Hi all, I have an issue when I want to install Sophos Intercept X on my server. I get the following error message : "Failed to install component(s): fim"
I see that in the log:
2022-06-28T06:17:16.3827942Z ERROR : SetupPluginCommand::onRun() failed with ComponentInstaller::InstallError: Failed to install component(s): fim2022-06-28T06:17:16.3827942Z INFO : Extracting CRT result from: C:\\Users\\ADMIN\\AppData\\Local\\Temp\\TelemetryConfig.json2022-06-28T06:17:16.3827942Z INFO : Command 'SetupPlugin' completed with failure with reboot code '0' and error message 'Impossible d’installer le logiciel'.2022-06-28T06:17:16.3827942Z ERROR : Installation failed.2022-06-28T06:17:16.3827942Z INFO : Sending HTTP 'POST' request to: sophos/management/ep/install/events/endpoint/ccc450d7-cf26-043c-89e2-122a977f34332022-06-28T06:17:16.3827942Z INFO : Did not discover an URL for a PAC file2022-06-28T06:17:16.3827942Z INFO : Discovered the system proxy http=our_proxy_adress;https=our_proxy_adress2022-06-28T06:17:16.3827942Z INFO : Attempting to connect using proxy 'http=our_proxy_adress;https=our_proxy_adress' of type 'System'.2022-06-28T06:17:16.3827942Z INFO : Set security protocol: 000008002022-06-28T06:17:16.3827942Z INFO : Opening connection to mcs2-cloudstation-eu-west-1.prod.hydra.sophos.com2022-06-28T06:17:16.3827942Z INFO : Sending request for connection confirmation through potential proxy2022-06-28T06:17:16.3827942Z INFO : Request content size: 02022-06-28T06:17:19.9839959Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST2022-06-28T06:17:19.9995828Z INFO : Subject certificate failed validation against root CA: SophosCA12022-06-28T06:17:19.9995828Z INFO : Subject certificate failed validation against root CA: SophosCA22022-06-28T06:17:19.9995828Z INFO : Certificate check succeeded2022-06-28T06:17:19.9995828Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT2022-06-28T06:17:20.0308519Z INFO : Response status code: 2002022-06-28T06:17:20.0308519Z INFO : Response data size: 1682022-06-28T06:17:20.0308519Z INFO : trySendRequestThroughPotentialProxy returning response with status code: 2002022-06-28T06:17:20.0308519Z INFO : Request content size: 10682022-06-28T06:17:20.0308519Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST2022-06-28T06:17:20.0308519Z INFO : Subject certificate failed validation against root CA: SophosCA12022-06-28T06:17:20.0308519Z INFO : Subject certificate failed validation against root CA: SophosCA22022-06-28T06:17:20.0308519Z INFO : Certificate check succeeded2022-06-28T06:17:20.0308519Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT2022-06-28T06:17:20.0933500Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST2022-06-28T06:17:20.0933500Z INFO : Subject certificate failed validation against root CA: SophosCA12022-06-28T06:17:20.0933500Z INFO : Subject certificate failed validation against root CA: SophosCA22022-06-28T06:17:20.1102549Z INFO : Certificate check succeeded2022-06-28T06:17:20.1102549Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT2022-06-28T06:17:20.1112596Z INFO : Response status code: 2002022-06-28T06:17:20.1113313Z INFO : Response data size: 0
But I don't know what are blocking ?? If you have any ideas, or you get the same issue like me, reply to me please !!!
I have already try to remove, reboot and reinstall but same thing.
Thanks you in advance
Hi Christophe,
Thanks for reaching out to the Sophos Community Forum.
Based on the following error, you may need to enable Root Certificate Updates on your device.
2022-06-28T06:17:20.0933500Z INFO : Subject certificate failed validation against root CA: SophosCA12022-06-28T06:17:20.0933500Z INFO : Subject certificate failed validation against root CA: SophosCA2
The following article covers this a bit further. - Sophos Central: Automatic Root Certificates Update is turned off, which could lead to installation and communication failures
If FIM failed to install there should be a FIM install log in %temp% where %temp% is the account that ran the installers temp directory.