Version
|
CU
|
5.0.8308.301
|
|
5.0.8308.291
|
Lync 2013 Monitoring Server Versions Table
Quick and dirty post which I'll update as and when the monitoring server version gets incremented:
Lync 2013 - September 2015 CU - now with added security patch
On Friday (October 2nd) the downloadable CU that Microsoft publish as "the latest" (read only) update got moved to version 5.0.8308.933
There are some good updates in there for such things as high CPU usage on a topology publish and unable to join a meeting from iOS 9.
One of the confusing things is that the September security update still has the following text:
Now - leaving aside the copy and paste that has resulted in "Lync Server 2013" being on the line twice we have the confusion around should this be after the latest update (5.0.8308.933) or the latest update when the security article was first published (5.0.8308.920).
The security patch was actually 5.0.8308.927:
and as such versioning dictates that 5.0.8308.933 should contain all of the security goodness that was lacking in the July CU, and to find that out you have to drill deeper into the release notes 5.0.8308.933 of the web components server:
showing that yes - the latest CU does indeed contain the security update. Thus the only reason I can see for the security update to still be offered as its own download is if you are at the July (5.0.8308.920) CU (as that is a prerequisite) and do not want to move to the latest CU (5.0.8308.933) but do now want the security patch installing.....
There are some good updates in there for such things as high CPU usage on a topology publish and unable to join a meeting from iOS 9.
One of the confusing things is that the September security update still has the following text:
Now - leaving aside the copy and paste that has resulted in "Lync Server 2013" being on the line twice we have the confusion around should this be after the latest update (5.0.8308.933) or the latest update when the security article was first published (5.0.8308.920).
The security patch was actually 5.0.8308.927:
and as such versioning dictates that 5.0.8308.933 should contain all of the security goodness that was lacking in the July CU, and to find that out you have to drill deeper into the release notes 5.0.8308.933 of the web components server:
showing that yes - the latest CU does indeed contain the security update. Thus the only reason I can see for the security update to still be offered as its own download is if you are at the July (5.0.8308.920) CU (as that is a prerequisite) and do not want to move to the latest CU (5.0.8308.933) but do now want the security patch installing.....
When is a Cumulative Update not a Cumulative Update? When it's a security patch. #BadJoke #Lync2013 #SfB2015
Updated 22:21 BST, Skype for Business is now re-released as a full Cumulative Update - did this post help :-)
Updated 6th October - new FULL CU out for Lync 2013 that includes the security patch
Quick heads up that the September 2015 security update for Lync Server 2013 and Skype for Business Server 2015 is delivered as a CU installer *BUT* without previous updates included:
"Before installing any updates for Skype for Business Server 2015 or Microsoft Lync Server 2013, the latest publicly released Cumulative Updates for Skype for Business Server or Lync Server must be installed"
This does lead to an issue that has been seen already where CU's are getting out of step and indeed is called out in this update:
"Known issues:
After you install this security update on a system that is running Microsoft Lync Server 2013, you find that the Central Logging Service is not listening on designated ports.
Cause
This problem can occur if you install this security update on Lync Server 2013 before you install the August Update of Lync Server 2013.
Resolution
If you already installed this security update without first installing August 2014 Update 5.0.8308.738, you must uninstall this security update, install August 2014 Update 5.0.8308.738, and then reinstall this security update."
(Unsupported fix: http://aspoc.net/archives/2014/09/30/error-lync-server-centralized-logging-service-could-not-be-started/)
So taking a brand new RTM install of Lync 2013 to get fully up to date you would need to:
Updated 6th October - new FULL CU out for Lync 2013 that includes the security patch
Quick heads up that the September 2015 security update for Lync Server 2013 and Skype for Business Server 2015 is delivered as a CU installer *BUT* without previous updates included:
"Before installing any updates for Skype for Business Server 2015 or Microsoft Lync Server 2013, the latest publicly released Cumulative Updates for Skype for Business Server or Lync Server must be installed"
This does lead to an issue that has been seen already where CU's are getting out of step and indeed is called out in this update:
"Known issues:
After you install this security update on a system that is running Microsoft Lync Server 2013, you find that the Central Logging Service is not listening on designated ports.
