Release Notes Swisscom Storebox Release 5.0 Swisscom AG 1/24
Table of Content 1 Introduction... 3 2 Portal... 3 2.1 End-User features... 3 2.1.1 Enhanced Collaboration... 3 2.1.2 User Avatars... 8 2.1.3 Drag & Drop Upload to the Cloud Drive... 9 2.1.4 Online File Viewer... 10 2.1.5 File Versioning... 11 2.1.6 Recycle Bin... 11 2.2 Admin features... 12 2.2.1 Notification Dashboard... 12 2.2.2 Automatic Plan Assignment... 13 2.2.3 Cloud Drive Content Policy... 14 2.2.4 Password Strength Policy... 15 2.2.5 Force Backups to Use or Not Use a Passphrase... 16 2.2.6 Fine-Grained Control over Workstation Backup License... 16 3 Client... 17 3.1 VDI Mode... 17 3.2 Outlook Plug-in... 18 3.3 Single Sign On from Client to Portal... 20 3.4 Mac OS X Shell Extension... 20 3.5 Browse Previous File Versions Shell Extensions... 21 3.6 File Edit... 21 3.7 Email Notification If a Volume Selected for Cloud Backup is Offline... 22 4 NAS-Gateway... 22 4.1 Sync Gateway Mode... 22 4.2 NAS-Gateway Network Troubleshooting Tools... 22 4.3 Email Notification on Predicted Drive Failure... 23 4.4 SMART Disk Health Check... 23 2/24
1 Introduction With the new release 5.0 of CTera, Swisscom Storebox receives a major uplift on all elements (Portal, Client and NAS-Gateway), including numerous enhancements and new functions. The most important enhancements are concerning the end-user portal of Storebox which has been revamped in order to improve the usability of the end-users. 2 Portal 2.1 End-User features Version 5.0 features a new End User Portal with a mobile-responsive user interface for use on tablets. This feature is supported on the following browsers: Internet Explorer 9 and higher Chrome Firefox Safari Users with older versions of Internet Explorer will not be able to access the End User Portal. 2.1.1 Enhanced Collaboration Version 5.0 features completely revamped collaboration. 2.1.1.1 Directory Structure The Cloud Drive directory structure was modified. The former Projects and Shared With Me folders were consolidated to a single location called Shared With Me, which includes all files that were shared with the user. In addition, each folder under the Shared With Me location includes the name of the folder owner in parentheses, as well as the user s access rights to the folder. 3/24
Tip: Shared folders defined as a "Team Project" will appear under "Shared With Me" without the name of the folder owner in parentheses. 2.1.1.2 Sharing with public links Users can quickly generate public links to files and folders in their Cloud Drive. 4/24
Upon generating a public link to a file or a folder, the public link icon turns green to indicate that the file or folder is shared. Public links enable users to: View existing public links generated for a file or folder, by clicking on the public link icon. Modify the expiration date of existing public links. Re-use existing public links, by clicking the Copy button. The link will be copied to your clipboard. Remove a public link and revoke access to the file/folder, by clicking on the menu button and selecting Remove. In order to comply with security enforcements, the portal administrator can define the maximum validity period of public links via the Global Administration View, by setting the Maximum Validity Period field in the Virtual Portal Settings page s Collaboration area. 2.1.1.3 Group Collaboration Users can easily collaborate on files and folders with internal users or groups, as well as with external users. 5/24
Upon collaborating on a file or a folder, the collaborators icon turns green to indicate that the file or folder is shared. To collaborate, the user selects a file or a folder from their Cloud Drive, clicks on the collaborators icon, and adds all of the team members and/or groups (local or domain) with whom they would like to collaborate. Collaborators can be quickly added, by starting to type their name or e-mail address. When adding collaborators that are local users/groups or domain users/groups (in the event that the user s team portal is connected to Active Directory), the dialog box will automatically complete the names of the users/groups. It is also possible to add external users by typing their e-mail addresses. To ensure security when collaborating with external users, the user can require a second step of authentication via code sent in a separate email or SMS. In the following image, michael.bower is an example of an external user. 6/24
