Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

App Control: Approvals Out of Date on Agents & High CPU on App Control Server

App Control: Approvals Out of Date on Agents & High CPU on App Control Server

Environment

  • App Control Server: 8.7.X and Higher
  • App Control Agent: 8.7.X and Higher

Symptoms

  • High CPU on App Control Server Services
  • High CPU on PHP-cgi.exe process
  • Approval out of date in most of the computers
  • IIS logs reporting thousands of events similar to: 
    2022-01-01 00:00:00 00.00.00.00 GET /hostpkg/pkg.php pkg=TrustedCertList.pem 443 - 00.00.00.00 Bit9+Parity - 000 0 0 00

Cause

TrustedCertList.pem file is corrupted

Resolution

  1. Verify the Resource Download Location (RDL) specified is correct.
  2. Log in to the application server as the Carbon Black Service Account.
  3. If an Agent is installed, temporarily disable Tamper Protection.
  4. Stop the App Control Server service.
  5. Delete the file:
    C:\Program Files (x86)\Bit9\Parity Server\hostpkg\TrustedCertList.pem
    
  6. Start the App Control Server service, and verify the file is rebuilt.
  7. If an alternate Resource Download Location is being used, verify the new file is synced to the alternate RDL correctly.

Related Content


Labels (1)
Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎09-20-2022
Views:
1097
Contributors