Neverfail Engine 23 Release Notes

Neverfail Engine 23 Release Notes

Summary

The following information applies to the v23 release of Neverfail Engine.

Engine 23.0

This release supersedes Engine v22.

What's New

Independent Identity Installation via CLI

  1. Engine may be deployed in an Independent Identity (IID) cluster architecture via CLI Installer only.
    1. CLI deployment process demands configuration of Standard / Independent Identity installation type.
    2. EMS driven installation currently supports only Standard (Cloned Identity) cluster architecture.
    3. Requirement: IID deployment must be driven via Neverfail Professional Services: additional requirements and post-deployment configuration may be needed, depending on the deployment scenario and protected application.
  2. Plugins will be changed to support IID application deployment (where applicable).

In-Product Notification Optimizations

  1. Core delivery mechanism improvements.
  2. Interactive notifications are pushed to EMS then to managed Engine clusters. Advanced Management Client users will "see" the notifications in-AMC.
  3. Silent trigger mechanism improvement: separate threads for unicast/multicast/broadcast Engine targets.
  4. License authorization features and plugins updates are pushed and applied automatically on Engine targets (online licensing scenario). 
    1. Engine license check mechanism will alert any unlicensed items situations.

Engine Compliance - SBOM

  1. SBOM improvements: 
    1. Downloadable SBOMs (CycloneDX) are available in EMS for current GA version of Engine components.  
    2. Added missing component supplier information (required by NTIA).
    3. Added verification pack containing the digital signatures and public key required to verify the integrity and authenticity of the Engine SBOMs.

Alerting based on Managed Server Telemetry

  1. By enabling telemetry, you empower the EMS to deliver better monitoring and alerting for critical events that matter most to your business. This will translate into quicker response times, more accurate alerts, and ultimately, greater peace of mind knowing that your systems are running optimally.
  2. The first chapter in unlocking advanced monitoring and alerting was to enable our new telemetry service v16, which will seamlessly extract relevant information about events happening on the Engine nodes.
  3. v17 adds more to this feature by improving the telemetry data upload-via-EMS feature for a deployment not managed via Engine Management Service. 
  4. v18 enables In-Product Notification feature which may be used for announcing and alerting customers with relevant Engine information.
  5. v19 extends and prepares notification vehicle to be used in relicensing and alerts delivery.
  6. v20 brings granular, deeper access to Engine online deployment targets for Engine silent relicense mechanism. 
  7. v21 extends In-product Notification for managed Engine servers receiving license authorization updates.
  8. v22 brings in-AMC notification: interactive notifications are pushed as far as to managed Engine clusters, enabling users to see and manage them in-AMC also (additionally to in-EMS).
  9. v23 brings expanded telemetry reporting to improve alerting precision and accuracy for user defined configurations.

Better User Experience

Application Management - Automating Discovery and Protection via Dedicated Plugins  (on-going)

  1. New plugins will be developed and added to Engine family, release by release. These plugins will replace the manual implementation of User Defined application protection. 
  2. Application protection made simple. Homogeneous. Reliable.

Engine Management Service Web Console (EMS)

  1. Service Security
    1. Updated the Neverfail Engine Management Web Services to log on using a dedicated Windows Virtual Account.
  2. UI & Usability Enhancements
    1. Show services display names when adding service to protected set.
    2. Easily retrieve the standalone AMC (x64 .msi) installer from the Settings menu within the EMS UI.
  3. EMS Online Licensing Wizard
    1. Automated retrieval of license activation key for existing (paid) subscriptions.
  4. EMS Offline Licensing Management
    1. UX Improvements for hardened environments: managed server will show Product Version on grey background with tooltip message "Cannot validate support". Access to offline licensing is permitted.
    2. Self-service offline licensing based on telemetry data: customers may claim license keys directly from Engine Management Service for deployments which are not managed via EMS.
    3. Install Engine Management Service on any supported Windows machine with access to internet (i.e. Engine Licensing Server) then claim your license keys corresponding to your purchased software subscription from the Support section. Details in Self-Service Offline Licensing: How to Claim a License Key for a Deployment Not Managed via Engine Management Service.
  5. EMS Alerts Bar Improvements
    1. EMS Alerts Bar is a lightweight, always-visible Windows notification bar running on machines where EMS web console is installed to provide real-time monitoring of Engine clusters health by displaying the latest events, role assignments, and replication status.
    2. Improved events handling in Engine transition scenarios.

