IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR: Windows Sensors are Not Communicating to the Server After Installation or Upgrade (Certificate Issue).

EDR: Windows Sensors are Not Communicating to the Server After Installation or Upgrade (Certificate Issue).

Environment

  • EDR Windows Sensor: All Supported Versions
  • EDR Server: All versions
  • Windows OS: All Supported Versions

Symptoms

  • Sensor diagnostics file "sensorcomms.log" shows these errors:
Time | URL | HRESULT | Code | DurationMs | TxBytes | RxBytes | Throttle KB/s | Upload Speed KB/s
-------------------- + ---------------------------------------------------------------------------------------------------- + ---------- + ----- + ---------- + -------- + -------- + -------------------- + --------------------
2019-12-26 13:10:37 | https://cb.server.name.here:443/sensor/register/29530 | 0x80072f9a | 12186 | 0 | 0 | 0 | 500 | 0
2019-12-26 13:10:37 | https://cb.server.name.here:443/sensor/register/29530 | 0x80072f9a | 12186 | 0 | 0 | 0 | 500 | 0
2019-12-26 13:10:37 | https://cb.server.name.here:443/sensor/register/29530 | 0x80072f9a | 12186 | 0 | 0 | 0 | 500 | 0
  • Running the Windows certutil shows the following error:
c:\windows\system32 certutil -store carbonblack 

missing stored keyset



 

Cause

During the install or upgrade of the sensor, the certificate keys were not installed properly.

Resolution

  1. Manually uninstall the corrupt sensor- EDR: How to uninstall a corrupt sensor
  2. Reinstall the sensor on the Windows Endpoint.

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
2486
Contributors