Upgraded SESCSP 6.5 or 7.0 Managers will not allow fresh installed agents to register.
search cancel

Upgraded SESCSP 6.5 or 7.0 Managers will not allow fresh installed agents to register.

book

Article ID: 164350

calendar_today

Updated On:

Products

Data Center Security Monitoring Edition Data Center Security Server Data Center Security Server Advanced

Issue/Introduction

After upgrading a Symantec Embedded Security: Critical System Protection manager from 1.0.1 to 6.5 or 7.0, fresh installed 6.5 or 7.0 agents will not register.

The same can also work in reverse, where the Manager is fresh installed 6.5 or 7.0, but the agents were upgraded from 1.0.1 or earlier.

Cause

The cipher types for the certificates changed from SECSP 1.0.1 to 6.5, from JKS to PKCS12.

When the manager is upgraded from 1.0.1 to 6.5 or newer, the cipher versions do not change.
However, when a fresh install of the manager is done, the cipher is installed directly as PKCS12.

Also, when agents are upgraded from 1.0.1 to 6.5 or newer, the cipher versions also do not change.

Resolution

Perform a full reinstall the manager and database without upgrading. The cipher will then be at PKCS12.

New certs can be generated and imported into the agents to allow for communication.