The portal administrator can define the required external user authentication scheme via the Global Administration View, by setting the External User Authentication field in the Virtual Portal Settings page s Collaboration area. Folder and file sharing enables users to: Collaborate on folders, sub-folders and individual files. Determine whether the invited internal team members can synchronize the shared folder to their PC or not. If synchronizing the shared folder to one s PC is disabled, the invited team members will only be able to access the shared data directly from the portal interface. Disable resharing of the shared folder. By disabling resharing, the owner can prevent the invited team members from resharing files and folders that the owner shared with them, thus preventing data leakage. If the owner allows resharing, then the owner will receive an e-mail notification when a team member reshares the file or folder. The owner can open the Collaborators dialog box to view all users with whom the folder has been shared. Quickly resend sharing invitations to individual team members. Define whether the shared folder is a team project or not. If the folder is defined as a team project, the name of the folder owner will not appear in parentheses as a part of the folder name. View the name of the team member who performed the most recent changes to a shared file. 7/24
To ensure security, the portal administrator can define that shares generated via group collaboration will expire after a certain number of days, and that this expiration date is mandatory, that is, users will not be able to specify a later expiration date. This is done via the Global Administration View, by setting the Shares automatically expire after field in the Virtual Portal Settings page s Collaboration area. 2.1.2 User Avatars Storebox Portal supports user avatars. A user avatar is an image uploaded to a user profile, and it is used to represent the user in the following situations: When selecting team members in group collaboration, each member is represented by their avatar. When an external user accesses a public link or a share, the owner of the file or folder is represented by their avatar. The avatar represents the currently signed-in user in the End User Portal. 8/24
User avatars are not mandatory. When an avatar is not defined, the user s initials are used instead, so for example, John Smith becomes JS. 2.1.3 Drag & Drop Upload to the Cloud Drive A user can drag files and folders from Windows Explorer and drop them into the End User Portal s Web interface. The files and folders will be uploaded to the user s Cloud Drive. The user can also drop files directly into a subfolder. 9/24
This feature is fully supported on the following browsers: Chrome Firefox Safari This feature is partially supported on Internet Explorer version 10 and up, which supports only file drag & drop and not folder drag & drop, due to a browser limitation. Internet Explorer 9 does not support drag & drop uploads. 2.1.4 Online File Viewer Users can now view files online in the End User Portal s Web interface, the Cloud Drive, and backup folders. When a user clicks on a file s name or icon in one of these locations, the file is displayed in the online viewer. A wide variety of files types are supported, including: Document Formats: DOC, DOCX, XLS, XLSX, PPT, PPTX, RTF, CSV, PDF, ODT, ODS, ODP, and many older document formats Web Formats: HTML, SVG Image Formats: TIFF, JPG, JP2, GIF, PNG, RAS, CAL, MIL, DIB, BMP, PSD, PCT, PCX, DCX, PCD, WMF, EMF, TGA, and many more image formats Medical Image Files: DICOM CAD Formats: DGN (support for V7 and V8 DGN, including V8 XM and V8I), DWG (version 2.5 through 2014), DXF (version 2.5 through 2014) 10/24
Email Formats: EML, MSG Other formats: txt The files are displayed using a fully native HTML5 viewer, and no browser plug-ins are required. Searching inside a file, as well as copying and pasting text, are supported. Tip: Password-protected files cannot be previewed. Tip: The default maximum file size for preview is 5MB. To change the default, contact the Swisscom support. 2.1.5 File Versioning Users can easily track changes to and versions of their files. To browse previous versions of a file, select the desired file in the Web interface and click on Version History. Alternatively, if you are using the Storebox Client to synchronize a folder, simply right click on the file and then click on Storebox Client -> Version History. In both cases, the File Version dialog box appears displaying the different versions that exist for the file. You can then do any of the following: Review the various versions of the file. If you are part of a group collaboration, you can also see who made the most recent changes to the file and the file size. Use the online file viewer to preview the versions. Download the file versions. Restore a file to a previous version. The number of versions that are retained, as well as which versions are retained, depends on the retention policy, which is configured in the user s plan. This feature is available both for Cloud Drive and backup folders. 2.1.6 Recycle Bin Users can recover deleted data from their Cloud Drive using the Recycle Bin feature. When deleting a file or a folder either via the Web interface, or via the local synchronization folder, the deleted data is moved to a recycle bin. It is then retained in the recycle bin for a period of time (in days) defined in the user's assigned subscription plan. In order to access the deleted items, the user can click on the trash can icon located in the upper-right corner of the file manager. The deleted files in the folder then appear in gray, in strikethrough style. 11/24
