Agent Installers Not Generating and Tamper Protection Events For makecab.exe
search cancel

Agent Installers Not Generating and Tamper Protection Events For makecab.exe

book

Article ID: 432467

calendar_today

Updated On:

Products

Carbon Black App Control

Issue/Introduction

  • App Control Agent is installed on the application server hosting the Console.
  • The Rapid Config Server Tamper Protection is enabled.
  • Tamper Protection Events in Reports > Events for the makecab.exe process similar to
    Carbon Black App Control Agent blocked an attempt to create 'c:\program files (x86)\bit9\parity server\cab07877.tmp' by 'DOMAIN\USER' because of Tamper Protection.

Environment

  • App Control Server: 8.12.0+
  • App Control Agent: All Supported Versions
  • Rules Installer 1.30 (or lower)

Cause

The Agent's Server Tamper Protection is triggering and preventing files from being created in the Server directory due to a change in Server 8.12.0 with how Package Generation is handled.

Resolution

This issue is prevented with Rules Installer 1.32.

  1. Upgrading the Rules Installer will prevent Tamper Protection from triggering in this scenario the issue.
  2. The Shepherd Config's for the relevant Policy Installers may need to be turned back on
    1. Navigate to https://<ServerAddress>/shepherd_config.php
    2. Change the Property to true for any relevant Installers
      GenerateMacInstaller
      GenerateRedhatInstaller
      GenerateSha1Installer
      GenerateWindowsHostGroupZipPackage
      GenerateWindowsInstaller
    3. Verify Reports > Events shows successful package generation Events and Policy Installers are once again generating.
      • Type: Server Management
      • Subtype: Agent install package generation succeeded

Additional Information