Odd behavior: freezes and certificate errors

Hello all,

I've been running BIg Sur with the Sophos Endpoint Protection software for about two weeks now, and I'm noticing some intermittent issues. I am NOT certain that the Sophos client has anything to do with it.

Symptoms

* Sudden bouts of "freezing" applications. They become unresponsive, show the spinning circle, and must be Force-Quit. The impact at the times of these freezes is High; in effect, the system becomes unusable.

* Unpredictable and intermittent TLS Certificate errors within web browsers, claiming that sites present the incorrect certificate. The certs that are presented belong to different tabs. Happens in Chrome, Safari and Firefox. When they happen, they prevent pages from loading, so the impact is pretty high.

These symptoms started post-upgrade to Big Sur+EAP Sophos Client.

NOTE: there seems some negative interplay between Google Drive File Stream and the Sophos client as well, but I don't have enough of a handle on that yet to write something meaningful about

It APPEARS that disabling Cryptoguard resolves the issue. Obviously, that's not an acceptable workaround. However, when I went to Big Sur and the EAP client, I suspected that I was in for a bit of pain, so I'm not complaining (too much).

I'm running Big Sur on a 2008 Macbook Pro with 32Gb of Memory.

  • Just to update. The issue seems to continue, even when all components are in bypass. It is almost perfectly reproducible with triggering a rapid succession of operations on different files stored on a Google Drive volume.

    When the "freeze" triggers, I suspect all disk i/o is suspended, since apps that do NOT require any disk i/o continue to work. Once they access secondary storage, they too freeze.

    I'll put the exclusions for the Google Drive folders on again, and see if that makes a difference.

  • Hi Eric,

    This weekend I have seen a lot of connection errors. I can confirm it's not related to DNS or Certificate errors. It seems Sophos interrupts the network traffic because I noticed VPN connections are affected as well. During a VPN connecting I noticed drops (VPN keeps alive/reconnects). Besides that I have captured screenshot when the connection was lost in Safari. All I did was browsing and clicking on links. This issue happend this weekend many times.

    I've tried to upload an image but during upload I get to see this error "An error occurred. Please try again or contact your administrator." in this portal.

  • Hi Kees,

    We are aware of the issue of CryptoGuard interfering with Google Drive, and the fix for it is in the upcoming GA release being rolled as we speak. The GA version will be being released to both EAP and GA lines together so no action is required to get the update.

    Thank you and your feedback is much appreciated.