Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Upgraded corp srv to 10.0.2 but not seeing 10.0.0 clients

Status
Not open for further replies.

Auger282

MIS
Sep 27, 2003
978
...I have checked the option to manage clients 9.X and below and have rebooted.. I have not yet ran my upgrade script to upgrade the masses to 10.0.2..

Looking at the console I can see all my 9x and 8x clients and a few 10.0.2 clients that I have been testing my rollout with but I have ZERO 10.0.0 clients.. a bit disturbing..

any ideas?
 
I've found another odd thing messing with the grc.dat file

the new 10.0.2 doesnt use "norton antivirus corporate edition" for the application data area... it's using "symantec antivirus corporate edition"...

I've since downgraded back to 10.0.0 (I dont have a copy of 10.0.1) and now I cant see my 10.0.0 clients or my 10.0.2 clients.. all I have is my 8x and my 9x clients..


I tried just flopping the new grc.dat to my computer running 10.0.2 (server running 10.0.2 again) and its not seeing my computer.....

gah
 
I had a similar issue. My PKI files had gotten corrupted somehow....I deleted them and then restored from my backups and all the 10.x clients started showing up. Be very careful messing with the PKI folder...make lots of backups !!
 
I had to do a reinstall from a crashed machine... is there a smaller package I could send out to all the clients to trust this new server?
 
If you don't have a backup of the PKI files - I think you may be out of luck....I think I would give Symantec's tech support a call at this point to have them help you get your clients back...they helped me with my PKI files (I had backups)....they said if I didnt have backups - I would have to reinstall all my clients...I hope you arent in that predicament.
 
well I'm currently sending out nav upgrades to all clients.. and they seem to be reconnecting... I only have like 250 clients and I have remote access so I can tie up the loose ends...

I've heard people talk about sending the clients the GRC.DAT file to all the clients but I've done some testing and it doesnt help..

I'm guessing it re-establishes the settings but not the certs for the new server
 
Make sure to back up your PKI folder to some other location when youre done....it saved me big time !!
 
Copying the grc.dat files to the client doesnt seem to work well with 10.0.2

I tried it and the client showed the correct parent server and settings, but they would not show up in System Center Console.

I downloaded esugmakedrop from the Symantec site which is a tool for making stand alones into server based. Once I used this all my clients reported in to SSC.

No Guts No Glory. So I try and try again...
 
do you have a link for that util.. I'm having trouble finding it...
 
It was a password protect download from their FTP site. I would shoot them an email and im sure they will send you the logon.

I do have the app and the logon but I dont think I should give it out here.

If you really need it now, write back and we can make an arrangement to just give you the app.

They really should give it out with the program......

No Guts No Glory. So I try and try again...
 
What you want to is compare the root certificate on the server with the one on your client:

server: c:\program files\sav\symantec antivirus\pki\roots\<filename>

client: c:\program files\symantec client security\symantec antivirus\pki\roots\<filename>

If you have a different file on the client than on the server, merely copy the root certificate file from the server to the client and then remove the invalid root certificate on the client.

It won't hurt to drop a fresh GRC.DAT on the client as well...
 
the grc.dat didnt seem to help anything before when I was testing.. but the cert makes sense.. I'll give it a try
 
I have been putting my new cert from the server onto the clients and its been working like a charm..

..follow up question.. can I copy that root cert back to the server so there are 2 root certs?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top