Sensor Service Fails to Start with 517 error
search cancel

Sensor Service Fails to Start with 517 error

book

Article ID: 424983

calendar_today

Updated On:

Products

Carbon Black EDR

Issue/Introduction

Sensor services are failing to start. 

  • 517 error displayed during startup. 
    Error 577: "Windows cannot verify the digital signature for this file"
  • Sensors reported "Cb Service and CoreDriver Tamper Mismatch"

Environment

  • Carbon Black EDR Sensor: 7.4.2 and Lower
  • Microsoft Windows: All Supported Versions

Cause

Windows driver signature enforcement is blocking the sensor from starting due to expired "Microsoft Windows Early Launch Anti-malware Publisher" certificate on the cbedrelam.sys driver. 

Resolution

  • Install the 7.5.0 or higher EDR sensor with a valid signature. 

Additional Information

  • Disable Driver Signature Enforcement may be required within Microsoft Early Launch Anti-Malware in order to upgrade the sensor. 
  • With the Microsoft SDK Signtool, the expiration date can be validated.
    signtool.exe" verify /pa /v "C:\Windows\System32\drivers\cbedrelam.sys"