This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Linux client not able to update - Please help

Hello,

We have a single linux machine that we are running into issues with. We do the install by mounting a cifs share on the linux machine and running a script. The install seems to be successful and we can see the machine check-in initially. I assume it received its initial policies as it is configured to run its scheduled scans. The linux client seems to communicate on a regular basis with the management console based on time stamps. In the Enterprise console, "Up to Date" column shows not since [date of initial installation]. The computer details gives me the error code 0000006b "Download of savupdate failed from server sdds: SOPHOS and also code 0000006a "Installation caught error savupdate".

On the client machine, i ran /opt/sophos-av/bin/savupdate -v5 --debug and received the output below:

Update to include '*' priority 10
Update to exclude 'sav-*' priority 20
Update to exclude 'sdf.xml' priority 20
Update to include 'sav-linux/licence*' priority 30
Update to include 'sav-linux/manifest.dat' priority 30
Update to include 'sav-linux/manifest.spec' priority 30
Update to include 'sav-linux/cidsync.upd' priority 30
Update to include 'sav-linux/common/*' priority 30
Update to include 'sav-linux/x86/*' priority 30
Update to include 'uncdownload/*' priority 20
Update to exclude 'talpa/*' priority 20
Update to include 'talpa/talpa-srcpack.tar.gz' priority 30
Update to include 'talpa/manifest.dat' priority 30
Update to include 'talpa/cidsync.upd' priority 30
Update to include 'talpa/copying' priority 30
Update to include 'talpa/talpa-redhat/combined.tgz' priority 30
Update to include 'talpa/talpa-redhat/talpa-binpack-redhat-x86_64-2.6.32-431.17.1.el6.x86_64-1smpfriapr11172700edt2014.tar.gz' priority 30
Update to include 'talpa/talpa-redhat/talpa-binpack-redhat-x86_64-2.6.32-431.17.1.el6.x86_64.tar.gz' priority 30
Update to exclude 'sav-linux/x86/32/*' priority 40
Update to exclude 'uncdownload/32/*' priority 40
Updating from \\[server_name]\SophosUpdate\CIDs\S000\savlinux
Reading \\[server_name]\SophosUpdate\CIDs\S000\savlinux/savlinux/cidsync.upd
Reading \\[server_name]\SophosUpdate\CIDs\S000\savlinux/cidsync.upd
Reading \\[server_name]\SophosUpdate\CIDs\S000\savlinux/master.upd
Can't locate index of \\[server_name]\SophosUpdate\CIDs\S000\savlinux
Failed to replicate from \\[server_name]\SophosUpdate\CIDs\S000\savlinux
Exception recorded in /opt/sophos-av/tmp/savupdateException.log
DownloadConfigurationException for Invalid update source
SOPHOS source is either SOPHOS, or the warehouse update source address.
read_remote_metadata failed: result=4
error_details: Out of sources
log_entry: [E26245] Cannot locate server for http://dci.sophosupd.com/update/e/0a/e0abe8f45bbec20b556a063ff81ef388.dat
log_entry: [I20317] No proxy was used.
log_entry: [E26245] Cannot locate server for http://dci.sophosupd.net/update/e/0a/e0abe8f45bbec20b556a063ff81ef388.dat
log_entry: [I20317] No proxy was used.
log_entry: [E75373] Ran out of sophos aliases for this update source
log_entry: [E35369] Out of update sources
Failed to replicate from sdds:SOPHOS
Exception recorded in /opt/sophos-av/tmp/savupdateException.log
SDDSException for read_remote_metadata failed
Failed to replicate from all update sources

Any ideas on the issue? I have confirmed that the share is accessible by that machine. The share is the same share we use to perform the initial install.

:51334


This thread was automatically locked due to age.
  • Could you point me to the file where the correction needs to be made? Also, is it possibly to make the change on a test machine before making the change on the file in the update location? I would like to be able to test before making the update available to all machines.

    Thank you,

    :51482
  • Hello QC,

    Just want to make sure that I fully understand. The console currently shows me that the policy currently differs from policy. When I open up the computer details I do see it telling me when the last scheduled scan completed time is, so it seems that there has to be some sort of communication occurring between the server and client. So are you saying that this can be expected?

    console.PNG

    Thank you for everyone's help. I am very new to Sophos and recently started in a new position supporting an existing implementation of Sophos.

    :51490
  • Hello aphanman,

    in the console, lower left pane Policies, view/edit the applicable Updating policy. This opens the Primary Server tab where you replace the NetBIOS name with the FQDN.

    Communication is independent of updating and the Status View shown in your screenshot provides only an aggregate policy compliance status, i.e. it might be just one or several policies which differ. The Error is expected, as it has troubles updating.

    Maybe you should watch this 11 minute video on YouTube, might help you more than me trying to write a crash course :smileyvery-happy:. Feel free to ask if something is not clear or you need more details.

    Christian

    :51492
  • Thanks QC. I did find the video a little helpful. I will be making the change in the updating policy as you mentioned. Currently, I implemented a working around by adding an entry into the /etc/hosts file so it is able to pull updates again. However, I can't seem to figure out how to get the machine to be come compliant with the policies. Do you know how I can find out which policies are not being applied properly? Also, the status of "On-access" is reporting as Inactive, however I had the admin run  the command "service sav-protect status" and got a response saying that the daemon is active. My understanding is that this means on-access is currently active, is that correct?

    Since the change was made to hosts file I have no seen an error in the Sophos AutoUpdate Status for the specific machine.

    --Edit--

    I just noticed the console is reporting different statuses on two different tabs. One tab indicates that the policy differs and another tab indicates that the policies are the same. I've included screenshots. Could this be a bug in Enterprise Console 5.2.0?

    status.PNG

    update_details.PNG

    :51544
  • Hello aphanman,

    the compliance in the Status tab is an aggregated value. The endpoint is compliant with the updating policy but as on-access is Inactive guess it does not comply with the A-V policy - check this tab. Right-click and select Comply with ... to have SEC send the policies.

    Christian
    :51556
  • I tried running the "comply with", but it doesn't seem to help. I had the admin run service sav-protect status to see if it is running and the result was that it currently is running. But the console does not reflect that.

    Thanks,

    :51560
  • Hello aphanman,

    can't say right now (just watching ARG vs. SUI) why it doesn't comply (or correctly report its status). Using the EICAR testfile it's quite simple to check whether on-access is indeed active and whether the detection is reported to the console or not.

    Christian
    :51566