    Advanced Management Client (AMC)

    1. UI & Usability Enhancements
      1. Make it more obvious which are tasks and which are sections or sponsors.
      2. Change the button labels added lately to match the existing Title Case pattern
      3. Show services display names when adding service to protected set.
    2. In-AMC Notifications: users will "see" and manage notifications also in AMC UI, additionally to EMS UI.
    3. License Management: hot-add/remove license keys without stopping Engine service.
    4. Remote Engine management
      1. Standalone AMC (x64 MSI) Installer and Portable AMC (zipped) - updated with all the improvements.
        1. more details in: Neverfail Engine Advanced Management Client (Portable) Requirements 
    5. Quad configuration support where compatible* (customized 4-node, dual-site HA). 
      1. *requires compatibility check and implementation via Neverfail Professional Services.

      Patching Downtime Reduction with Passive Management Name

      1. Engine's Passive Management Name feature enables the ability of patching of standby passive nodes in centralized update management environment.
      2. Following document lists all the Patch Management or Backup Software Solutions / Technologies proven to work or scheduled in the near future for interoping validation with Engine's Passive Management Name feature: Patch Management Solutions / Technologies supported by Engine's Passive Management Name

      Mitel CX Plugin v201.5.8 - Support for Mitel CX 3.0

      1. Support for Mitel CX 3.0 for MiVB  / SIP deployments
      2. Optimizations in starting (and respectively stopping) protected MCX services. 
      3. More details in Mitel CX Plugin v201.5.8 - Release Notes

      SQL Server Plugin v201.5.20 - Separate Licensing for Express Tier and Enterprise Tier

      1. Automated discovery mechanism improvements for detecting installed instances edition. 
        1. SQL Server Edition Support: This plugin supports both SQL Server Express and SQL Server Enterprise editions.
        2. Licensing Requirement: A valid Express Tier or Enterprise Tier license key must be applied to match your target database edition.
      2. Support enhancements for SQL Server 2025 Standard, Enterprise, and Express Editions 
      3. More details in SQL Server Plugin Version 201.5.20 - Release Notes.

      PostgreSQL Plugin v201.5.2 - Support for PostgreSQL 17.x, 18.x, and 19 (Beta)

      1. Support for EnterpriseDB PostgreSQL 17.x, 18.x, and 19 (Beta)
      2. More details in PostgreSQL Plugin v201.5.2 - Release Notes.

      MySQL Server Plugin v201.5.5 - Support for MySQL Server 8.4 LTS, 9.7 LTS

      1. support for MySQL Server 8.4 LTS, 9.7 LTS (Community, Standard, and Enterprise editions).
      2. More details in MySQL Server Plugin v201.5.5 - Release Notes.

      Progress MOVEit 2026 Plug-ins Suite - Support for MOVEit 2026.0

      1. Support for MOVEit Automation Server 2026.0.
      2. Support for MOVEit Transfer Server 2026.0.
      3. New MOVEit Automation Server 201.5.8 plugin with improvements in automated discovery mechanism.
      4. Support for MySQL Server 9.7, MySQL Server 8.4
      5. More details in Progress MOVEit 2026 Plug-ins Suite - Release Notes.

      Automated Logic WebCTRL Plugin v201.5.4 - Support for WebCTRL 10.0

      1. support for Automated Logic WebCTRL 10.0.x system
      2. More details in Automated Logic WebCTRL Plugin v201.5.4 - Release Notes.

      System Plugin v401.0.13 - Support for IID

      1. Auto-configuration depending on Engine Standard or Independent Identity* installation
        1. Plugin will configure the protected data set and configuration depending on Engine's installation type implemented starting v21. No more need of any extra user configuration - all happens behind the scenes, automatically.
        2. Improvements to 'Cloned installation check' rule's triggering conditions.
          *limited support - Independent Identity deployments require Professional Services driven deployment
      2. Alerting service: Notifications received from EMS are replicated to all the Engine cluster nodes. This assures Advanced Management Client inline displayed notifications are in sync across all the active/passive nodes.
      3. More details in System Plugin v401.0.13 - Release Notes.

