This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Enterprise console4/client9 - all PCs greyed out and won't report back

I recently upgraded my servers to Server 2008 r2 and was surprised to find that Sophos wouldn't run on it, so I ended up having to setup a windows 2003 virtual drive specifically for Sophos. However, this was 6 weeks agao and Sophos has not worked since. I did a backup and restore according to the instruction sheet, but although my main site was OK, communication to our second site was lost. All the pcs at the remote site showed up but showed 'awaiting  policy transfer' on every single PC. After four weeks of calls to Sophos, they couldn't resolve it, so I installed a PC at the remote site and loaded a second copy of Enterprise console there which then worked, although I can no longer see the whole domain from the main site.

Some PCs were still not reporting back at the main site either, so following a tech sheet I removed the console from the main site, cleared all the files and registry settings out and did a clean reinstall. I then imported all the pcs again and did a reprotect. Result? All pcs remain greyed out and report "fffffd -This computer is not yet managed. The computer is protected but has not yet reported back". I've phoned Sophos almost every day for 6 weeks now and they still can't come up with a solution. I'm getting very frustrated with them -has anyone else ahd this problem?  (It occurs on both XP and Windows 7 PCs).

:2937


This thread was automatically locked due to age.
Parents
  • HI,

    As a quick test the following should align between server and client:

    Server:

    HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Certification Manager\CertAuthStore\RouterKey

    Client:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Messaging System\CertificationIdentityKeys\CertificationIdentityKey

    Server:

    HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Certification Manager\CertAuthStore\ManagedAppKey

    Client:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Remote Management System\CertificationIdentityKeys\ManagedApplication

    Server:

    HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Certification Manager\CertAuthStore\DelegatedManagerKey

    Client:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Remote Management System\ManagementAgent\Private\CertificationIdentityKey

    Server:

    HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Certification Manager\CertAuthStore\cac

    Client:

    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sophos\Messaging System\cac

    These strings are transferred to the client in the files: Mrinit.conf and cac.pem by setup.exe and added to the clients registry by the executable: "C:\Program Files [(x86)]\Sophos\Remote Management System\ClientMRInit.exe".  This exe is run by the RMS MSI at install.  It expects to find the files cac.pem and mrinit.conf in the same directory. 

    I put some more information about RMS on this thread also:

    if anyone fancies a read.

    Regards,

    Jak

    :8563
Reply
  • HI,

    As a quick test the following should align between server and client:

    Server:

    HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Certification Manager\CertAuthStore\RouterKey

    Client:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Messaging System\CertificationIdentityKeys\CertificationIdentityKey

    Server:

    HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Certification Manager\CertAuthStore\ManagedAppKey

    Client:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Remote Management System\CertificationIdentityKeys\ManagedApplication

    Server:

    HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Certification Manager\CertAuthStore\DelegatedManagerKey

    Client:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Remote Management System\ManagementAgent\Private\CertificationIdentityKey

    Server:

    HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Certification Manager\CertAuthStore\cac

    Client:

    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sophos\Messaging System\cac

    These strings are transferred to the client in the files: Mrinit.conf and cac.pem by setup.exe and added to the clients registry by the executable: "C:\Program Files [(x86)]\Sophos\Remote Management System\ClientMRInit.exe".  This exe is run by the RMS MSI at install.  It expects to find the files cac.pem and mrinit.conf in the same directory. 

    I put some more information about RMS on this thread also:

    if anyone fancies a read.

    Regards,

    Jak

    :8563
Children
No Data