Symantec Mobile Management 7.2 SP3 MR1 Release Notes



Similar documents
Transcription:

Mobile Management 7.2 SP3 MR1 Release Notes

Mobile Management 7.2 SP3 MR1 Release Notes This document includes the following topics: About What's new in 7.2 SP3 MR1 Fixed issues in 7.2 SP3 MR1 Known issues for 7.2 SP3 MR 1 Product documentation for this version requirements Network ports used by Upgrading Installing About lets you manage, secure, and troubleshoot the mobile devices in your organization. Using, you can automate IT tasks and control your IT environment more effectively. By becoming more effective, you can reduce the effort and costs of managing, securing, and troubleshooting mobile devices. works with the

7.2 SP3 MR1 Release Notes What's new in 7.2 SP3 MR1 3 Management Platform to simplify the management of and communication with the devices in your environment. What's new in 7.2 SP3 MR1 The 7.2 SP3 MR 1 release of resolves several issues found in previous releases. See the Fixed Issues list for more information. Fixed issues in 7.2 SP3 MR1 The following issues from previous releases are fixed in this release. Re-enrolled devices are unable to install MDM profile. Inventory for ios7 devices doesn't show a valid MAC address. Automated policy evaluation for some ios devices ends prematurely, failing to complete. Exchange ActiveSync setup: Better alignment between Implentation Guide, KB articles, and the EAS.BAT tool. Blackberry: Unauthorized devices is displaying all versions of BB devices as unsupported OS. Android device location not being reported. Regular policy evaluation and automated push fails for ios 6 and ios 7 devices. In the Wifi profile, once you select a SCEP server or certificate, you are unable to deselect it and make a different choice. In the VPN profile, once you select a SCEP server or certificate, you are unable to deselect it and make a different choice. Wifi password is displayed in the NT_Demand log file. ios profile's debug logs show passwords located in profiles in plain text. Unable to bootstrap Windows Mobile. Windows Mobile devices attempt to obtain agent bootstrap files from wrong virtual directory path name. The ExpirationDate field in Inv Mobile_Provisioning_Profile_iOS is emptied upon upgrade from SP2 to SP3 Samsung SAFE devices show device safe status = False in Device Information screen. Issue resolved by installing the SMM SAFE Agent. ios device shows as not compliance when Agent EULA is set to not required.

7.2 SP3 MR1 Release Notes Known issues for 7.2 SP3 MR 1 4 nlog configs for log rotation are incorrect. Provisioning profiles are not delivered to ios devices when targeted in a policy. In certain regions, Windows Phone can not enroll because MMService.exe cannot process lattitude and longitude values that use commas. Certificate payload in Samsung SAFE causes devices to stop communicating with the MMS. App-installed or ipcu-installed provisioning profiles are removed from the device when in Supervised mode and same profile is also targeted from SMM. Samsung SAFE profiles are not removed from device when the agent is uninstalled. Add support for Samsung SAFE WiFi Configuration. Add support for Samsung SAFE VPN Configuration. Samsung SAFE payload password shown in debug logs. Android device receives Wipe TouchDown command at policy check-in. Known issues for 7.2 SP3 MR 1 The following are known issues for this release. Table 1-1 Issue Cause Workaround Samsung SAFE: Wifi PSK profile doesn't install on device- shows error: Samsung WifiManager.setNetworkPSK() failed The SAFE Wifi PSK shared-key must be eight characters or longer. The field cannot be empty. Use a shared-key value that is at least eight characters long. Do not leave the field empty. Upgrade to to agent causes agent to reset. Samsung SAFE: Blocked Hardware Keys does not work on device. Changes to device identification method between agent versions. Investigating Re-enroll the agent. None at this time.

7.2 SP3 MR1 Release Notes Product documentation for this version 5 Table 1-1 Issue (continued) Cause Workaround Samsung SAFE: The Peak Sync Interval and Off Peak Sync Interval settings options do not match the options on the device SAFE API implementation varies by device. N/A Product documentation for this version The following documents are available for this version of Mobile Management: 7.2 SP3 Release Notes (this document). http://www.symantec.com/docs/doc7178 7.2 SP3 Implementation Guide http://www.symantec.com/docs/doc6826 7.2 SP3 Quick-start Guide http://www.symantec.com/docs/doc6827 requirements The following table describes the requirements of each component. Table 1-2 Component requirements Requirement and description Management Agent. Web (IIS) that corresponds with your operating system. IIS must also have the role defaults and Role Service IIS 6 Management compatibility..net Framework that corresponds with your operating system and IIS. ASP.NET. Apple Push Notification Service (APNS) certificate. Microsoft Message Queuing

7.2 SP3 MR1 Release Notes requirements 6 Table 1-2 Component requirements (continued) Requirement and description Management Console Internet Explorer 7.1 or later. Silverlight 4.x/5 Java Runtime Environment Agent iphone 3G, 3GS, 4, 4S, and 5 running ios 5.0 or later ipod Touch 2nd generation, 3rd generation, and 4th generation running ios 5.0 or later ipad running ios 5.0 or later Note: Agent 5025 and later for ios 6 and ios 7 only. Android 2.2 or later Samsung SAFE devices. Windows Mobile 6.0, 6.1, and 6.5 Professional and Standard Windows CE 4.2 to 6.0 Windows Phone 7.5, 8.0 Blackberry OS 4.3 to 6.0 A complete "agent compatibility by platform" matrix is available at www.symantec.com/docs/tech206740. Management Platform server Microsoft SQL Active Directory LDAP Trusted SSL web server certificate Certificate Authority SCEP Windows 2008 R2, R2 SP1-64-bit only. (Core Edition not supported.) SQL 2005 or 2008 IIS 6.0.NET Framework 3.0 Management Platform 7.1SP2, 7.1 SP2 MP1-MP1.1, 7.5 See SQL documentation. See Active Directory documentation. See LDAP documentation. See SLL documentation. See Certificate Authority documentation. See SCEP documentation.