Tip: The default retention period for deleted files is 30 days. This is configurable from the users retention policy. 2.2 Admin features 2.2.1 Notification Dashboard The notification dashboard allows tracking of error and warning conditions. For instance, one can use the notification dashboard to track failed backup jobs. The notification dashboard is available for virtual portal administrators and portal global administrators. It displays error and warning conditions that are currently in effect, including alerts related to the system, storage nodes, specific virtual portals, users and devices. The notifications are available through the Notifications menu in the administrator panel. In addition, the portal dashboard also displays a summary of the ten highest priority notifications. It is possible to mark specific notifications as hidden, if you do not feel that they require immediate attention. Those notifications can always be unhidden later if desired. 12/24
2.2.2 Automatic Plan Assignment The Automatic Plan Assignment feature allows virtual portal administrators to define a policy that determines which subscription plan will be assigned to the virtual portal s users. Using this feature, you can automatically assign a subscription plan based on the following user attributes: Username User Groups Role First Name Last Name Company Billing ID Comment The policy rules are processed in ascending order. The first rule that matches applies. You can change the rules order by using the Move Down/Move Up buttons. You can also choose to apply a default plan in the event that no rule applies. This feature is very useful in an environment configured with Active Directory. It allows you to define a policy even before users have joined the service, so that when users join, they will be automatically assigned the appropriate quota and licenses. 13/24
2.2.3 Cloud Drive Content Policy This feature enables virtual portal administrators to define rules specifying the type of data that can be synchronized through the Storebox Client and NAS-Gateways, or uploaded to the Storebox Portal via the Web interface or Storebox Mobile Apps. The virtual portal administrator can create DENY and ALLOW rules based on the following attributes: File Size File Name File Type Each rule can be applied to everyone or to a specific user or group, whether they are Active Directory users and groups or local users and groups defined on the Storebox Portal. In addition, it is possible to apply Cloud Drive content policy rules to external users (that is, users who were invited to collaborate by email address or by means of a public link), by using a special group called "External Users". 14/24
Tip: If Alice, a folder owner, attempts to share a link with an external user, the Cloud Drive content policy rules that apply are both the rules that apply for Alice and the rules that apply for the External Users group. If Bob attempts to re-share a link to Alice s folder with an external user, the rules that apply are both the rules that apply for Bob and the rules that apply for the External Users group. 2.2.4 Password Strength Policy Storebox Portal features a password strength policy to comply with security standards. The portal administrator can: Configure a password rotation cycle (in months) Prevent the re-use of the last X passwords Determine the number of character groups required in a user s password. The available character group values are: Lowercase characters Uppercase characters Numerical characters Special characters such as!@#$ Prevent users from using their personal details in their password, including first name, last name, email, username, and company name. 15/24
This feature is available to the virtual portal administrator via the Virtual Portal Settings menu. 2.2.5 Force Backups to Use or Not Use a Passphrase The portal administrator can force users to use or not use passphrase protection for backups. By default, the passphrase protection policy is set to Optional. To modify it, in the Global Administration View, configure the Backup Passphrase Protection field in the Virtual Portal Settings page s Default Settings for New Folder Groups. Tip: Data protected with a user-defined passphrase cannot be retrieved if the passphrase is lost. 2.2.6 Fine-Grained Control over Workstation Backup License Storebox Portal features fine-grained control over Workstation Backup licenses. Users who use the Cloud Drive service on multiple devices, and who would like to use the Cloud Backup service for only some of them, can now transfer the Workstation Backup licenses to the PCs on which they would like to enable the backup service. For instance, if Alice obtains one Cloud Drive license and one Workstation Backup license, she can use the Cloud Drive license on up to five devices, and she would like to use her Workstation Backup license on one of her five devices. To do so, Alice disables the Cloud Backup service on all of the devices she does not want to back up and leaves it enabled on the one she does want to back up. To disable the Cloud Backup service for one or more connected devices, browse to the End User Portal Web interface, click Devices on the left side of the page, click on the > icon to open the Device Status dialog box, and then choose Disable Cloud Backup. The Workstation Backup license is immediately transferred to the next device you own. 16/24
