This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SGE 5.60 - autologon issue

Hi everyone,

I upgraded SGE and 3 clients to 5.60 and one of the upgraded clients has problem with Autologon / POA. Installation process completed successfully and connection with the server exists, but after reboot I can see message "Autologon will continue shortly." everytime. Two of the upgraded clients have no problems. Could anyone tell me what might be wrong? I have to give this laptop back to one of manager, so problem is quite urgent.

Edit: I reinstalled Windows 7 a few times ( with disk format) with the same effect. In the status pane of SGN Client I can see: SGN user state is pending and Data packets prepared for transmission = 2. Additionally in the Management Center in inventory section for this machine POA checkbox is unchecked, but in the policy POA is enabled.

I have to decide and tell to my principal if it is a problem with hardware ( so they have to buy another laptops) or it is a problem with software.

:12969


This thread was automatically locked due to age.
  • Hi secadm.

    In order to investigate this issue please raise a support call. When doing so please provide a trace with level 0 form one reboot.

    Enabling the trace is described in this KBA http://www.sophos.com/support/knowledgebase/article/108081.html

    Regards

    Dan

    :13027
  • Hi,

    Same for me but with 5.50.x, solution in my case was to start SGE client installation with NOATA=1 parameter.

    Just for your information you don't have to reinstall windows just boot from Win 7 recovery CD and run bootrec.exe /fixmbr (I had to run bootrec.exe /fixboot also) boot normally to Windows, uninstall SGE client and install it again with NOATA parameter.

    Of couse this apply to nonencrypted disk.

    Regards,

    Igor

    :13145
  • Hi all,

    please note when removing the MRB from an encrypted machine this can cause severe side effects and in the worst case the machine will become unusable!

    In this case it seems as if the POA boot is working fine but the communication between client and server is not working properly which cannot be fixed with a hotkey at POA level or NOATA parameter as this only affects the boot and not the communication.

    Regards

    Dan

    :13151
  • Did you get a resolution to this? I've just put SGE 5.60.1 onto our pilot Win 7 machines and they never add the user as an owner.

    They contact the server and create an entry but never come out of the autologon step. 

    :17311
  • Hi timw,

    thank you very much for posting. Actually there is no general answer to this problem as already mentioned. I would recommend that you open a ticket providing the trace file as this is the easiest way to check such issues =)

    Regards

    Dan

    :17313
  • Is doing the tracefile still the best way to find a solution to this?  Are there any "generalized" things to check at all?  We have 2 laptops T520's that are doing this after the first reboot following installation of SGN.

    :17917
  • Hi sallzall,

    thank you very much for posting. Actually the trace file does contain the most and best information for us to check if things are ok.

    At your side you could check if the SGN POA kernel is properly written to the disk (open a cmd prompt > chkdsk c:\ (No Parameters!) > see if there is approx 98mb of bad sectors on the drive).

    Additionally you can check in the Management Center if the machine has reported any events back that would point to a problem.

    Last but not least you can check if the encryption does kick in > should those machines also not start to encrypt there is a problem with the kernel but this would then still require further analysis.

    Finally you could also try to change the log on name (user@domain instead domain\user) - eventually things will change then?

    Regards

    Dan

    :17919
  • Hello,

    I'm brand new to working with Sophos products.. :) I need your help, please. I've the same issue, so boot without pre-boot authentication (POA) but after logon with Sophos profile the SGN status is on "pending", what's wrong?

    Where can I see any log files, please?

    Thanks

    Fabrizio.

    :52751
  • If the SGNuser status is still "pending" usually its down to a connection issue. We have had problems like this a few times and usually rebooting the device a few times helped.

    Its worth checking that the configuration package is installed (its the third MSI you will install and should appear in Add / Remove programs).

    Also worth a check is whether the endpoint can connect to the server. To do this browse to C:\ProgramData\Utimaco\SafeGuard Enterprise\LocalCache\transout\config\init.xml and open it in note pad. (each letter will have a space between them - dont worry this is normal)

    There should be website address there. See if you can open it in your internet browser and click "check connection". If you cant access the website then that is likely the reason why Safeguard cant synchronise the user state. It could be an issue with the certificate - especailly if the date is wrong on the laptop.

    :52813
  • I just ported the script from my XP machines and missed out the credential provider from my install script.

    ADDLOCAL=Client,Authentication,CredentialProvider,BaseEncryption,SectorBasedEncryption

    Adding that in fixed it for me on my installs.

    :52823