App Control: Upgrade Status For Agent Reports 'Unprotected' After Applying OS Patch
book
Article ID: 290769
calendar_today
Updated On:
Products
Carbon Black App Control (formerly Cb Protection)
Issue/Introduction
After applying OS patches, Upgrade Status column in Assets > Computers screen reports machine(s) as 'Unprotected'.
Environment
App Control Agent: All Versions
Linux: All Supported Versions
Cause
Agents were not moved to a 'Disabled' Enforcement Policy before applying OS patch.
Resolution
Open the Console > Assets > Computers page
Select the check-box under the Action column for the effected machine(s)
Open the Action drop-down menu
Select a disabled Policy listed under 'Move Computers to policy ' listed, then OK
Perform steps for applying OS patch
Move agent(s) back to original enforcement policy
Additional Information
Moving agent back to original enforcement policy will cause the agent to re-initialize
The App Control Linux agent is very kernel specific, therefore when applying a patch to the Linux OS it is strongly suggested to move the agent to a disabled enforcement policy prior to applying the patch, this suggestion is discussed on Pg 6 of the Release Notes: https://community.carbonblack.com/t5/Documentation-Downloads/Cb-Protection-Linux-Agent-v7-2-4-Release-Notes/ta-p/43023