This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

endpoints points to the old enterprise server

I migrated Sophos Enterprise Console 4.5.1 to a Windows 2003SP2 32-bit physical server to a 2008 R2 virtual server hosted on Hyper-V R2.

All endpoints appeared on the new server without any errors at the migration, but about a week later some clients started pointing at the old server again.

I uninstalled Sophos AntiVirus, AutoUpdate, Remote Management System and reprotected again. It didn't work.

The following is what I have done so far.

1. Edited all mrinit.conf in the clients manually so that it will point at the new server

2. Copied and pasted cac.pem from another endpoint that points at the new server

3. Copied a value from another endpoint and modified the following keys in endpoints

    HKLM\SOFTWARE\Sophos\Messaging System\cac key

    HKLM\SOFTWARE\Sophos\Messaging System\CertificationIdentiKeys\CertificationIdentityKey key

    HKLM\SOFTWARE\Sophos\Messaging System\Router\ParentAddress key

    HKLM\SOFTWARE\Sophos\Remote Management system\CertificationIdentityKey\ManagedApplication key

    HKLM\SOFTWARE\Sophos\Remote Management system\Management System\CertificationIdentityKey key  

4. Restarted Sophos Message Router Service

After the above procedures, I checked Router log. I saw several entries don’’’’t sound right.

ACE+D::::open failed for TAO_ImR_Client: Error

Unable to find service: ImR_Client_Adapter

type=Certification.CertRequest, no originator cert

It sounds the machines don't have a correct cert???

Is there anybody tell me how I  can fix this???

Thanks!

:11441


This thread was automatically locked due to age.
Parents
  • Hi,

    You could try my HTA:

    /search?q= 8939

    Essentially, you need to find the correct cac.pem and mrinit.conf from the CID of the new server.  Run the tool above and select both of those fles where requested.  This will create you a vbs file you can run on the machines, this will re-initialise them to point to the new server.

    Please try it on a couple of endpoints first.


    I hope this help or at least gives you an option.

    Jak

    :11461
Reply
  • Hi,

    You could try my HTA:

    /search?q= 8939

    Essentially, you need to find the correct cac.pem and mrinit.conf from the CID of the new server.  Run the tool above and select both of those fles where requested.  This will create you a vbs file you can run on the machines, this will re-initialise them to point to the new server.

    Please try it on a couple of endpoints first.


    I hope this help or at least gives you an option.

    Jak

    :11461
Children
No Data