Issue:
- How to install F-Secure Email and Server Security 15.00?
- Why I cant push install F-Secure Email and Server Security 15.00 using Policy Manager Console?
- For step 8 , do I need a domain and username ? What format is required?
Resolution:
Before planning any upgrade, it is highly recommended to check release version and make sure your Exchange server meets the criteria. System requirements can be found under our official web page: Email and Server Security | Email and Server Security | 15.10 | WithSecure User Guides
If you are using Business Suite, make sure that your WithSecure Policy Manager Server version is the latest. More about version release please refer here: Support - Policy Manager | WithSecure™
Note: WithSecure Policy Manager Server needs to be the latest version before you can upgrade the clients to the latest versions.
Licensing:
- If you are upgrading from version 12. xx to 15.xx and you do not have product activation key, please contact your F-Secure reseller or Partner to obtain the latest keycodes for Business Suite products.
- If you are upgrading from version 14. xx to 15.xx no additional keys are needed.
- If you have WithSecure Email and Server Security standalone version and do not have the key or installer, please contact your WithSecure reseller or Partner to obtain the latest keycodes for Business Suite products and the
Conditions that should be met for installation to be successful (these are applied to user that will run MSI):
WithSecure Email and Server Security for Microsoft Exchange:
- User must be in local "Administrators" group
- User must have access rights to create/configure application in the "Program Files" folder
- User must be able install/configure local services
- User must have rights to run PowerShell scripts
- User must be a member of "organization management" (could be added in MS Exchange Security group or via Exchange admin center>permissions)
- User must be in "Local Administrator" group
WithSecure Email and Server Security for Microsoft SharePoint:
- User must be in "Local Administrator" group
- Note: User for scan and service (credentials entered at the installation in UI or config tool after installation):
- User must be in "Farm Administrators" in SharePoint Group
- User should have "Logon as a service" privilege enabled
Supported scenarios for the upgrade:
IMPORTANT: Push operations using WithSecure Policy Manager Console for WithSecure Email and Server Security respectively Exchange and SharePoint components have never been supported and will continue to be unsupported. This means that no push installation is possible for WithSecure Email and Server Security via the WithSecure Policy Manager console. It would be a security risk to share DB passwords / SHP admin credentials over the network and no changes in the installation process.
Currently we support only the two upgrade scenarios:
- Local upgrade using MSI
- Policy-based upgrade from Policy Manager
If you are upgrading from Version 12.xx:
Note: Microsoft® SQL Server must be installed before upgrading your Email and Server Security. SQL Express is no longer included in the installer as it used to be with version 12.xx.
Please refer to the deployment guide how to install SQL. Installing Microsoft SQL Server instructions can be found here: 50 | Installing Microsoft SQL Server | F-Secure Email and Server Security https://www.withsecure.com/userguides/data/pdf/wsess15.10-deployment-eng.pdf
If you upgrade using Policy Manager ‘policy-based upgrade option, you still need to setup the SQL Database locally on your Exchange server by running setup F-Secure.Ess.Config.exe as administrator. Tool can be found here: C:\Program Files (x86)\F-Secure\Email and Server Security\ui\F-Secure.Ess.Config.exe
For more help, please refer to 4.1 Installing the product locally page 25: https://www.withsecure.com/userguides/data/pdf/wsess15.10-deployment-eng.pdf
Additionally, check the articles below to make sure you have all prerequisites for the WithSecure Email and Server Security Web Console.
You might want to verify if TLS 1.0, 1.1 and 1.2 are enabled. Our advise is to use 1.2
Upgrading standalone:
If you don't have the MSI installer, please contact your reseller or customer support to provide you with the installer.
Note: After installing this standalone version of Email and Server Security it will take some time for it to recognise that it is a standalone installation. Customers are advised that they should not restart the server EVEN if prompted until "Update Server" in the Updates section of the settings user interface shows "guts2.sp.f-secure.com". If the customer restarts the computer before this time, the process will start over. In some cases this may take up to three hours, we will improve this in the next version.
FAQs:
Do I need to run maintenance mode and take servers offline from the DAG cluster when upgrading F Secure Email and server security?
More about the maintenance mode and DAG: https://docs.microsoft.com/en-us/exchange/database-availability-groups-dags-exchange-2013-help
The upgrade process does not require servers to be offline. However, to avoid any compatibility issues that might come up during the upgrade, you advise you to run the upgrade on one server first using the local installation option.
To install the product on a server with MSI you created with Policy Manager:
- Log in to the WithSecure Policy Manager Console
- Go to the Installation tab
- Click Installation packages
- Click Import
- Import the F-Secure Email and Server Security 15.00 Jar file
- Select the imported Jar file from the Installation packages list and click Export as MSI
- Run the MSI locally on your Exchange server with the domain admin or the local admin rights
- Complete the setup by following the on-screen instructions
If you have any questions about the specific configuration, please refer to the Administrator or Deployment guides:
Article no: 000029421