App Control: Upgrade Status For Agent Reports 'Unprotected' After Applying OS Patch
search cancel

App Control: Upgrade Status For Agent Reports 'Unprotected' After Applying OS Patch

book

Article ID: 290769

calendar_today

Updated On:

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

After applying OS patches, Upgrade Status column in Assets > Computers screen reports machine(s) as 'Unprotected'.

Environment

  • App Control Agent: All Versions
  • Linux: All Supported Versions

Cause

Agents were not moved to a 'Disabled' Enforcement Policy before applying OS patch.

Resolution

  1. Open the Console > Assets > Computers page
  2. Select the check-box under the Action column for the effected machine(s) 
  3. Open the Action drop-down menu
  4. Select a disabled Policy listed under 'Move Computers to policy ' listed, then OK
  5. Perform steps for applying OS patch
  6. Move agent(s) back to original enforcement policy

Additional Information

  • Moving agent back to original enforcement policy will cause the agent to re-initialize
  • The App Control Linux agent is very kernel specific, therefore when applying a patch to the Linux OS it is strongly suggested to move the agent to a disabled enforcement policy prior to applying the patch, this suggestion is discussed on Pg 6 of the Release Notes: https://community.carbonblack.com/t5/Documentation-Downloads/Cb-Protection-Linux-Agent-v7-2-4-Release-Notes/ta-p/43023