      Advanced User Defined Application Protection - Preview Announcement

      1. We are expanding our application protection capabilities by introducing Advanced User-Defined Application Protection. This feature empowers users to create highly customizable protection profiles for non-plugin-protected or proprietary applications directly within the AMC and EMS interfaces.
      2. Note: This feature is currently in active development. Specifications, UI availability, and underlying architecture are subject to refinement prior to general availability.

      Advanced Process Management

      1. Leverages ExeProcessManager for granular execution control and process lifecycle protection.
      2. Automates the launching, monitoring, and stopping of desktop applications and background EXE processes during Neverfail Engine start and failover plans.
      3. This plugin operates both as a GUI for configuration and a headless CLI runtime called directly by Engine tasks, eliminating the need for PowerShell scripts, CMD batch files, or Windows Scheduled Tasks

      Import/Export User Defined Configuration

      1. Back up your personalized settings by exporting them to a file, or import an existing configuration file to instantly apply your saved setup.

      Expanded Telemetry Reporting

      1. Enhanced telemetry automatically gathers user-defined configurations—including protected services, file filters, registry filters, and scheduled tasks—to help identify application trends and improve community templates.

      Registry Filters Management (coming soon)

      1. Integrated protection and filter definition for Windows Registry keys exposed in both AMC and EMS UIs

      Community Template Repository (coming soon)

      1. Access and contribute to a shared repository of user-defined protection templates to streamline deployment of common third-party applications.

      Access to Engine Utilities Repo

      1. Access Engine collection of utility scripts and add-ons designed to extend core features
      2. Collaborate for enhancing and extending Engine functionality for specific scenarios 
      3. Utilities repo may be accessed directly from EMS UI> Support> Add-ons

      Snapshot Management Improvements

      Ransomware Recovery: With Snapshot Management organizations can take snapshots each 15 minutes and roll back the dataset to before the incident happened thus restoring the protected application server to full operating conditions.
      1. How to Use Engine For Ransomware Mitigation
      2. How to Setup Snapshot Management for Neverfail Engine

      CLI Installer Improvements

      1. Installer: Strengthened privilege verification checks to ensure adequate system permissions before installation.. 
      2. Upgrade:  Improvements in passive node upgrade process to ensure it remains  hidden from the network during Engine upgrade.  
      Engine command-line installer (CLI) may be used for installing, upgrading or uninstalling Engine on a specific node. 
      It was designed to be used in the scenarios where EMS-driven fully automated install/upgrade cannot be used. Contact Support for guidance.

      More Secure

      Security Updates for Bundled Open-Source Dependencies

      Software Integrity & Release Verification

      • Compliance: SBOM (CycloneDX) with verification pack is now available for this release, providing transparency to help identify and manage vulnerabilities.
      • Integrity & Verification: A separate .sha256 sidecar file is provided alongside each .msi installer for download checksum verification.
      • Build-Time Binary Authenticity: All compiled binaries (.exe, .dll) are digitally signed at build time using an EV Code Signing Certificate (Neverfail, LLC), and final .msi installer packages are signed prior to distribution.

      New Supported Versions

      VMware vCenter Server and VMware vCenter Converter Support

      1. Supported - Engine Management Service API Support for deployment using the latest versions of VMware vCenter Server 7.0 and VMware vCenter Converter 6.2.
      2. Supported - vSphere Integration Plugin Support for interoping with the latest versions of VMware vCenter Server 7.0
      3. Supported - Engine Management Service API Support for deployment using the latest versions of VMware vCenter Server 8.0 and VMware vCenter Converter 6.3.
      4. Supported - vSphere Integration Plugin Support for interoping with the latest versions of VMware vCenter Server 8.0.
      5. Coming Soon - Engine Management Service API Support for deployment using the latest versions of VMware vCenter Server 9.0 and VMware vCenter Converter 6.6.
      6. Coming Soon - vSphere Integration Plugin Support for interoping with the latest versions of VMware vCenter Server 9.0.

      Licensing Updates 

      License Management - Plugin Subscription

      1. Each Engine deployment requires the appropriate Plugins to be installed and corresponding Plugin subscriptions to be purchased.
      2. A separate Plugin subscription is required for each installed and protected application that has its own dedicated Plugin. 
      3. Important: Engine detects unlicensed installed Plugins at runtime and consequently will raise repeated Invalid License error notifying user to fix the situation by purchasing the required Plugin subscription.  Not fixing the situation will lead to plugin uninstallation.  

