IT Management Suite

 View Only
Expand all | Collapse all

Windows Patch Assessment failing

  • 1.  Windows Patch Assessment failing

    Posted Apr 10, 2023 05:19 PM

    We have a few servers failing on Windows Patch Assessment. Certs are installed, tried uninstalling and reinstalling the agent. still failing.

    attached is a the logs screenshot:
     



  • 2.  RE: Windows Patch Assessment failing

    Broadcom Employee
    Posted Apr 11, 2023 12:08 AM

    Hi WTargarean!

    Probably you have a same symptoms as described in this KB Article:
    https://knowledge.broadcom.com/external/article/164743/windows-system-assessment-scan-fails-wit.html

    Best regards,
    IP.




  • 3.  RE: Windows Patch Assessment failing

    Posted Apr 11, 2023 07:00 AM

    We ran into this over the last weekend too. You likely need this certificate: https://cacerts.digicert.com/DigiCertTrustedRootG4.crt

    It looks like they have changed how their signing is being done as of March 2023: https://knowledge.digicert.com/generalinformation/digicert-root-and-intermediate-ca-certificate-updates-2023.html 




  • 4.  RE: Windows Patch Assessment failing

    Posted Apr 11, 2023 08:10 AM

    Hi all,

    we have the same issue! installing the new certificate didn't work. Then I saw that we only have issues on the machines that have no internet access. So just enabled internet access for a few minutes, opened a browser to whatever website, closed it and after that patch assessment scan was resolved. could it be an issue caused by CRL lookup?




  • 5.  RE: Windows Patch Assessment failing

    Posted Apr 11, 2023 10:24 AM

    We are also seeing the same issue.  However, we are not in a position to be able to give all our server estate access to the internet. We can definitely see where the limited number of servers and workstations that do have internet access are working with no issue, guessing as you say, they can perform CRL lookups.  




  • 6.  RE: Windows Patch Assessment failing

    Broadcom Employee
    Posted Apr 11, 2023 10:43 AM

    We plan to update KB164743 shortly with new certificates information but here is the short summary.
    The following certificates need to be installed on affected computers (according to our investigation these are endpoints that don't have access to Internet):

    https://cacerts.digicert.com/DigiCertTrustedRootG4.crt to Trusted Root Certification Authorities
    http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt to Intermediate Certification Authorities

    The easiest way to distribute them to numerous endpoints is using Notification Server Connection Profile functionality - it has an ability to transfer certificates to the managed endpoints and install to appropriate certificate stores there:




  • 7.  RE: Windows Patch Assessment failing

    Posted Apr 11, 2023 11:19 AM

    Hello,

    What is the required password ?




  • 8.  RE: Windows Patch Assessment failing

    Broadcom Employee
    Posted Apr 11, 2023 11:41 AM

    Alex,

    The files I downloaded were a .crt.  Importing a .crt didn't require a password for me. Looks like you're importing a .cer file?

    Both certificates imported correctly:

    Hope that helps,
    Roy




  • 9.  RE: Windows Patch Assessment failing

    Posted Apr 11, 2023 11:59 AM

    Hello Roy,

    yes with CRT name, it works correctly without requesting a password. Thank you for your help
    Alex




  • 10.  RE: Windows Patch Assessment failing

    Posted Apr 13, 2023 07:08 AM

    I am seeing the same issue on my side.  However, I am not using a certification infrastructure and I am also not able to allow all machines access to the internet.  It doesn't even work on my NS and SQL server.  So where to from here?




  • 11.  RE: Windows Patch Assessment failing

    Broadcom Employee
    Posted Apr 13, 2023 07:27 AM

    Hi Jacques,

    please check KB164743 - it currently contains two options how to install the required certificates and we're looking into possibility to automate the process.

    Best regard,
    Dmitri.




  • 12.  RE: Windows Patch Assessment failing

    Posted Apr 13, 2023 07:29 AM

    We following the KB https://knowledge.broadcom.com/external/article/164743/windows-system-assessment-scan-fails-wit.html and then downloaded all the certs.  Then as per method 3 in the KB, we deployed via the NS Communication Profile - our servers also don't have internet access, but this method worked for us.  We are now up and running again.




  • 13.  RE: Windows Patch Assessment failing

    Posted Apr 13, 2023 07:44 AM

    As mentioned before we are not running in HTTPS or SSL mode so we are not using certificates in the environment. I have no existing certificates to replace and I don't intend on enabling HTTPS mode either.  Any other suggestions?




  • 14.  RE: Windows Patch Assessment failing

    Posted Apr 13, 2023 08:22 AM

    I got mine to work now by downloading the certs and adding them to the SSL settings as described in the article.  The logs showed that the certs are being replaced on the client machine and then the patch scan was able to complete.  I did not have to touch the HTTPS settings.




  • 15.  RE: Windows Patch Assessment failing
    Best Answer

    Broadcom Employee
    Posted Apr 14, 2023 12:05 PM

    KB164743 is updated with additional resolution options.




  • 16.  RE: Windows Patch Assessment failing

    Posted Apr 17, 2023 03:39 PM

    Thank you! everything is working




  • 17.  RE: Windows Patch Assessment failing

    Broadcom Employee
    Posted May 19, 2023 02:51 AM

    Just in case, there is a custom inventory available to get information about installed certificates in trusted root and CA from managed client computers, to make sure that all computers have required certificates installed

    https://community.broadcom.com/symantecenterprise/viewdocument/custom-inventory-to-get-installed-c?CommunityKey=bf23126f-6eab-4bbe-965d-e26838c079e0&tab=librarydocuments




  • 18.  RE: Windows Patch Assessment failing

    Posted May 22, 2023 11:33 AM

    This is helpful, Thank you Igor!