After regenerating agent packages (commonly following a CA certificate renewal), newly installed Windows agents initialize with a Config List version (CLVer) of 0. This prevents the agent from using the "baked-in" configuration, forcing a full incremental synchronization from the server that can take 24–48 hours in case of CL versions above 1 million.
Symptoms:
CLVer = 0.InitCache: ImportErrors[1] or Cache::ValidateConfigListFile Error: Decrypting the file seccon2.bt9 failed with error: [Bad Data].This is caused by a known defect (CRE-23916) where the agent fails to successfully import the embedded Config List file during the initial installation phase.
Fixed in App Control Server version 8.13 and Agent version 8.12.
For environments unable to upgrade their agents to 8.12 immediately, follow these steps:
https://####/shepherd_config.php on the App Control Server.UseEncryptedConfigListInWindowsPackagestrueUsers are recommended to subscribe to this article for further updates regarding this defect.