      Licensing Service Access only for Supported Versions

      1. End-User License-Subscription Agreement changes are summarized in the below section extracted from Neverfail End-User Software Subscription License Agreement.
      2. License Key Issuance vs. Software lifecycle: License Key issuance for a new or a renewed Software Subscription is viable only on currently supported versions of the Software..
      3. Engine follows a software subscription term and rental licensing  model. Engine Licensing Service (ELS) enables call-home features that power our software subscription based licensing. The new license service is free but is required for Term and Rental deployments. For more information on how the licensing works and upgrade notes please read Engine Licensing Model. 

      Backward Compatibility

      Engine 23 Management Service is compatible with older supported versions of Engine (i.e. EMS 22.0 manages correctly, including licensing services, for all the supported versions 19/20/21/22). 

      1. If I upgrade to Engine 23, will my perpetual license cease? Yes! You are accepting software subscription's  requirements outlined in the new EULA for Term and Rental. Neverfail will generate new software subscriptions expiring the same day as the support was paid through. This means you will need to pay for support to continue software operations yearly or monthly depending on the type of subscription.
      1. Can I upgrade using the Upgrade Wizard from older/unsupported versions to Engine 23? Yes, the upgrade wizard is still supported. Keep in mind that Continuity Engine versions 6.7, 7.x, 8.x, 9.x, 10, 11, 12, 13, 14, 15, 16, 17, 18 are currently End-of-Life (EOL), thus Unsupported. To ensure organization continued support and access to licensing services, you must upgrade to the latest Continuity Engine version.
      2. When will Engine EOL? Check End of Life Policy for Neverfail Engine

      3. Can I stay on previous versions of Engine? Yes, however, previous versions will eventually EOL and you will not be able to take full advantage of the new features of Continuity Engine. And evenly important, your systems will be more exposed to cyberattacks. For example:

        1. CEv18.0
          1. misses all the Java OpenJDK security fixes released between April 2025 (8u452-b09) and July 2026 (8u502-b07).
          2. misses all the Apache Tomcat security fixes released between May 2025 (Tomcat 9.0.105) and July 2026 (9.0.120).

      Fixed Issues

      1. [EN-6799]: [AMCx64]: Group/Connection behaves funky: works when defined first. But after restarting AMC group definition is missing and defined connection is misbehaving.
      2. [EN-6816]: [EMS UI]:Logout after timeout expires is not user friendly - it shows a lot of RED toast messages. 
      3. [EN-6828]: [CLI Installer]: Fix version reporting. 
      4. [EN-6848]: [EMS UI]: Replace login suggested "administrator" with something more appropriate indicating a local\domain account.
      5. [EN-6904]: [Windows Server 2025 Support] -  Fix for Preinstall validation check: "Cannot determine number of Free System Table pages."
      6. [EN-6839]: Neverfail Engine's listener thread for the AMC GUI (port 52267) crashes silently sometimes.
      7. [EN-7005]: [EMS UI]: Dashboard> Supported versions is not loading the pie chart if no Unknown servers are counted, when version support cannot be evaluated (i.e. ELS cannot be contacted)
      8. [EN-7006]: [EMS UI]: Settings> vCenter Server connection> Delete should be allowed (button enabled) when Status is Not connected.
      9. [EN-6716]: [FileServer plugin vs Windows Update]: Windows Updates changes the MsQuic service into not-a-service. This impacts plugin's service protection.  
      10. [EN-6868]: [CLI]: Leftover NFBase path using PFx86 path is causing issues with CLI upgrade.
      11. [EN-6899]: Engine licensed features validator enhancements. 
      12. [EN-7149]: Removed welcome file list declaration from HBWS web.xml that was useless anyway (not being used).
      13. [EN-7123]: Cannot connect from remote AMC client to Engine server: Error unmarshaling return header.
      14. {EN-7192}: [CSW]: Rename "Physical Hardware Identity" to "Server Node Identity".
      15. [EN-7191]: [Systray tool]: Rename "View NT Event Log" to "View Windows Event Log".
      16. [EN-7225]: Subscription identifiers are not persisted at online licensing when no new license key is generated.
      17. [EN-7198]: [EMS Scope collector task refactoring]: Change the way collected data is kept then sent to avoid potential OOM in heap space.

