This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Pre-configure Mac Packages installs as 9.4.3, then downgrades to 9.2.10 on updating

Good morning,

Network setup

Clients are pre-configured to use the existing relays (avrelay01, avrelay02) as update sources. 

The primary update source called avmain updates from sophos and pushes any updates to the relays. It has a SEC installed.

Problem

We needed to create a new package for out mac clients, because our old package did not install on El Capitan. This succeeded, Endpoint version is 9.4.3 right after the installation, updates sources are avrelay01 and avrelay02

After updating, the Endpoint software downgrades to 9.2.10. It is still running (and working, as far as I can tell, I am no Mac guru), but I am still amazed why the client does that. Even wondering where he gets the sources from.

I checked the software abonnements on avmain, for Mac it is on "Recommended" which translates to 

  • Platform: Mac OS X - Please see KBA119018 for supported platforms
  • Version: 9 Recommended
  • Functions: Anti-virus, Device Control

Details are showing:

  • Sophos Anti-Virus for Mac OS X: 9.4.3
  • Sophos Detection Engine for Mac OS X : 3.64.1

So that seems to be in order.

Additional information:

  • Even while manually configuring the Endpoint to use avmain as an update source, he still stays at 9.2.10 and does not upgrade to 9.4.3.
  • I am no SEC/ Sophos expert, so please be gentle with explanations

Question

What the heck is going on? Can I check what version is residing on the http update path, I don't know which files to check for that. Why does the client downgrade at all? Why doesn't the client install the version the update sources provide?

Thanks for your assistance, 

Sebastian Will



This thread was automatically locked due to age.
  • Hello Sebastian Will,

    first of all, you tagged your post deployment packager - that might be confusing as Deployment Packager is the tool to create packages for Windows (only).

    Anyway, that the endpoints downgrade suggests that the location they are updating from contains 9.2. They are updating via HTTP? You can check the version in the file http://<yourupdatepath>/Sophos%20Installer.app/Contents/Info.plist, (yourupdatepath could look like //server/SophosUpdate/CIDS/S000/ESCOSX) looking for the string following <key>CFBundleShortVersionString</key>.

    I assume SEC does not show any SUM errors. Do you use subscriptions other than Recommended?

    Christian