When PMS 2.1 is installed, the upgrade from Gateway 11.1.4 to 11.2.0 is failing on the installation of PMS 3.0 with the following error in the pms logs:
com.broadcom.patchman.service.PatchVerifier checkTrustedCertificates
WARNING: Signer certificate has expired: CN=Broadcom Inc, OU=CA Canada Company, O=Broadcom Inc, L=San Jose, ST=California, C=US; not after Wed Apr 29 01:59:59 CEST 2026
AM com.broadcom.patchman.PatchManagementServiceHandler channelRead0
WARNING: Patch API Error: The patch contains signed entries that are not signed by alias in the keystore: CN=Broadcom Inc, OU=CA Canada Company, O=Broadcom Inc, L=San Jose, ST=California, C=US
com.broadcom.patchman.service.PatchException: The patch contains signed entries that are not signed by alias in the keystore: CN=Broadcom Inc, OU=CA Canada Company, O=Broadcom Inc, L=San Jose, ST=California, C=US
API Gateway 11.1.4, 11.2.x
PMS 2.1, 3.0
PMS 2.1 already has the new signer and an upgrade to PMS 3.0 is not needed.
If you have installed PMS 2.1, you do not need to install PMS 3.0. The PMS 2.1 is using the same signer as PMS 3.0 and can install the 11.2 files.
If you are using the oneClickUpgrade.sh and ssg-inplace-upgrade-readiness-checker.sh script from the upgrade patch to 11.2, this one still expects that PMS 3.0 needs to be installed and will fail on this .
Download the new oneClickUpgrade.sh and ssg-inplace-upgrade-readiness-checker.sh from the Solutions & Patches page and use these to complete the upgrade.
Layer7_OneClickUpgrade_07062026.zip