Unable to install Symantec Management Agent on Red Hat 8 Enterprise Workstation
search cancel

Unable to install Symantec Management Agent on Red Hat 8 Enterprise Workstation

book

Article ID: 246554

calendar_today

Updated On:

Products

IT Management Suite

Issue/Introduction

Unable to install the Symantec Management Agent (SMA) x64 bit on a Red Hat 8 Enterprise Workstation.  You tried the Symantec Management interface as well as manually installing it and keep getting the following error when trying to push:

// Failed to connect (SSH) - Exception from HRESULT: 0x8000EE06
// Computer 192.168.0.86(192.168.0.86) might be switched off.
// You may also need to check the credentials supplied, the firewall rules on the computer and its SSH or telnet configuration.

You confirmed that SSH works (testing with Putty) and that you can login to the Red Hat 8 Enterprise Workstation using SSH and the credentials used are valid.  You are using the root credentials.  

The usual ports are open (based on our KB article Ports and Protocols for Symantec IT Management Suite (ITMS) 8.x:

TCP ports open: 22, 80, 53, 443,1024, 52028, 1433, 389, 137, 3476

UDP ports open: 22, 53, 137, 138, 389, 445, 1024, 1433, 138, 3476, 1434, 52028, 52029, 65536

This is the error you get when trying to install the Symantec Management Agent (taking the text directly from the Linux machine you are attempting to install this to):

[root@sc1-lab-example Downloads]# ./aex-bootstrap-linux
Verifying archive integrity... All good.
Uncompressing Symantec Management Agent Installer 8.6.3126
......
INFO: Trying to extract embedded install XML from bootstrap file.
INFO: Connection established with 'https://SCUpdate.example.com:443/'.
INFO: Getting Package: https://mainserver.example.com:443/Altiris/NS/NSCap/Bin/Unix/Agent/Linux/x64 into temp dir: /opt/altiris/notification/nsagent/.tmp_inst
INFO: Successfully verified package signatures.
INFO: Success getting Package.
INFO: Installing package...

======================================================================================
Fri Jul 15 10:26:29 EDT 2022
Performing installation of Symantec Management Agent for UNIX, Linux and Mac 8.6.3126
======================================================================================
Installing Symantec Management Agent for UNIX, Linux and Mac 8.6 on the system.
 DEBUG: agent-upgrade:780, Native package: aex-nsclt.rpm
 DEBUG: agent-upgrade:486, install_cmd=while [ -f /tmp/aex-pkgmanager.lock ]; do pid=`cat /tmp/aex-pkgmanager.lock`; kill -0 $pid >/dev/null 2>&1; if [ $? -ne 0 ]; then break; fi; sleep 2; done; echo $$ > /tmp/aex-pkgmanager.lock; a=0; while [ $a -ne 10 ]; do a=`expr $a + 1`; rpm -U --ignorearch --force --nodeps --badreloc --relocate /opt/altiris/notification/nsagent=/opt/altiris/notification/nsagent aex-nsclt.rpm; install_res="$?"; if [ $? -eq 0 ]; then break; fi; sleep 20; done; rm -f /tmp/aex-pkgmanager.lock >/dev/null 2>&1; rmdir /tmp/nsclt >/dev/null 2>&1
package aex-nsclt-8.6-3126.x86_64 does not verify: no digest
ERROR: At least one input parameter for event sending is invalid: Action: 'Remote Install Finished', Client ID: ''.
ERROR: Failed to install package. Agent install failed.
Must provide either install XML in current working directory,
or run correct bootstrap file with embedded install XML,
or specify NS/URL parameter.

Environment

ITMS 8.x

Cause

Known issue. If FIPS is enabled then the installation process has been blocked.

Resolution

This issue has been fixed in the ITMS 8.7 release.

In order to validate if FIPS is enabled, please run the following command:

sysctl crypto.fips_enabled

If FIPS is turned on, the output should looks like this:

[root@sc1-lab-machine ~]# sysctl crypto.fips_enabled

crypto.fips_enabled = 1

As a workaround do the following:

  1. Disable FIPS

    To turn off fips:
    As root run: #fips-mode-setup --disable

    To verify fips is off:
    As root run: #fips-mode-setup --check

  2. Install the Symantec Management Agent
  3. Enable FIPS