Signature Update Failure with HTTP Proxy on 4.1 Sensor
book
Article ID: 434047
calendar_today
Updated On:
Products
Carbon Black Cloud Endpoint Standard
Issue/Introduction
Customers running Carbon Black Cloud Sensor 4.1 in environments that use an HTTP proxy may experience failures when downloading antivirus signature updates.
All other sensor-to-cloud communications continue to function normally.
Environment
Carbon Black Cloud Windows Sensor: 4.1.0
Cause
The root cause has been identified in the Symantec LiveUpdate (LUX) component, used by the Stargate AV module.
The LUX library incorrectly prepends the prefix https:// to the configured proxy host even when the protocol is explicitly set to HTTP.
This results in connection failures when attempting to reach the proxy.
Resolution
Resolution:
Upgrade to version 4.2 where this issue has been resolved (CRE-23319)
Workaround:
If unable to upgrade, a temporary workaround is available by explicitly defining the proxy with the http:// prefix: