Sensor Gateway 1.2.0 or older fails to start with error
search cancel

Sensor Gateway 1.2.0 or older fails to start with error

book

Article ID: 396483

calendar_today

Updated On:

Products

Carbon Black Cloud Workload

Issue/Introduction

1. New installation of Carbon Black Cloud (CBC) sensor with Carbon Black Sensor Gateway fails on Windows/Linux platform. The existing sensors installed work fine and communicate with the Sensor Gateway.

2. Sensor Gateway 1.2.0 and older fails to start with error

2024-11-06 22:09:48,246 - /opt/vmware/sgw/etc/sgw.py - ERROR - Failed to start the container with projects.registry.vmware.com/sensor_gateway/linux/sensor-gateway:1.2.0 image - error: None, status_code: 500
2024-11-06 22:09:48,246 - /opt/vmware/sgw/etc/sgw.py - ERROR - Failed to start Sensor Gateway container

3. Sensor Gateway may go to unhealthy status with the following in the /sgw-service.log

TLS error: 268435581:SSL Routines:openssl_internal:certificate_verify_failed

Environment

  • Carbon Black Sensor Gateway: 1.2.0 and older
  • Carbon Black Cloud Sensor: All Versions

Cause

  • Carbon Black Sensor Gateway 1.2.0 and older are no longer supported because because the SaaS public repository for downloading sensor gateway packages has changed from VMware SaaS public repository(packages.vmware.com) to Broadcom public repository (sensor-gateway.packages.broadcom.com) and sensor gateway packages required for Sensor Gateway 1.2.0 and older are no longer available in VMware SaaS public repository (packages.vmware.com).
  • To support this change, the Sensor Gateway 1.2.1 was released which used Broadcom SaaS public repository.
  • Check Carbon Black Sensor Gateway 1.2.3 Release Notes

Resolution

  • It is recommended to install the latest Carbon Black Sensor Gateway
  • Version 1.2.3 OVA can be downloaded from here.
  • The upgrade and install scripts for Docker can be found here

Additional Information

  • When deploying a updated replacement of the Sensor Gateway appliance, use the same Sensor Gateway Entry point FQDN. If not, existing sensors can stop communicating and will need to be manually updated with the new entry point FQDN.