Cause
This problem can occur if you install this security update on Lync Server 2013 before you install the August Update of Lync Server 2013.
Resolution
If you already installed this security update without first installing August 2014 Update 5.0.8308.738, you must uninstall this security update, install August 2014 Update 5.0.8308.738, and then reinstall this security update."
(Unsupported fix: http://aspoc.net/archives/2014/09/30/error-lync-server-centralized-logging-service-could-not-be-started/)
So taking a brand new RTM install of Lync 2013 to get fully up to date you would need to:
- Install August 2014 Update 5.0.8308.738 OCSCore.msp (although that appears to have issues too!)
- Patch to July 2015 cumulative update 5.0.8308.920
- Patch to September 2015 Security update 5.0.8308.927
For Skype for Business Server 2015 the process is a little easier since there is just the one CU out at the moment:
Patch to June 2015 cumulative update (6.0.9319.55)- Patch to September 2015 Security update (6.0.9319.72) Updated as 10 hours later Microsoft revised their security update.
I would hope that the next *real* CU for both products Lync 2013 actually become true CUMULATIVE updates and include all previous versions with no requirement to uninstall/reinstall individual components..... but I'm not holding my breath!
No T-Rex love in Skype for Business (sadface)
Today the Skype for Consumer blog posted that a funky new emoticon was available to celebrate the launch of Windows 10 (and related to Ninja Cat of course).
Unfortunately its not available in the stuffy Skype for Business client :-(
Unfortunately its not available in the stuffy Skype for Business client :-(
Lync Server 2013 Updates - July 2015 (CU13)
July's updates have the following new items in them:
|
Participants cannot see your video when you join an online meeting
through B2BUA in a Lync Server 2013 environment
|
|
|
Response group usage report takes longer time to run or cannot
complete in a Lync Server 2013 environment
|
|
|
Call park orbit number is not displayed when you park a call in a
Lync Server 2013-based environment
|
|
|
Lync Mobile Client call is dropped immediately when you dial 0 for an
operator
|
|
|
Lost data when Lync Server 2013 directories move to Skype for
Business
|
|
|
Event ID 1000 is logged and RTCSrv.exe crashes when the process is
selected in Resource Monitor tool in Lync Server 2013
|
|
|
CPU usage percentage of the RTCSrv.exe process is high on a Lync
Server 2013 front-end server
|
Updates available from: https://www.microsoft.com/en-us/download/details.aspx?id=36820
Changing SQL Database Owner for Lync 2013
When you install SQL back end the mirroring endpoint is set to the person who ran the installer (so in our case Domain\XXXXRichXXXX)
If you use the following SQL:
You will get back the current endpoint owner (PrincipalName), what other endpoints can interact with the mirror (GRANTED TO) and who granted those rights (GRANTED BY)
This example is from XXX-SQL01 Principal, its partners are XXX-SQL02 mirror and XXX-SQL03 Witness:
As the Domain\XXXXRichXXXXX account is being removed we created a new Service Account called “DOMAIN\svc-lync-sqlmirror” (standard windows user).
