Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Macs not registering in cloud console after CLI installation

Hi all, just joined

I'm having trouble deploying Sophos Central at one of our customers. I have followed the instructions at 

https://community.sophos.com/kb/en-us/120570

What seems to happen is that the product installs successfully and is visible in the Applications folder. The command line installer exits 0 and states:

Sophos Installer[6804:164987] Starting Sophos Bootstrap Installer
Sophos Installer[6804:164987] Installation successful

The app launches and appears to work, but auto update is not configured and the device fails to show in the cloud console.

I have found the instructions at https://community.sophos.com/kb/en-us/120825 for re-registering a Mac client and have run them successfully. However, when the machine reboots it still fails to show up in the console. 

The strange thing is, a small subsection of Macs have installed Sophos via the exact same method and have worked fine. Unfortunately, it's the majority (hundreds) that are failing.

I have tried completely uninstalling via /Library/Application\ Support/Sophos/saas/Installer.app/Contents/MacOS/tools/InstallationDeployer --force_remove and then reinstalling again, but the device still fails to show in the console. After removing it using this method I can confirm that the output:

Upgrading the "saas" product.

is not shown in the install log, as detailed in the above KB. To me, this indicates that Sophos was correctly uninstalled previously by the --force_remove option.

Running /usr/local/bin/SophosUpdate reports "Sophos AutoUpdate is not configured!". This seems to be unique to machines that have failed. Machines that are showing in the console run SophosUpdate fine and the output is as you would expect.

I feel I'm close, but have hit a brick wall. Can anyone please offer any advice? This site has previously run the non Central version of Sophos, but it was uninstalled before attempting to install Sophos Central. I mention this in case it's relevant!

Thank you

Here are, what I think are, some relevant log entries:

2017-09-01 18:14:45.269 [SophosMcsAgentD 718:6384 status user domain] Detected computer description: johnson123.
2017-09-01 18:14:45.288 [SophosMcsAgentD 718:6384 status user domain] Detected domain name: BOBB
2017-09-01 18:14:45.303 [SophosMcsAgentD 718:6384 start] Registering endpoint
2017-09-01 18:14:45.304 [SophosMcsAgentD 718:6384 registration] Attempting to register endpoint...
2017-09-01 18:14:45.337 [SophosServiceManager 710:6312 start] [SMEServiceManager.m:902] Configure and if necessary start any kexts which are associated with the already running service: com.sophos.mcs
2017-09-01 18:14:45.338 [SophosServiceManager 710:6312 monitor] [SMEServiceManager.m:1103] The job com.sophos.mcs already being monitored
2017-09-01 18:14:45.338 [SophosServiceManager 710:6313 report] [SMEServiceManagerHealthInfo.m:96] Reported running state for service: com.sophos.mcs
2017-09-01 18:14:45.338 [SophosServiceManager 710:6312 serviceInfo] [SMEServiceManager.m:734] Evaluating service: com.sophos.cleand




This thread was automatically locked due to age.
  • I just tried a GUI install and seem to have the same or a similar issue. See attached pic, it's been like that for a couple of hours and still hasn't registered

     

    Much more info in the install log this time though:

    2017-09-01 19:19:04.047 [SophosMcsAgentD 13285:54309 registration] Attempting to register endpoint...
    2017-09-01 19:19:04.056 [SophosScanD 13298:55810 oas perf] file 'configuration.plist' for 'SophosMcsAgentD' 13285 allowed in 0.0085s (2)
    2017-09-01 19:19:04.057 [SophosMcsAgentD 13285:54309 mcs] Setting the preferred server: dzr-mcs-amzn-eu-west-1-9af7.upe.p.hmr.sophos.com/.../ep
    2017-09-01 19:19:04.066 [SophosMcsAgentD 13285:54309 mcs] Setting the polling interval: 20s
    2017-09-01 19:19:04.070 [SophosConfigD 13271:53905 settings configuration configd] Value changed for key: SMEMcsRegistrationUrl
    2017-09-01 19:19:04.076 [SophosServiceManager 13270:53886 config] [SMEServiceManager.m:1242] Notification received for global settings change: SMEMcsRegistrationUrl
    2017-09-01 19:19:04.076 [SophosServiceManager 13270:53886 config] [SMEServiceManager.m:1251] Will evaluate the system configuration in 2.000000 seconds
    2017-09-01 19:19:04.078 [SophosAntiVirus 13297:55057 scheduler] load scheduled scans
    2017-09-01 19:19:04.081 [SophosMcsAgentD 13285:54309 registration] Sending registration request
    2017-09-01 19:19:04.102 [SophosMcsAgentD 13285:54309 status registration] Computer status is not complete
    2017-09-01 19:19:04.106 [SophosMcsAgentD 13285:54309 status registration] Computer status - domain name : BOBB
    2017-09-01 19:19:04.106 [SophosMcsAgentD 13285:54309 status registration] Computer status - computer name : johnson123
    2017-09-01 19:19:04.106 [SophosMcsAgentD 13285:54309 status registration] Computer status - last logged on user :
    2017-09-01 19:19:04.106 [SophosMcsAgentD 13285:54309 status registration] Computer status - computer description : johnson123
    2017-09-01 19:19:04.106 [SophosMcsAgentD 13285:54309 status registration] Computer status - operating system : OSX
    2017-09-01 19:19:04.106 [SophosMcsAgentD 13285:54309 status registration] Computer status - IPv4 : 10.30.10.82
    2017-09-01 19:19:04.106 [SophosMcsAgentD 13285:54309 status registration] Computer status - FQDN : johnson123.bobb.uk
    2017-09-01 19:19:04.106 [SophosMcsAgentD 13285:54309 status registration] Computer status - processor : x86_64
    2017-09-01 19:19:04.102 [SophosConfigD 13271:53905 settings configuration configd] Value changed for key: SMEMcsDomainName
    2017-09-01 19:19:04.110 [Sophos Installer 1167:15103 install debug communications] [SMESophosBootstrapAppDelegate.m:1427]<main thread>[SMESophosBootstrapAppDelegate.handleGlobalSettingsDidChange:]. key: SMEMcsRegistrationStatus
    2017-09-01 19:19:04.108 [SophosConfigD 13271:53905 settings configuration configd] Value changed for key: SMEMcsRegistrationStatus
    2017-09-01 19:19:04.114 [SophosServiceManager 13270:53886 config] [SMEServiceManager.m:1242] Notification received for global settings change: SMEMcsDomainName
    2017-09-01 19:19:04.114 [SophosServiceManager 13270:53886 config] [SMEServiceManager.m:1242] Notification received for global settings change: SMEMcsRegistrationStatus
    2017-09-01 19:19:04.106 [SophosMcsAgentD 13285:54309 status registration] Computer status - OS major version : 10
    2017-09-01 19:19:04.116 [SophosMcsAgentD 13285:54309 status registration] Computer status - OS minor version : 12
    2017-09-01 19:19:04.116 [SophosMcsAgentD 13285:54309 status registration] Computer status - OS bugfix version : 6
    2017-09-01 19:19:04.116 [SophosMcsAgentD 13285:54309 registration] Registration request wasn't sent

    I didn't get any of the above info when I tried a CLI install.

    Any ideas?

    Giving up for the weekend...