Do you know what the new AexNSChttp.exe and AexNSChttps.exe files (under ".../Program Files/Altiris/Notification Server/nscap\bin\Win32\X86\NS Client Package") are for?
Differences between AeXNSC.exe, AeXNSChttp.exe, and AeXNSChttps.exe
This article provides technical details regarding the Symantec Management Agent (SMA) installation packages, including verification methods for file integrity and an explanation of why hashes for HTTP/S variants are unique per server.
ITMS 8.x
About the SMA installation package:
Note:
In some cases, in order for the AeXNSCHTTP.exe and AeXNSCHTTPS.exe files to be updated as well, re-save all the communication profiles in use (if you have more than just the default one) under Settings>Agents/Plug-ins>Symantec Management Agent>Symantec Agent Communication Profiles. Change something (uncheck/check box) and save. You should be able to see in Trace logging that these files were created.
Also, you can add a password to the AeXNSChttp.exe or AeXNSChttps.exe file so it can be protected if someone tries to run the executable manually (under Settings > Agents/Plug-ins>Symantec Management Agent > Settings > Agent Install > Default Settings > Security: Pull Packages and select the option "Password protect package".
Verify that AeXNSC.exe is signed by a valid Broadcom certificate.
It is impossible to provide a universal hash for AeXNSCHTTP.exe and AeXNSCHTTPS.exe because these files are dynamically generated and unique to every server.
Both the core and the HTTP/S variants are self-extracting archives. You can inspect the injected configuration files by running the following command:
After extraction, you will find the aexnsc.xml and certificate files that define that server's unique installation package.
⚠️ Note: AeXNSCHTTP/S.exe is not digitally signed unless the administrator has provided a specific signing certificate within the ITMS Console settings.