7.2 SP3 MR1 Release Notes Network ports used by 7 Table 1-2 Component requirements (continued) Requirement and description Microsoft Exchange ActiveSync Exchange ActiveSync integration software requirements: Microsoft Exchange 2007 SP1 or SP2 with Exchange 2007 Management Tools or Microsoft Exchange 2010 SP1 or SP2 with Exchange 2010 Management Tools Note: Exchange ActiveSync access control integration with F5 BIG-IP LTM and EAS ABQ rules supported on Exchange 2010 only. Microsoft Windows Management Framework, specifically Windows PowerShell 2.0 See Microsoft Exchange ActiveSync documentation for Exchange ActiveSync requirements. Google Cloud Messaging (GCM) See Google Cloud Messaging documentation Additional requirements exist for Data Loss Prevention. See Data Loss Prevention for Tablets Solution Guide for VPN On Demand Enforcement, which is available at the Data Loss Prevention knowledge base. Network ports used by The following table describes the ports that are used by : Table 1-3 Network ports used by Port From To Description 80, 443 Agent IIS HTTP for agent communication, IIS HTTPS for agent communication (optional) 7780 Agent Remote control connection

7.2 SP3 MR1 Release Notes Network ports used by 8 Table 1-3 Network ports used by (continued) Port From To Description 5223 Agent Apple Push Notification Service APNS communications to Apple by APNS servers 2195, 2196, 5223 Apple Push Notification Service APNS communications to agent by APNS servers 7778 Management Platform Remote control connection 80, 443 Management Platform IIS HTTP 80, 443 7778 Management Console browser Management Console browser Management Platform Console Remote control connection Standard SQL ports Management Platform Microsoft SQL Database 50120-50124 Management Platform SMP Client Task Agent communications Note: If these ports are not available, the Client Task Agent will fail-over to use HTTP-HTTPS for communications. 80 Google Cloud Messaging (GCM) Google Cloud Messaging (GCM) communications

7.2 SP3 MR1 Release Notes Upgrading 9 Table 1-3 Network ports used by (continued) Port From To Description 5087, 5061 Microsoft Push Notification Microsoft notification server communication Upgrading Use the following procedure to update to latest version of Mobile Management: Prerequisites for upgrading to 7.2 SP3 Upgrading to version 7.2 SP3 is only supported from version 7.2 SP2. If your current installation is an earlier version that 7.2 SP2, you must first upgrade to 7.2 SP 2. Be aware of the following warnings: Warning: The update to 7.2 SP1 or later from 7.2 or earlier can result in the loss of WiFi connectivity for managed ios devices. The managed devices that have a WiFi profile are affected. Read the knowledge base article TECH194739 Loss of Device Wi-Fi Communication After Upgrade of SMM to 7.2 SP1 for more information about this issue. Some installations may also lose authentication services. For more information and instructions to correct the problem, see the knowledge base article TECH197019, Authentication stops working after upgrading to Mobile Management 7.2 SP1. Warning: If using F5 rules and your environment has custom irule requirements, manually remove the irule cache file (C:\ProgramData\\MobileManagement\eas_rule.txt). Replace this cache file with the new version by running the NS.Quarter-Hour{5834ae07-1160-4037-8a25-67aebf6a254e} scheduled task after upgrading. Replacing the cache file allows the irule definition version to update to the new version. The irule definition version is not automatically changed during an upgrade to the latest version. TouchDown configuration fails as a result.

7.2 SP3 MR1 Release Notes Upgrading 10 To upgrade 1 Log in as the service account (application identity) and make sure that it has local admin rights. 2 You upgrade through the Installation Manager. Go to Start > All Programs > > Installation Manager. Right-click the Installation Manager and select Run as administrator. 3 On the Installed Products page, click Upgrade installed products.. 4 Select with the correct version number of the upgrade, and click Next. 5 On the Optional Installations page, click Next 6 Accept the EULA and click Next. 7 On the Contact Information page, click Next. 8 Verify the installation details and click Next. 9 On the Installation Complete page, click Finish. Note: After an upgrade, Exchange ActiveSync configuration is lost. If using EAS, you must rerun the eas.bat batch file after the upgrade to restore the EAS server information. Then, you can re-configure EAS functionality. For more information about the eas.batch file, see the knowledge base article TECH201454, Configuration of EAS Integration Using the EAS ConfigTool. During an upgrade, the database is locked, and communication between the Management Platform Notification and the site server is stopped. The site server still attempts to communicate with the Notification computer. This situation can cause errors and issues. After you install 7.2 SP3, you must upgrade servers manually in the Management Console to complete the upgrade. Use this procedure to upgrade servers: Upgrading the manually 1 In the Management Console, click Home > > Settings > Settings 2 In the right pane, highlight the site server and then on the toolbar, click Upgrade. 3 Repeat Step 2 for each server. 4 Click Save changes

7.2 SP3 MR1 Release Notes Installing 11 For more information about upgrading the products that use the Management Platform, see Knowledge-base article HOWTO 44338, Installing an update or an additional product. Installing You install this product by using the Installation Manager. You can download the installation files directly to your server or you can create offline installation packages. Note: recommends configuring SSL communication in the server environment ( Management Platform and site server). Configuring SSL communication protects data, process communications, and account information that is transferred between the servers. For more information, see the IT Management Suite Implementation Guide at http://www.symantec.com/docs/doc3464. For detailed information about installing and setting up 7.2 SP3 MR1, see the 7.2 SP3 Implementaion Guide at: http://www.symantec.com/docs/doc6826.