How the Web Address and the Databases Are Connected
On ABM Service Server, every company you add is its own Windows service listening on its own port, connected to one company database of ABM (Advanced Business Manager) and to ABM's control database. The port is what makes the web address: people open http:// followed by the server's name, a colon and the company's port, and they sign in with their ABM name and password.
What is a company's web address on ABM Service Server?
A company's web address is http://, the server's name, a colon and the company's port, for example http:// followed by your server's name and :5080 for the first company added. ABM Service Server Manager shows each company's port on its line as port followed by the number.
- Give people the server's name as other computers know it: the name on your network, or the name your own address book or domain gives it. The company answers on every network address the server has.
- The port is fixed per company, from 5080 upwards unless you chose another. It changes only if you change it in the company's Settings....
- Windows Firewall is opened for you: adding a company creates an incoming rule for its port, for every network profile, named like the company's Windows service. Removing the company deletes the rule. A firewall other than Windows Firewall, or one between offices, has to be opened by you. Going out, the server needs HTTPS to
updates.abm-portal.com, where each company gets the ABM web application and its updates. - The address serves plain http. ABM Service Server does not install a certificate or answer https by itself; https has to come from something you put in front of the server, such as a reverse proxy.
Opening the address from another computer should show the ABM Service sign-in page, listing the ABM users. If it does not open at all, check the company shows Running in ABM Service Server Manager, and that every firewall between the two computers allows the port.
Can a company's web address have no port number, such as port 80?
Yes, as long as nothing else on the server uses port 80. A web address with no port number goes to port 80, and the Port box in Add a company and in Settings... in ABM Service Server Manager takes any number from 1 to 65535, so a company given port 80 is reached at http:// followed by just the server's name.
- The manager checks a port only against the other companies on the server, including stopped ones and those of the development channel. It never checks whether another program uses the port. Port 80 is the one Internet Information Services (IIS) and most other web servers use, so on a server that runs one it is probably taken.
- When another program has the port, the company cannot start its web server: its line in the manager keeps going back to Starting or Restarting, and the child log file shown by Open logs says the port is already in use. Choose another port in Settings..., or free port 80 first.
- Only one company can have port 80 on a server; the others keep a port number in their addresses.
The Windows Firewall rule the manager makes follows the company's port, so nothing else needs opening on the server itself.
Can I put an SSL certificate on ABM Service Server so the website runs on https?
Not on ABM Service Server itself: there is no certificate or https setting in ABM Service Server Manager, and each company answers plain http on its own port, on every network address the server has. To give people an https address, or to reach ABM Service from outside the office, put something in front of the company's address that answers https with your certificate and passes the requests on to http:// the server's name, a colon and the company's port, such as a reverse proxy, a gateway or a tunnel service. That is set up separately from ABM Service Server, and your software supplier can advise on it.
- Nothing changes in the manager when you do this: the company keeps its port and address on the server, and the manager starts, checks and updates it exactly as before.
- The sign-in cookie is marked secure only when a request reaches ABM Service Server over https itself. Behind a proxy or tunnel that passes requests on over plain http, the browser's connection is still encrypted as far as the proxy, but the cookie is not marked secure, so keep the plain-http leg between the proxy and the server on the server itself or on your own network.
Can a company answer on only one of the server's network addresses?
Not from ABM Service Server Manager: a company added in the window answers on every network address the server has, and the Windows Firewall rule the manager makes allows its port on every network profile. To limit which computers can reach a company, use your network's firewall. The manager deletes its own Windows Firewall rule and makes it again each time the company's settings are saved, so a change made to that rule does not last.
The one exception is a company that only a reverse proxy on the same server should reach. The command-line add accepts /bind:127.0.0.1, which makes the company answer only on the server itself, so the network reaches it only through the proxy:
ABM.Service.Server.Manager.exe add /instance:<name> /connection:"<company database connection string>" /control:"<ABMControl connection string>" /bind:127.0.0.1 /quiet
- It is chosen when the company is added. Settings... and the
setcommand keep it and cannot change it. To change it later without removing the company, change the address afterBindAddressin that company's settings file,instance.json, to127.0.0.1for the server alone or0.0.0.0for every network address, the same way as the log retention in How to Read the ABM Service Server Logs: keep a copy of the file first, and restart the company's Windows service straight away, because the company reads the file only when its service starts. - Use no address other than
127.0.0.1. The company checks its own web server at127.0.0.1whatever it is bound to, so a company bound to one of the server's network addresses fails that check every time, shows Unhealthy, and has its web server restarted every few minutes.
Which databases does each company on ABM Service Server use?
Each company uses two databases: its own ABM company database, where the calls, customers and everything else people work on are kept, and ABM's control database, usually called ABMControl, which lists the ABM users, their passwords and which companies each of them may open.
- The company database is the one named in the first group of Add a company. One company on the server is always one company database.
- The control database is read only to sign ABM users in. Customer portal sign-ins are kept in the company database and do not use it. ABM Service Server works out which company in ABM the company database belongs to by itself, from the company database, so nothing about it is typed in the manager.
- The connections are SQL Server logins, stored on the server encrypted for that machine. Copying the files to another machine does not carry working passwords with them.
- The connection is not forced to be encrypted, because older SQL Server versions at many sites cannot do it; it is encrypted when the SQL Server insists on it.
