progress and status will be shown as the update progresses UEFI update 1. Unzip package and load onto a flash drive 2. Boot to UEFI shell, and navigate to the folder where this package lives 3. Run cypFwUpdateBMC.nsh or tnpFwUpdateBMC.nsh and follow prompts =============================================================================== FIRMWARE UPGRADE/DOWNGRADE PROCEDURES =============================================================================== Upgrade of BMC FW from version 2.87 to later versions will be documented in the release notes for those versions. Reverting to a lower version of firmware may have unexpected side effects, including but not limited to user settings reset to defaults, and will always result in the loss of functionality which was present in the higher version but was not implemented in the lower version. We do not guarantee that any downgrade will operate without side-effects. Always observe caution when downgrading firmware. =============================================================================== KNOWN ISSUES/WORKAROUNDS/REQUIREMENTS =============================================================================== WARNING: If there is a retimer update process shown on the screen, the whole process will cost about 15 minutes to 20 minutes. Please do not interrupt. WARNING: This release disables RMCP authentication by default. ipmitool uses RMCP by default, so it will fail to authenticate. Add the '-I lanplus' parameter to all ipmitool commands to use RMCP+ instead. WARNING: This release disables the BMC PCIe bridge. This will cause a majority of operating systems to fail to boot as they stall during video driver init. More information can be found in the defect below: 1209995146 - Host OS fails to boot when AST2500 P2A bridge is disabled. WARNING: When using IPMI to establish a SOL session using KONSOLE: A. The "Delete" input cannot be captured when pressing "Backspace" Workaround: Modify the "Backspace" key to "0x08" in the KONSOLE profile keyboard settings B. Resizing a KONSOLE window with an active SOL session can cause the content to overlap Workaround: None. Recommend using the Java SOL Viewer instead of KONSOLE Steps to recover a failing OS: Linux variants (one of the below): A. Ensure that the nomodeset parameter is set in your boot loader (grub) config. B. Ensure that you are using a kernel version of 4.10 or above Windows variants: Boot to safe mode, and load aspeed video driver v1.03 or greater and reboot Redfish API: Redfish API POST requests using a browser extension or plugin will fail if the extension manipulates the HTTP(S) Origin header. This affects REST clients which are implemented as browser (chrome, Firefox) plugins or extensions such as the older versions of Postman. It is recommended to use Postman version 6.0 or later. For security purposes, the BMC Redfish API requires that if a HTTP Origin header is present, the host portion of the Origin header must match the HTTP Host header. Some browser based REST clients alter the Origin header preventing their use with the BMC. WARNING: Start from BMC v1.89, by default BMC only enables cipher suite 17, to use that, you must add "-C 17" in ipmitool command. WARNING: Start from BMC v2.21, When KCS control mode is put in restricted and deny all mode, BMC EWS CPU and DIMM page displays blank or last DC on configuration information. WARNING: IPMIUtil can not support user password length larger than 16 bytes. WARNING: When KCS policy control mode is configured as "Deny All", BMC and FRUSDR cannot be upgraded/downgraded as expected behavior. =============================================================================== MISC =============================================================================== Vers BMC Version Changes… v2.81 2.81 Resolve in-band update