3 Client 3.1 VDI Mode Storebox Client now includes VDI mode, which enables using the Storebox Client with a virtual desktop infrastructure (VDI) in a Microsoft Windows environment and works with Active Directory. Enterprises and service providers who launch a virtual desktop as a service can leverage VDI mode in order to: Enable users to access data on their Cloud Drive from their virtual desktop. Decouple the user data storage and the actual system storage, as user data will be stored on the Cloud Drive rather than the VDI host. This enables one to: o o Maximize the number of VDI instances that can be hosted on a single host. Save on expensive, high-iops VDI host storage. In order to enjoy these benefits, the enterprise or service provider must incorporate a Storebox Client in VDI mode into the VDI desktop image. VDI mode works as follows: 17/24
1. VDI mode is enabled by applying a registry key to the target machine. For instructions, refer to the document "Using CTERA Agent in VDI Mode" at https://kb.ctera.com/article/using-cteraagent-in-vdi-mode-333.html. 2. When a user accesses their virtual desktop, the Storebox Client performs Single Sign On (SSO) and automatically signs on to the Storebox Portal with the user s credentials as listed in Active Directory. 3. Upon completing SSO, the user s Cloud Drive is mounted as a network drive called Cloud (Z:). If the drive is unavailable, the previous drive letter (for example, Y, X, etc) will be used. 4. The user can then access their personal and shared folders through the network drive. Tip: Tip: It is possible to apply the registry key via Active Directory GPO, by uploading the cteravdi.adm file to the group policy on Active Directory. This file is available from Swisscom Support. Single Sign On (SSO) works only in a portal environment configured with Active Directory. If these conditions are not met, the user will need to input their username and password. 3.2 Outlook Plug-in This feature is currently only supported on Microsoft Outlook for Windows. The Outlook Plug-in is a Microsoft Outlook plug-in that replaces standard e-mail attachments with public links. When a user attempts to attach one or more files to an email thread, a download link can be embedded in the message body, and the attachments synchronized to the Storebox Portal. The email recipient can then use the download link to view or download the files from Storebox Portal. 18/24
The conditions for embedding a download link and synchronizing the attachments are configurable, as follows: Outlook Plug-in can always perform these actions, never perform these actions, or only perform these actions when the size of the attached files exceeds a certain threshold (in MB). The Outlook Plug-in can ask the user before performing these actions. The download link to the sent attachments automatically expires after a certain number of days, and shortly after, the files are removed from the portal s sent attachments folder. 19/24
The main advantages of this feature are: Users can send large files as email attachments. Commonly, exchange servers limit the size of an email attachment. Less exchange server storage is required. Exchange server storage is commonly high-iops, and storing the attachments elsewhere (on the Storebox Portal) helps reduce the amount of storage required. You can define a threshold determining when a public link will be used and when a standard email attachment will be sent. Unlike email, your files are never sent in a non-encrypted format. If needed, you can delete or update files after they have been sent. 3.3 Single Sign On from Client to Portal In the Storebox Client, when a user is redirected to the cloud to perform actions (for example, View Online, Restore, Invite Team Members, and so on), the user will not be prompted to enter their credentials. Instead, the user will be automatically authenticated and presented with the relevant page for the selected action. This feature is supported in multi-user mode and single-user mode. In single-user mode, SSO will be performed only for users with client administration privileges. 3.4 Mac OS X Shell Extension The new Storebox Client provides shell extension support for Mac OS X, providing Mac users with: File and folder synchronization feedback via overlay icons in the finder Right-click options to quickly generate public links, invite team members to collaboration folders, browse previous file versions, browse or view files online, and more. 20/24