In a SQL Server trace or activity list, ABM Service's connections show the application name Unified ABM Service, so a database administrator can tell them from ABM's own programs.
Where does ABM Service Server keep the SQL passwords, and are they in the logs?
Each company's two SQL Server connections, logins and passwords included, are kept in two files in that company's own folder, C:\ProgramData\ABM Service\Server\service\ followed by the company's name: connection.dat for the company database and control.dat for ABM's control database. Each file holds the whole connection, encrypted with Windows' own data protection for that machine (DPAPI at machine level). ABM Service Server writes them nowhere else.
What that protects, and what it does not, for an auditor:
- A copy taken off the server cannot be read. A backup, a copied ProgramData folder, a file sent to support or a disk taken out of a dead server does not carry a usable password, which is also why a company cannot be moved by copying its folder.
- It is not a secret from the server itself. Any administrator, and any program running on that server that can read the file, can decrypt it. The server data folder can be read only by administrators, the system and the companies' own Windows services; Windows Explorer cannot open it even for an administrator, but an elevated command prompt can.
- The launcher log never shows a password or a login. When the company's Windows service reads a connection it writes one line naming only the SQL Server and the database.
- The child log can show a login name, never a password. It is the web server's own output, and its errors are written word for word, so when SQL Server refuses a login its message names the login it tried.
Changing a password is done with Settings... in ABM Service Server Manager, which writes the file again.
Who can sign in to ABM Service over the web?
Anybody who is an ABM user, has a password in ABM, and has been given this company in ABM can sign in, with the same name and password they use in ABM. ABM Service Server reads all three from ABM's control database each time someone signs in, so changes made in ABM's own user list apply at that person's next sign-in. Neither the ABM Service Server setup nor ABM Service Server Manager adds ABM users or sets their passwords; that is always done in ABM. Somebody who is already signed in stays signed in until they sign out, the company restarts or updates, or they leave it unused for thirty days; to cut off everyone at once, for example after removing someone's access in ABM, press Restart under the company in ABM Service Server Manager, which signs everybody out.
The sign-in page lists every ABM user except those whose name is marked as removed in ABM. When a person is refused, the ABM Service sign-in page says why: That password was not accepted. Check it and try again. for a wrong password, This user has no password yet. for a blank password in ABM, and ABM has not given this user this company. when the person may not open this company. When the control database or the company database cannot be reached, the page names that database followed by did not answer. What to check for each of these messages is in What to Check When ABM Service Server Goes Wrong.
The system administrator (ABM user 1) can also require an authenticator app for every web sign-in, from the Administration menu in ABM Service, and can give the service company's own customers access to the Customer portal, which is on the same web address.
Can I run several companies on one ABM Service Server?
Yes. Add each company separately in ABM Service Server Manager: each gets its own Windows service, its own port and so its own web address, and each is started, stopped, updated and removed on its own. There is no single address that serves them all with a choice of company: each company's sign-in page lets in only the people ABM has given that company, so give each group of people the address of their company.
- They share the versions of the web application the server has downloaded, so each version is downloaded once, but each company updates on its own: after Update now under one company, that company can be on a newer version than the others. Apply at... sets the nightly apply time for every company answering the manager at that moment; a company added later keeps midnight until you set it again.
- A person signed in to one company is not signed in to the others, even in the same browser: each company keeps its own sign-in.
- A problem in one company does not stop the others: removing, stopping or restarting one leaves the rest serving.
- Updating the service software stops them all together for about ten seconds, because they share it.
Two companies cannot share a port. The manager refuses a port already given to another company, including one that is stopped, and including one from the development channel if that is installed on the same server.
How many users does the server manager say are connected?
The number on a company's line in ABM Service Server Manager counts the different network addresses that used that company in the last five minutes, not sign-ins. It is a guide to how busy the company is, not a licence count. The manager does not show who those people are, and has no button that signs out one person: Restart under the company signs out everybody signed in to it.
Everyone who reaches the server through one address counts as one: the people on one Remote Desktop server, the people behind one router, and everyone coming through a reverse proxy in front of the company. One person using both a laptop and a phone counts as two. Update now shows the same number before it restarts a company, so you can see whether anybody would be interrupted.
How do I point our network monitoring at a company on ABM Service Server?
Point your monitoring tool at two addresses on each company's port, both answered without anyone signing in: the company's web address followed by /health, which says whether its web server is up, and followed by /health/db, which says whether it can reach its company database. For a company on port 5080 of a server named abmserver, those are http://abmserver:5080/health and http://abmserver:5080/health/db. ABM Service Server sends no alerts of its own, so this is the way to be told when a company goes down.
/healthgives a normal answer (status 200) containing the word ok whenever the web server is running, with the number of people using the company and a list of any problems a person has to fix, such as a company with no ABM control database connection, where nobody can sign in, or a change ABM Service could not make to the company database. A problem does not change the status, so have the monitor read the text too if you want those. No answer at all means the company is stopped, restarting or unreachable on the network./health/dbanswers normally, with ok, when the company can run a simple query on its SQL Server, and with status 503 (Service Unavailable) and SQL Server's own reason when it cannot. It is the same check behind the red database: not answering since line in ABM Service Server Manager.
Watch both. Checking only that the sign-in page opens, or that the company's Windows service is running, misses a company whose company database has stopped answering, and the Windows service keeps running while it restarts a web server that has stopped.