issues & update Retimer to v1.2.0 & update HSBP CPLD version: v1.90 v2.87 2.87 Update EDSFF to v1p7. v2.87 2.87 Exit Air Temp (#0x2E) CRITICAL event: Exit Air Temp reports the sensor is high state. v2.87 2.87 Change #Sensor_Number display to desired Sensor Name v2.87 2.87 without expected event log after update BMC and BIOS/ME in BMC force update mode. v2.87 2.87 Correct HDD Drive Set/Get Fault LED State Check v2.87 2.87 Fix there is no channel3 on TNP(AT2 network adapter) v2.87 2.87 Align CPU names with BIOS v2.87 2.87 Fix klocwork errors v2.87 2.87 Revert "[Whitley][Feature][VM]Support IMG/IMA media type" v2.87 2.87 Complete CCB3418 & Fix CA signed cert issue & Fix remote folder mount issue & SG1 card FRU support v2.87 2.87 Fix Global Fault LED ON issue v2.87 2.87 Add Retimer handshaking with BIOS (Part 2) v2.87 2.87 [CCB 3432] Remove option to update NVRAM in EWS and Redfish v2.87 2.87 Hotfix for HSD: 1508772959,1509923459,1509883596 v2.87 2.87 Fix for "System Air Flow" sensor reading. FRUSDR 0.38 for SG1 Support. v2.87 2.87 Remove ".cap"/".bin" restriction on EWS BIOS update. =============================================================================== CHANGES =============================================================================== v2.87 - Remove ".cap"/".bin" restriction on EWS BIOS update - Fix for "System Air Flow" sensor reading. FRUSDR 0.38 for SG1 Support. - Hotfix for gating issue HSD-1509883596 - Fix gating issues: HSD-1508772959 HSD-1509923459 - [CCB 3432] Remove option to update NVRAM in EWS and Redfish - [CCB 3430] Modify BIOS setup behavior around complex password(Sync up Purley CCB3356 to Whitley) - [CCB 3418] Display message on screen when system is in T-1 and BMC is up - [CCB 3471] Detect SG1 card and set thermal profile to support 4 x SG1 cards, BIOS change refers from CCB #3030 - Add MTM check before applying FRU assigning policy (#51) - Renew the Java certificate date - Fix build flow process (#46) - Fix syslog 3.33.2 config file not conpatiable (#44) (#45) - Fix klocwoek issues. (#40) - Patch CVE-2021-35942 CVE-2021-38604 on glibc-2.29-INTEL_RELEASE - update syslog-ng to 2.33.2 (#33) - add CY8C29566 posc FW. add failover mechanism. (#32) - Increase ERROR_EXT_INFO_MAX to 1024 (#31) - Use internal image size instead of fixed size (#30) - JavaAP check if own the device before unmount it when terminating. (#29) - Fix parse the wrong filename with PutFileToImage (#28) - Fix Login to EWS with LDAP or AD users, there shows a new added "CPLD Update" option in the "Configuration" menu. (#27) - Fix SUT will fail to connect to the SSH console after change default port number to other port. (#25) - update kernel to 4.9.282 (#23) - update openssl to 1.1.1l (#22) - update glib to 2.69.2 (#21) - Add Retimer handshaking with BIOS (Part 2) - Read and check SSD type - Enable EWS -> BIOS Configurations -> System Event Log - Fix Global Fault LED ON issue - Add Retimer handshaking with BIOS - Revert "[AMP] Add retimer version 1.9.0" - Support multi-node HSBP CPLD FW online update - Add HSBP CPLD FW v1p0 - Correct CPU names in CPU/Memory VRD Hot SEL - Fix IPMI CMD_SET_HDD_DRIVE_FAULT_LED_STATE - Fix it pops up an empty dialog box when replace a new certificate - Fix the SSH console is still active when disable SOL SSH in EWS - Forbid "SC" HSBP to update FW - There is no link to channel 4 in redfish after enable HOST interface - Forbid "SC" HSBP to update FW - Use raw 0x06 0x52 0x8 0xb0/0xb2/0xb8 0x2 0x0 to check - SG1 FRU support - Unable to boot up into OS successfully if plug in the folder remotely via HTML5. - Repair code lacks fault tolerance processing - Fix the ca signed of the 4096-bit SSL certificate are error - After BMC online update, the “Tcontrol modifier value” will be set as 80(Hex) which is not synced to the value of “exit air