Views:

The ACS Certificate Integrity Checking Enhancement will be added from:

  • Apex One as a Service March 2023 maintenance – (Block New Agent Installation & Block Program Upgrade)*
  • Apex One On-Premise March Critical Patch release – (Block New Agent Installation & Block Program Upgrade)*
 

The non-ACS program upgrade blocking is a best effort implementation to prevent accidental deployment of new build on non-ACS compliant system.

Customers are strongly advised to apply appropriate MS KB immediately to enable ACS support before deploying latest Apex One builds.

Important notice on Non-ACS blocking enhancement:

  • On some environment, the ACS compliant detection logic may not work correctly and fail to block program updates on non-ACS compliant systems.
  • If current agent build is at Dec 2022 build(11960) or lower, user might experience high network usage due to repeated downloads of program upgrade module.
  • Non-ACS supported endpoint may remain unnoticed at an old build missing out on critical security fixes that may increases vulnerability of the system.
 

Please refer to the summary table for Trend Micro recommendations:

ACS Compliance LevelRecommendationOther Info
All systems are ACS compliantCan apply latest build without any issuesCan upgrade agents to latest build without issues
All systems are not ACS compliantDisable Agent program upgrade before applying latest hot fix or patch. Please install appropriate Windows KB before applying re-enabling program upgrade. Warning: It is recommended to separate the systems by grouping and to upgrade only ACS compliant systems.In-place upgrade using EXE or MSI package will also do ACS check and block if not compliant.
Systems are partially ACS compliant

 

If the target endpoint does not have the required Windows updates, the following messages will be shown:

  1. Applying Patch on Apex One server (On-Premise)

    Apex One Critical Patch

    Click the image to enlarge.

  2. Fresh Installation of Apex One Security Agent:
    • Popout message (Standalone MSI Installer)

      Unable to Install 1

      Click the image to enlarge.

    • Web Console Remote Installation (On-Premise)

      Unable to Install 2

      Click the image to enlarge.

  3. Program Update: Application Event Logs will have recorded events below. (Security Agent will stay on current version)

    Program Update

    Click the image to enlarge.