3.5 Browse Previous File Versions Shell Extensions In the Storebox Client, you can view the previous revisions of a file synchronized from your Cloud Drive, with just two clicks: 1. Right-click on the desired file, and then click Storebox Client > Version History. 2. You are redirected to the Storebox Portal and presented with a page displaying the file revisions. You can use this feature to quickly view, download, or restore previous file versions as needed. You can also stay up to date on who performed changes to the file, in the event that you are working in collaboration with your colleagues. 3.6 File Edit This feature is currently only supported on Google Chrome for Windows. The Storebox Client automatically installs a browser plugin that enables users to easily edit files downloaded from the portal, and have the updated files uploaded automatically to the portal when they are saved. The flow is as follows: 1. The user accesses the Storebox Portal Web interface, select a file, and clicks Edit. 2. The file is downloaded from the portal and opened by the relevant local PC program. 3. The user makes changes to the file and saves it. 4. The updated copy is automatically uploaded to Storebox Portal. 21/24
Tip: This feature requires a Storebox Client to be installed on the user s PC and logged in to the user s Storebox Portal account. 3.7 Email Notification If a Volume Selected for Cloud Backup is Offline As a Storebox Client owner, you will now receive warning messages if you chose to back up files and folders from a volume/partition that is currently offline. Warnings are displayed in the Storebox Client tray, including the offline drive names. 4 NAS-Gateway 4.1 Sync Gateway Mode NAS-Gateways now include Sync Gateway mode. This feature allows accessing the user s home and shared folders from other NAS-Gateways, for example a gateway at a branch office, while enforcing the permissions set in Storebox Portal. Here is how it works: 1. Enable Sync Gateway mode on the NAS-Gateway. Tip: The NAS-Gateway must be connected to a Storebox Portal using an administrator account. 2. The NAS-Gateway s data synchronizes all the data in the team portal onto local storage, including all the user's home folders and shared folders, and exposes them to local users while preserving file permissions and the directory structure seen by each user. 3. The users access the cloud data from the following network destination: \\<MyCloudGateway>\cloud using standard network access over NAS protocols, such as: CIFS, NFS, and so on. Tip: It is highly recommended to use Active Directory. Otherwise, using Sync Gateway requires the manual creation of local users with the same names as the cloud users. Sync Gateway mode offers many benefits in an office environment: Users can enjoy full LAN speed access to their data when they are in the branch office, using standard file sharing protocols. Furthermore, users retain full offline access to their data during Internet or cloud service outages. Users retain data access (using the same credentials) outside the office, via browser, mobile device, WebDAV network drive, and so on. Sync Gateway mode allows content distribution, so that files and folders can be uploaded to a centralized location (Storebox Portal) and then automatically synchronized to remote gateways that reside at the branch. Sync Gateway mode allows collaboration between users in different branch offices. Sync Gateway mode also accommodates user migration procedures, so that if users are migrated from one branch to another, or if they frequently travel between branches, their files and folders will follow them to the target branch. 4.2 NAS-Gateway Network Troubleshooting Tools 22/24
The following network troubleshooting tools were added to the NAS-Gateway, to diagnose potential network-related issues: ping For testing the reachability of a host on the network nslookup For querying the DNS traceroute For displaying the route packets across the network TCP Connect For testing whether a specific TCP port is open The network troubleshooting tools are available through the gateway s administrator Web interface, under System > Network > Diagnostics. 4.3 Email Notification on Predicted Drive Failure In a case of a drive failure, or if the drive has indicated that it will likely fail in the near future, an e-mail notification is sent to the Storebox NAS-Gateway administrator, so that the administrator can quickly address the problem. 4.4 SMART Disk Health Check You can check the health of the disks attached to the NAS-Gateway, by running a disk health check through the gateway s administrator Web interface. You can run short or long SMART tests. You can perform SMART tests on drives as follows: 1. Access the gateway s management interface using the gateway administrator account. 23/24
2. In the navigation pane, click Dashboard. 3. Select the requested drive. 4. Click on the Self Test tab. 24/24