temp” setting of BIOS. - Update TNP EDSFF to v1p7 - Fix HSBP update hang issue - CCB 3418 Display message on screen when system is in T-1 and BMC is up - Revert "[Feature][VM]Support IMG/IMA media type" - Re-order Platform Event Filter Table - Fix klocwork errors - Fix abnormal in the restore BMC with checking "Keep User and LAN configuration" - Cannot Send alert email when set the SMTP authentication - The "PercentComplete" always is 60 when simple update BMC via redfish. - Fix the issue that asm key page appears on purley - There are four channel options in EWS->VLAN Settings->LAN Channel. - Fix img file can not be read on the host by WEBISO. - Add a protection mechanism for httpd. - Fix CA signed cert uploading issue on Redfish - Fix can't upload ca signed cert. - With three virtual media devices mounted by HTML5, MountImage should return Bad Request - Align CPU names with BIOS - update kernel to 4.9.279 - update monit to 5.28.1,glib to 2.69.1,curl to 7.78.0 - The boot order can't be changed via redfish - Fix KW issues 69346, 69347 - The DIMM location is incorrect for "Mem err Sensor" SEL in EWS. - Change KVM secure port value, open KVM/HTML5 session and it will be disconnected auto - Fix there is no channel3 on TNP(AT2 network adapter) - Correct HDD Drive Set/Get Fault LED State Check - There is no link to channel 4 in redfish after enable HOST interface - Return 400 Bad Request if encounter error with file upload in Redfish - Disconnect virtual media and remount to BMC with UmountImage - Fix corrupted HSBP CPLD FW - Missing size limition definition for VM over HTML5 help page. - Patch CVE-2021-33574 on glibc-2.29-INTEL_RELEASE and fix kernel z version error - Update HSBP CPLD FW to v2p00 - Combine HSD 1509355132 and KW issue: 69306 fixes - sometimes the NV directory data (bmc ip/user name/pwd/sdr) would be clean after online update bmc to 2.82 - BMC Lan IP address will be cleared after updating BMC FW to 2.83b under EFI shell - The NTP server IP can't be set successfully when NTP server IP is xxx.xxx.xxx.1~9 in EWS - Add HSBP CPLD FW v0p9 - Support HSBP CPLD FW downgrade - R_version BIOS update informations show incorrect in SEL(regression issue) - lighttpd upgrade to 1.4.59 - update kernel to 4.9.276 - without expected event log after update BMC and BIOS/ME in BMC force update mode. - FAB4 HSBP supports v1p9 downgrading to v1p8 - Change #Sensor_Number display to desired Sensor Name - Fix Klocwork issue: 69306 - Fix HSBP CPLD not initialized properly after reboot - Add retimer version 1.9.0 - Remove impact of abnormal high voltage waveform to raid card - Fix The Mount type is missing NFS in web ISO help page issue. - Fix Alert events cannot be selected whe click "Check All" button - There is an extra character '<' in the Date&Time help page in the Chinese EWS - Riser card FRU is corrupted when AIC card is installed in MTM1 mode. - The Integrated IO Configuration of EWS BIOS Configuration function tab is blank. - Upgrade glib to 2.69.0 and kernel to 4.9.274 - Fix HDD Power LED ON issue even if the node is offline - Fix SSD abnormal temperature - Add HSBP CPLD FW v0p8 - Add missing sensor records wrt PS4 - Additions / Corrections wrt PSU - Fix klocwork 69293 with more length checking mechanisms - Fix KVM "mouse mode setting" screen in ews shows exceptions issue. - Fix lighttpd cannot start after replacing BMC certificate - Ambiguous caution message when upload invalid/expired SSL certificate via Redfish. - Fix Cannot modify "anonymous" user under EWS issue. - Remove "Unknow" item from Subsystem - Upgrade glib to 2.68.3 and libffi to libffi-3.4.2 - update openLDAP to 2.4.59 - Add HSBP slots for E1.L - Resolve Utilities command stuck issue when "KCS: Deny all" - Add retimer version 1.7.0 - Add HSBP CPLD FW v0p7 - Exit Air Temp (#0x2E) CRITICAL event: Exit Air Temp reports the sensor is high state. - Fix klocwork 69293 Array "authKul" of size 1 may use index values(s) 0..143 - Internal Virtual Media improvement - Add PSU 4 Input display support in EWS - Ignore HSBP Peer Power State check - Remove cryptographic algorithm DES - update dhcp to 4.4.2-P1 - Revert " Update D50TNP EDSFF to v1p7" - Updating BMC will not auto reset if there is a "defer reset" update previously. - It takes almost 30s for system status LED turn on (normal=solid green) after BMC initial completed (Blue ID LED off). (Corner test)”. - Implement Client certificate in Redfish - Supports NFS protocol for Redfish VirtualMedia Schema - Fix cannot mount ISO image via Redfish - Fix cannot upload Redfish EventService CA certificate. - Fix ipmid insydeEntry OEM command table wrong request length without AT_LEAST_BIT - Fix cannot mount Web ISO - Fix Entire Platform power consumption value mismatch - SUT will not auto power on after IBB/OBB watchdog timeout with IBB/OBB BIOS flashed via Sysfwupdt_V14_2_Build9. - ID LED is off on second T-1 state after flash BIOS on recovery region. - Make Fan Fault LED offset value unique - Update PFR CMD Whitelist - After the Bios test has finished the jumper test, the BMCweb interface cannot be loaded - update kernel to 4.9.272 - Add HSBP CPLD FW v0p6 - Resolve multi-node PS4 sensor reading error - Support PS4 Hot-Plug and Auto-Config - Fix Klocwork issue: 69254 - Implement E1.L RSSD Thrm Mrgn and RSSD status sensor - Fix It prompts incorrect password when open Java KVM in EWS with AD account or LDAP account. - Extend IPMI CMD_GET_SATELLITE_UPD_STATE to max PDBs - Extend IPMI CMD_GET_PDB_FW_VER to all available PDBs - Add Fan Redundancy/Non-redundant Event Associations - Add HSBP CPLD v0p5 - Update System Fan 5-10A/B sensor values - Unify Front and Rear U.2 HSBP - Update D50TNP EDSFF to v1p7 - After BMC online update, the “Tcontrol modifier value” will be set as 80(Hex) which is not synced to the value of “exit air temp” setting of BIOS. - Fix It prompts incorrect password when open Java SOL or Java KVM in EWS with AD account or LDAP account. - Get event log abnormal in EWS after updating BIOS - Update CPLD FW interrupted, after reset system, CPLD FW still displays old version, but there has been an update successfully event log in EWS. - Set Slave Fan information as per PDBType - Add E1.L FRU device and Ruler BP Temp Sensor - Update FRU Device ID for uniqueness - Correct Fan5-10 Fault LED offset value - Correct Mem VR Temp Sensor numbers - Update PWM/TACH range check - Update Sensor numbers and FAN Domain mapping - NNPTool is not working with CYP BMC - There should be more clear caution when you try to add new user with “invalid PWD” which does NOT meet password complexity requirement. - To determine EWS SNMP feature to build at compile time. - Update BIOS Version representation format in SEL - BIOS option will not roll back to default after flash bios via EWS with parameter Nvram and back. - Fix A lack of "Role Group ID"in Active Directory help information issue. - Upgrade libxml2 from v2.9.10 to v2.9.12 - update curl to 7.77.0 - SNMPV2/V3 Support - Internal Virtual Media - RAM Disk - Save different config in webiso - Fix redfish alerting has power on/off backwards issue. - Support IMG/IMA media type - Fix KlockWork scan issue - Upgrade Busybox from v1.32.1 to v1.33.1 - Take max FANS and TACH Reg Base from config.xml - Take PDB FW Image filename from config.xml - Add PDB as parameter to relevant API's - Add init support for 2 PDB/PIC32 - Support online FW update of multiple PDBs - Support 4 PSUs - Add Rear Temp1/2 and U.2 SSD Temp Sensors - Add Front Temp1/2 and U.2 SSD Temp Sensors - SDPTool - SDR Upload shows success even when failure - Add HDD Drive Status Sensors - Add Global Fault LED support - Remove