      Supported Deployment Infrastructure

      • Server roles/applications for which protection will be installed automatically via plugins are:
        • SQL Server 2008 SP4*, SQL Server 2008 R2 SP3*, SQL Server 2012 SP4*, SQL Server 2014 SP3*, SQL Server 2016 SP3, SQL Server 2017, SQL Server 2019, SQL Server 2022. SQL Server 2025
        • Exchange 2010 SP3*, Exchange 2013 up CU17*, Exchange 2016*, Exchange 2019
        • SharePoint 2007 SP2, SharePoint 2010 SP2, SharePoint 2013 up to SP1*, SharePoint 2016, SharePoint 2019
          • Microsoft Office Online Server 2016*
        • File Server including Windows Server 2025 version
        • Internet Information Server including v10 on Windows Server 2025 version
        • Progress MOVEit Automation & Transfer: Central 8.0/8.1, MOVEit DMZ 8.1, MOVEit 2017, MOVEit 2018, MOVEit 2019.2, MOVEit 2020.1, MOVEit 2021.1, MOVEit 2022.1, MOVEit 2023.0, MOVEit 2023.1, MOVEit 2024.0, MOVEit 2024.1, MOVEit 2025.0, MOVEit 2025.1, MOVEit 2026.0
        • MySQL Server 5.x, 8.0, 8.4, 9.7
        • Mitel CX 3.0, Mitel CX 2.x, Mitel CX 1.x, MiContact Center Server v9.0, MiContact Center Business 9.3, MiContact Center Business 9.4, MiContact Center Business 9.5MiContact Center Business R10.0/SIP
        • Any of the following SolarWinds Orion Network Management components: SolarWinds NPM v12.0.1, v12.1, SolarWinds APE v12.0.1, v12.1, SolarWinds NCM v7.5.1, v7.6, SolarWinds SAM v6.3.0, v6.4, SolarWinds NTA v4.2.1, v4.2.2
        • Oracle Database 19c, 18c, 12c, 11g
          • Oracle Management Agent v12, v13
        • System Center Operations Manager (SCOM) platforms: 2007*, 2007 R2*, 2012*, 2012 R2*, 2016, 2019 
        • PostgreSQL 9.3, 9.4, 9.5, 9.6, 10.x, 14.x, 15.x, 16.x, 17.x, 18.x, 19
        • Apache Tomcat 8.x.x., 9.x.x, 10.x.x. versions
        • OpenText CX-E Voice (formerly xMedius/AVST CX-E/CallXpress) up to version 23.4
        • Clever Devices CleverCAD 9.9, 10.x
        • Automated Logic WebCTRL 8.0, 9.0, 10.0
        • Hyper-V Server 2016, 2019, 2022 (non-clustered architecture)
        • Mitel BluStar 7.3.0
        • OPSWAT MetaDefender Managed File Transfer v3.6.x, 3.7.x., cloned or non-cloned architecture
        • Honeywell Pro-Watch 6.5.1, 6.6
        • Honeywell MAXPRO VMS R795
        • Siemens Desigo CC 7.0
      • Additional supported plugins
        • Neverfail CE for Business Application
           *Limited support as per manufacturer (via older Continuity Engine versions) - contact Neverfail Support 

      Engine Plugins

      Note: Detailed information about each plugin is contained in the plugin's knowledgebase file that is available by clicking on the link.

      Engine plugins provide protection for specific installed application configuration data, services, and application data files.  

      The following plugins are included in this release of Engine and are installed automatically if the application is present and version supported:

      Plugin Installation

      Initial installations of Engine Plugins must be performed using the Engine Management Service. Subsequent plugin re-installations and upgrades may be performed using the Applications: Plugins tab of the Advanced Client. However, Neverfail recommends that any subsequent plugin repair installations or upgrades to be performed using Engine Management Service.    

      To manually install a plugin follow the How to install a Continuity Engine Plugin using Advanced Management Client procedure.

