CMS Verification Failure During Installation of Community SONiC Image on SN5600

Currently, we are using the SN5600 device to install the Community SONiC image in an ONIE environment, but we encountered issues related to CMS verification during the installation process. We have confirmed that the installed SONiC image file is complete and not corrupted (verified via MD5 checksum).

Could you please advise on any additional items we need to pay attention to when installing the Community
SONiC image on this device? Thanks.


Here are the detailed specifications of the device and the SONiC image:

  • onie-sysinfo: x86_64-nvidia_sn5600-r0
  • SONiC image (Mellanox):
  • A. Version: Community SONiC commit ID: 1661aca3ff
  • B. Self-compiled version: Master branch
  • Both image sources produce the same installation error.

SONiC image MD5: 0ffc709af749e140a784b6eef31a846d

The DUT (Device Under Test) has no installed NOS (the previously installed Cumulus OS has been removed).

The error message during installation is:

ONIE:/tmp # onie-nos-install sonic-mellanox.bin
discover: installer mode detected.
Stopping: discover... done.
ONIE: Executing installer: sonic-mellanox.bin
CMS Verification Failure
Failure: CMS signature verification failed.

Note: The DUT information can be found in the attached file.
sn5600_dut-info.txt (2.6 KB)

Best regards,
Lewis

Hi Lewis,

Please try this command and see the value of security attributes,
sudo flint -d /dev/mst/mt53120_pciconfe g full

If it is secure-fw, it has to be disabled from bios of the switch, then set to disabled in Secure Boot field.
Please give it a try. If still no lucky, please raise TAC case for further assistance.

Thanks