all CPU2/3 references - Add AMP platform check during load_stage_two() - Add retimer version 1.2.0 - Add PEF Action for Right/Left FP Temp Sensor - Support IMG/IMA media type in Web ISO page - When BMC is running factory image, try to update BMC, BMC backup image instead of primary image will be updated. - Filter "ATS Support" for AMP as well - [CCB3389][CCB3388]Adding Memory Error Extension and OEM BIOS POST Event sensor offset - Add front panel temperature sensors - Add PFR online update support in safe mode - Enable KVM for AMP - Remove EDSFF from platform config - Improve the message when ASMK is inactive or RMM is not installed. - Remove NW_SWITCH_ID from platform config - Update Default and FCT SDR - Add ASMKey support - Update sensor mapping - Fix Can’t mount Virtual Media via Redfish. - Fix the PowerLimit object of the PowerControl schema can not patch in the Redfish. - Update HSBP & retimer FW version accordingly v2.81 - Update kernel to 4.9.268 - [Utilities] [SDPTool-2.1-0][Redfish] CPLD version showing incorrect - Fixed the problem that the server was not started for the second time during the BIOS in-band recovery update (need the new version of CPLD) Fixed the beep code and abnormal SEL problems that occurred on the server during the BIOS in-band update warm reset - EWS does not decode CPU ID correctly, there are additional “f” characters contained in process signature. - Move "LicenseStatus" & "LastUpdateTime" to pre-defined schema - Update HSBP CPLD to v1.90 - 3.5 in SIlver SKU HSPB IPMI returns incorrect LED status - Update retimer to 1.2.0 - Upgrade glib to 2.68.1 - Update curl to 7.76.1 - Fix Can't upload SSL cert through EWS, warning message will pop up. - Update kernel to 4.9.265 - Upgrade jQuery-ui to v1.12.1 - Update glib to 2.68.0 - Update openssl to 1.1.1k - Update mbedtls and monit - Update openldap to 2.4.58 - Update libcurl to 7.76 - Add busybox patch. - Help info of ASMK is not completed on EWS. - Fix WebSocket session timeout problem - After OOB flash corrupted BIOS and reboot SEL log behavior is changed on BMC 2.78. - Fix the caution message incorrect when upload invalid and expired SSL certificates in EWS. - Temperature,RSSD Thrm Mrgn 2 (#0x62)" SEL event reported during DC cycle on TNP Storage Module [Storage][Pre-ST]BMC report "RSSD Thrm Mrgn 1,Temperature, Lower Critical - going low - Asserted/NVMEof-FIO about 1 day" - Fix incorrect values in System NIC info and cannot access Drive. - Correct the help info of Date & Time to align with User guide. - [InBand-update]SUT will have beep code after flash BIOS and reset. - [InBand-update]"VR Watchdog" and "Power Unit Failure detected" error event show in SEL after flash BIOS via Sysfwupdt_V14_2_Build9. - SDR Report present empty (invalid) contain in System Debug log. (regression issue) - Fix Advanced System Management Key” function link is disappear randomly after login/logout EWS multiple times. - Fix cannot upload 4096 bits SSL cert via Redfish. - Correct the EWS certificate time. - Mount folder remotely via Virtual Media over HTML5 of EWS is not work. - [klocwork] Fix klocwork issue: 56489 - Fix mount folder can not work of VM HTML5 at EWS issue. - Restrict the private key length to RSA 2048-bit and verify the cert prior to replacing it. - Fix SSL Certification file can not upload at EWS issue. - Correct the interpreting when SMBIOS type 190 offset 0x17 value is FFh - Fix Advanced Boot Options of BIOS Configurations can not loading via firefox/IE. - Fix OEM SEL record type range 0xE0-0xFF overwriting non-timestamped data. - Update HSBP version number in release note - Correct the warning message when adding a user. - Help info of ASMK is not completed on EWS as user guide. - Check whether username contains the password prior to adding a username. - Update JAVA Certificate