-
Citrix sessions left open due to Server Security system tray icon on end-user desktop
Issue: When launching Citrix sessions/applications, the Business Suite Server Security or Email and Server Security system tray icon will also appear on the end-users machine, and will remain on the machine after closing the Citrix application. The F-Secure process for the user needs to be closed separately from the Citrix…
-
How to allow Client Security or Server Security to download updates from back-end when product is unable to connect to Policy Manager
Issue: How to allow Business Suite Client Security or Server Security client to download malware definition updates from back-end update server when product is unable to connect to Policy Manager Server? Resolution: By default, the client will failover to the Withsecure / F-Secure update server, guts2.sp.f-secure.com, when…
-
WithSecure Policy Manager Proxy gives error "Error: CA certificate verification failed" or "RA not issued by CA", when running fspmp-enroll-tls-certificate.bat
Issue: I executed fspmp-enroll-tls-certificate.bat for Policy Manager Proxy and it gives me the error "Error: CA certificate verification failed" or "RA not issued by CA".Resolution: This error can occur if the server's Simple Certificate Enrollment Protocol (SCEP) is not up to date. You can follow the steps below on the…
-
Security Cloud Client is not connected on Server Security / Client Security
Issue: Security Cloud Client is not connected on Server Security / Client SecurityResolution: You need to ensure that the affected F-Secure host is allowed to connect to the URL: * * https://a.karma.sc2.fsapi.com * * https://api.doorman.fsapi.com You can try to open https://a.karma.sc2.fsapi.com/healthcheck and…
-
Should I disable or uninstall Windows Defender on Windows Server 2016/2019/2022 after installing Server Security or Email and Server Security or Elements Endpoint Protection for Servers?
Issue: I've installed Server Security or Email and Server Security or Elements Endpoint Protection on a Windows Server 2016/2019/2022 server, but Windows Defender real-time protection is still on. Should I deactivate it when I'm using the WithSecure product?Resolution: Yes, Windows Defender should be deactivated when using…
-
Policy Manager Alerts tab shows "Databases are old" for a host
Issue: Policy Manager Alerts tab shows an alert with the Severity Security and the description "Databases are old" for a host. How to troubleshoot why Malware definitions or engines are shown as outdated? Resolution: WithSecure Policy Manager receives the updates through our guts2 delivery and stores them in…
-
Client Security or Server Security fails to download definition updates from Policy Manager Proxy and Policy Manager Server with "certificate expired" and "untrusted root ca" errors
Issue / Symptom After upgrading to Policy Manager Server 15.30, Client Security or Server Security fails to download malware definition updates from Policy Manager Proxy (PMP) and Policy Manager Server (PMS) with "certificate expired" and "untrusted root ca" errors. Host using PMP 2022-02-01 09:32:21.040 [1454.1a68] I:…
-
How to upgrade WithSecure Policy Manager to a newer version on a Windows Server?
Issue: How to upgrade WithSecure Policy Manager to a newer version on a Windows Server? Resolution: It's highly recommended that you first back up your existing WithSecure Policy Manager data before upgrading: Create a full backup of the WithSecure Policy Manager data (H2 database, preferences and other files). The backups…
-
Policy Manager hotfixes for Spring4shell vulnerability released
On March 31, 2022, a critical vulnerability was announced in the Spring framework, which is used by many vendors with Java based products. As soon as WithSecure became aware of this, we started investigating to see if any of our products were affected, and we found that the following products contained the version of…
-
Resolving connectivity issues between Client Security for Mac and Policy Manager
If you experience issues with the connectivity between Client Security for Mac and Policy Manager where the host is not being registered, try using Safari to open the Policy Manager Server welcome page using exactly the same Policy Manager address that was used to export the mpkg package with the HTTPS protocol. If you get…