Then on each endpoint in the SQL mirror (Principal, Mirror, Witness) ran the following (changing the server names as appropriate in the final SQL block):
After running the above the owner has now changed:
Once all three mirror partners changed rebooted the servers in the following order:
Ensure you wait between each reboot to allow the mirror state to become stable again (all green ticks):
(to run this, Open SQL Server Management Studio > Right click a mirrored database > Tasks > Launch database Mirroring Monitor
Edited 12/07/2015 to note that the db's will be on the mirror server after performing this procedure
If you use the following SQL:
SELECT
[PrincipalName] = sp.name, [PrincipalId] = sp.principal_id, me.*
FROM sys.database_mirroring_endpoints me with(nolock)
inner join sys.server_principals sp
with(nolock)
on me.principal_id = sp.principal_id
SELECT EPS.name, SPS.STATE,
CONVERT(nvarchar(38),
SUSER_NAME(SPS.grantor_principal_id))AS [GRANTED BY],
SPS.TYPE AS PERMISSION,
CONVERT(nvarchar(46),SUSER_NAME(SPS.grantee_principal_id))AS [GRANTED TO]
FROM sys.server_permissions SPS ,
sys.endpoints EPS
WHERE SPS.major_id = EPS.endpoint_id
ORDER BY Permission,[GRANTED
BY], [GRANTED TO]
You will get back the current endpoint owner (PrincipalName), what other endpoints can interact with the mirror (GRANTED TO) and who granted those rights (GRANTED BY)
This example is from XXX-SQL01 Principal, its partners are XXX-SQL02 mirror and XXX-SQL03 Witness:
As the Domain\XXXXRichXXXXX account is being removed we created a new Service Account called “DOMAIN\svc-lync-sqlmirror” (standard windows user).
Then on each endpoint in the SQL mirror (Principal, Mirror, Witness) ran the following (changing the server names as appropriate in the final SQL block):
USE
[master]
GO
CREATE LOGIN [DOMAIN\svc-lync-sqlmirror] FROM WINDOWS WITH DEFAULT_DATABASE=[master]
GO
ALTER SERVER ROLE
[sysadmin] ADD MEMBER
[DOMAIN\svc-lync-sqlmirror]
GO
ALTER AUTHORIZATION ON ENDPOINT::mirroring_endpoint
TO [DOMAIN\svc-lync-sqlmirror]
GRANT CONNECT ON ENDPOINT::mirroring_endpoint
TO [DOMAIN\XXX-SQL02$]
GRANT CONNECT ON ENDPOINT::mirroring_endpoint
TO [DOMAIN\XXX-SQL03$]
- The first block adds the Service Account in as a SysAdmin
- Next block changes the owner to be the Service Account
- Last block grants permissions back to the other two SQL servers to be part of the mirror again (running the second block wipes this out - http://blogs.perficient.com/microsoft/2014/03/changing-the-sql-mirror-endpoint-owner-breaks-mirror-in-lync-2013/)
After running the above the owner has now changed:
Once all three mirror partners changed rebooted the servers in the following order:
- Witness - (XXX-SQL03)
- Mirror - (XXX-SQL02)
- Principal - (XXX-SQL01)
(note that your DB's will be on the Mirror at the end of this procedure so use Invoke-CsDatabaseFailover to fail back - https://technet.microsoft.com/en-us/library/jj204991(v=ocs.15).aspx or reboot the mirror again!)
Ensure you wait between each reboot to allow the mirror state to become stable again (all green ticks):
(to run this, Open SQL Server Management Studio > Right click a mirrored database > Tasks > Launch database Mirroring Monitor
Edited 12/07/2015 to note that the db's will be on the mirror server after performing this procedure
Remote Code Execution or Skype for Business 2015 client, you choose!
Microsoft today released a patch that builds on the April 2015 client side patch. As such this means you need to have already taken the steps shown in my previous post if you want to block the new Skype for Business UI. After applying this patch there are some parts that will all reflect the new Skype branding even if you do make the previously advised changes:
In addition the sounds will change.
Having run the new Skype UI for a while now I much prefer it to the Lync 2013 UI, my call out features are the Call Hover window when you are in a call and pass focus to another application, this stops your scrambling about trying to find the active call to mute/unmute, hangup!
and the new emoticons :-D
- the notification area icon (it's not the system tray)
- the menu item in Windows
In addition the sounds will change.
Having run the new Skype UI for a while now I much prefer it to the Lync 2013 UI, my call out features are the Call Hover window when you are in a call and pass focus to another application, this stops your scrambling about trying to find the active call to mute/unmute, hangup!
and the new emoticons :-D
Subscribe to:
Posts (Atom)











