This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

"SophosSAU <hostname>" account locks out.

I am having problems with downloading the latest Updates from the SophosUpdate share.

If I click on the Blue Sophos Shield in the system tray and select "Update Now" I get a message saying "Could not contact Server".

In Active Directory Users and Computers the "SophosSAU" account which is used for downloading of Sophos updates becomes locked out each time I try to do an "Update Now" and the Sophos Blue Shield in the system tray has a red cross in it indicating that updating has failed.

In the "C:\Program Files\Sophos\AutoUpdate\logs\alc.log" there are references to
"There was a problem while establishing a connection to the server. Details : LogonUser ("SophosSAU-hostname",".",...) failed A Windows API call returned error 1326".

Now a confession : everything was working fine, but then I had to change the password hashing algorithm I use on this Server.

My guess is that the "SophosSAU" account or its password have been affected by this change, but I'm not sure what to do next. I tried re-installing by doing a "Protect Computers" from the "Enterprise Console" but that made no difference.

Any advice gratefully received.

Peter

:16469


This thread was automatically locked due to age.
Parents
  • Thanks for the reply Christian,

    it's still not working I'm afraid.

    I changed the password of "SophosSAU<servername>0" as suggested in the link but I was still getting the same problem after I re-protected the server.

    Then I tried deleting the AutoUpdate\Service key.

    This time the registry has set the Download User to be "SophosSAU<servername>1" instead of "SophosSAU<servername>0".

    But that account does not exist in the Active Directory so I guess that can't be right.

    The Download password in the registry's "AutoUpdate\Service" key is displayed as "ELIjwF........" which looks like it's been encrypted. The password I set up in Active Directory for "SophosSAU<servername>0" was just a simple 5 character plain text password.

    :16501
Reply
  • Thanks for the reply Christian,

    it's still not working I'm afraid.

    I changed the password of "SophosSAU<servername>0" as suggested in the link but I was still getting the same problem after I re-protected the server.

    Then I tried deleting the AutoUpdate\Service key.

    This time the registry has set the Download User to be "SophosSAU<servername>1" instead of "SophosSAU<servername>0".

    But that account does not exist in the Active Directory so I guess that can't be right.

    The Download password in the registry's "AutoUpdate\Service" key is displayed as "ELIjwF........" which looks like it's been encrypted. The password I set up in Active Directory for "SophosSAU<servername>0" was just a simple 5 character plain text password.

    :16501
Children
No Data