      Known Limitations

      • Passwords starting and/or ending with space ( ) character(s) are not supported (EN-3935).
      • (Re)cloning limitation: Disconnected Engine cluster after a cloning or recloning action: recloned node is connected to wrong port group. Workaround documented in Continuity Engine Cloning and Recloning limitations: disconnected Engine cluster  (EN-3354)
      • Recloning limitations when Continuity Engine passive nodes when static routes are configured: these are listed in Engine Recloning limitations when static routes are configured  (EN-3355)
      • Continuity Engine Localization limitations: following localized versions of Windows Server targets/topologies are supported for Engine installation: (EN-3221) 
        • any WS2008R2, WS2012/R2, WS2016 OS domain or workgroup member protected by HA, DR or HA+DR Engine topology having only alphanumeric chars in its hostname and AD domain name
        • any WS2008R2, WS2012/R2, WS2016 OS domain or workgroup member protected by HA or DR-with-same-Public-IP Engine topology having only alphanumeric chars in the AD domain name
      • Engine Management Service will not uninstall a server with an expired license (EN-1315).
      • Continuity Engine .msi installer package is sometimes detected as having untrusted publishers (EN-969).
      • The FileServer plugin bundled with Continuity Engine v8.5 (or newer) properly replicates DFS namespaces. The DFS Management Client does not load the namespaces correctly each time.
      • Affects only MOVEit Central/Automation Server protected by Engine v8.5 (or newer): Local folders specified as source/destination in MOVEit Automation tasks require user-defined filters for protection. (EN-2879)
      • [Applies to 9.0 (or newer) with Passive Node Management Identity configured] vCenter Inventory passive VMs are not detected as Protected nodes if management name is configured and webservices are stopped on the active. Dashboard's protected servers count in Global Inventory is also impacted. (EN-4647)
        • conditions: Management name configured AND active server webservices stopped
        • result: deployment.location is not available hence the clustername mechanism is used. that makes only the Active server to be reported as protected node (if VM). Passives cannot be determined as vmid is not available
      • [CE HTML5 UI] When extending from pair to trio (add DR to HA pair) Secondary webservices require restart in order to serve (when made active) the updated deployment topology (trio instead of pair). This is known as the webservices are not restarted on S and S is the T's cloning source. (EN-4657)
        • impact: only if S is made active before webservices restart: new HTML UI Datacenter info is not accurate on Tertiary. Possible Protected node count is wrong if management identity is configured on any of the passives.
        • remediation: restart webservices on Secondary/Tertiary
      • [AMFx]: User defined sponsor is not persisted in prefs till Engine service is restarted. Thus webservices don't know about it (till restart is done) (EN-4341)
      • [CE HTML5 UI] Active compression type is shown as 'Standard' when there are no passive instances present in the replication chain. Workaround: This issue is purely cosmetic and it will correct itself once there are passive instances present in the replication chain. (EN-4855)
      • [CE HTML5 UI] Data traffic value in serverlist API is not always accurate. (EN-4859)
      • [CE HTML5 UI] Reconstruct pair: transform from pair HA to pair DR> HA cached configuration must be cleaned up before defining new DR config (EN-4915)
      • [CE HTML5 UI] Startup Engine service may experience delay when unreachable nodes are selected for starting the service on. (EN-4949)
      • [CE HTML5 UI] EULA accept is required all the time when Engine service is stopped (even if previously accepted). (EN-4958)

      Known Issues

      Engine Management Service & Engine

      • With SQL Plugin + SQL 2014 & In-Memory Tables may result in an OFFLINE DB state during "In Recovery" state (EN-329). 
      • Trying to add a 6.7 pair/trio in EMS UI protected servers list fails with an error. 
        Workaround: Restart Engine Web Services on the active server. (EN-1354)
      • Virtual Bytes rule triggered at every check (EN-859).
      • The Engine Management Service MSI repair mode fails to operate properly (EN-1389).
      • If the Engine is running, a new license is added to the list of licenses. If the Engine is stopped, it replaces the list of licenses (EN-902).
      • [WS2022 only]: Sometimes file are not deleted on passive when they're being deleted on active. This may cause orphan files presence on passive nodes. (EN-6346). Workarounds:
        • Run Orphan Files Check on each of the passive nodes (from AMC)
        • Restart replication (stop/start)
        • Restart Engine service
        • (since v21) create a periodic task using bundled utility ..\R2\bin\OrphanFilesCheck.exe 

      Install/Uninstall

      Administration

      • LogCollector - The process was terminated due to an unhandled exception (EN-2011).

      Applies To

      Neverfail Engine v23