-
WithSecure Policy Manager Proxy gives error "Error: CA certificate verification failed" or "RA not issued by CA", when running fspmp-enroll-tls-certificate.bat
Issue: I executed fspmp-enroll-tls-certificate.bat for Policy Manager Proxy and it gives me the error "Error: CA certificate verification failed" or "RA not issued by CA". Resolution: This error can occur if the server's Simple Certificate Enrollment Protocol (SCEP) is not up to date. You can follow the steps below on the…
-
Security Cloud Client is not connected on Server Security / Client Security
Issue: Security Cloud Client is not connected on Server Security / Client Security Resolution: You need to ensure that the affected F-Secure host is allowed to connect to the URL: * * https://a.karma.sc2.fsapi.com * * https://api.doorman.fsapi.com You can try to open https://a.karma.sc2.fsapi.com/healthcheck and…
-
Should I disable or uninstall Windows Defender on Windows Server 2016/2019/2022 after installing Server Security or Email and Server Security or Elements Endpoint Protection for Servers?
Issue: I've installed Server Security or Email and Server Security or Elements Endpoint Protection on a Windows Server 2016/2019/2022 server, but Windows Defender real-time protection is still on. Should I deactivate it when I'm using the WithSecure product? Resolution: Yes, Windows Defender should be deactivated when…
-
Policy Manager Alerts tab shows "Databases are old" for a host
Issue: Policy Manager Alerts tab shows an alert with the Severity Security and the description "Databases are old" for a host. How to troubleshoot why virus definitions are shown as outdated? Resolution: WithSecure Policy Manager receives the updates through our guts2 delivery and stores them in C:\Program Files…
-
Client Security or Server Security fails to download definition updates from Policy Manager Proxy and Policy Manager Server with "certificate expired" and "untrusted root ca" errors
Issue / Symptom After upgrading to Policy Manager Server 15.30, Client Security or Server Security fails to download malware definition updates from Policy Manager Proxy (PMP) and Policy Manager Server (PMS) with "certificate expired" and "untrusted root ca" errors. Host using PMP 2022-02-01 09:32:21.040 [1454.1a68] I:…
-
Policy Manager hotfixes for Spring4shell vulnerability released
On March 31, 2022, a critical vulnerability was announced in the Spring framework, which is used by many vendors with Java based products. As soon as WithSecure became aware of this, we started investigating to see if any of our products were affected, and we found that the following products contained the version of…
-
Resolving connectivity issues between Client Security for Mac and Policy Manager
If you experience issues with the connectivity between Client Security for Mac and Policy Manager where the host is not being registered, try using Safari to open the Policy Manager Server welcome page using exactly the same Policy Manager address that was used to export the mpkg package with the HTTPS protocol. If you get…
-
Failed to login to Policy Manager Console suddenly despite using valid offline token
Issue: Failed to login to Policy Manager Console suddenly despite using valid offline token Resolution: After applying token, once Policy Manager connects to F-Secure license registration server (https://corp-reg.f-secure.com:443), it resets manually imported tokens. It becomes automatic token which has short validity…
-
Client Security 13 not accepting Software Updater exclusions based on software vendor
Issue: Client Security 13.X does not accept exclusion rules for Software Updater that have been set using the Software vendor field in the Software Updater settings in Policy Manager Console. The following type of entries are logged in the fssua.log-file: 2020-08-20 14:00:13.661 [3750.8278] *E: Failed to parse a rule type:…
-
Client Security for Mac is not able to connect to the Policy Manager Server after installation
Issue:Client Security for Mac is not connecting to Policy Manager Server after installation. The host does not appear in the pending list. Resolution:Why a Client Security for Mac host will not connect to the Policy Manager Server can be a result of several different reasons: The Policy Manager Address and ports were…