Advanced Threat Protection: Endpoint Protection Managers Webservers Authentication or Invalid Credentials errors after addition of MD5 Blacklist policy
search cancel

Advanced Threat Protection: Endpoint Protection Managers Webservers Authentication or Invalid Credentials errors after addition of MD5 Blacklist policy

book

Article ID: 164316

calendar_today

Updated On:

Products

Endpoint Protection Advanced Threat Protection Platform

Issue/Introduction

After adding an MD5 Blacklist Policy in Advanced Threat Protection (ATP) one or more Symantec Endpoint Protection Managers (SEPMs) display Authentication or Connection Errors as their Status.

Environment

Multiple 12.1.x SEPMs are configured in Settings > Global Settings> Endpoint Detection and Response > Symantec Endpoint Protection Manager (SEPM) Web Servers

Replication is enabled between all SEPMs

Resolution

The issue is resolved in SEP14.

If you cannot upgrade to SEP14 yet, a workaround is available: 

  1. Delete the MD5 Blacklist Policy in ATP
  2. Manually disable System Lockdown from all the SEP Client Groups and Domains in SEPM
  3. Manually delete all ATP Blacklisted Files File Fingerprint lists in SEPM

You may also contact Symantec Technical Support for assistance with steps 2 and 3 above if you have many Client Groups and SEPM Domains