This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Endpoint Protection Installer - Installation failed. Could not download software.

Hello one and all,

 

I work in a corporate environment where we've been using Sophos Central and Endpoint with InterceptX for quite a while now. Just recently (probably within the last 2 weeks) I have been unable to install Sophos Endpoint Protection on any Windows 7 desktops or laptops...when running the through the installation - it'll get to the "downloading software" step - then produce the following error:

 

"Installation failed. Could not download software"

 

I have tried installing using the corporate network, corporate wifi and my own personal wifi hotspot (using mobile device) and it fails each time with the above error. Windows firewall is disabled on every device, so I know it's nothing to do with that. It is the "Complete Windows Installer" freshly downloaded from Sophos Central today. SophosCloudInstaller log below:

Started C:\Users\ADMIN-~1\AppData\Local\Temp\sfl-68e97440\Setup.exe
2018-03-14T11:52:47.6013557Z INFO : SophosInstall command line: "C:\\Users\\ADMIN-~1\\AppData\\Local\\Temp\\sfl-68e97440\\Setup.exe"
2018-03-14T11:52:47.6013557Z INFO : Command line: Quiet mode on: 0
2018-03-14T11:52:47.6013557Z INFO : Command line: Automatic Proxy detection disabled: 0
2018-03-14T11:52:47.6013557Z INFO : Command line: No feedback mode on: 0
2018-03-14T11:52:47.6013557Z INFO : Command line: Dump feedback enabled: 0
2018-03-14T11:52:47.6013557Z INFO : Command line: Bypass competitor removal: 0
2018-03-14T11:52:47.6013557Z INFO : Command line: Using CRT catalog file path: --
2018-03-14T11:52:47.6013557Z INFO : Command line: Only register endpoint with Central: 0
2018-03-14T11:52:47.6013557Z INFO : Command line: Using custom server: --
2018-03-14T11:52:47.6013557Z INFO : Command line: Using custom stage 2 filename: --
2018-03-14T11:52:47.6013557Z INFO : Command line: Using cloud user: --
2018-03-14T11:52:47.6013557Z INFO : Command line: Using cloud group: --
2018-03-14T11:52:47.6013557Z INFO : Command line: Overriding computer name: --
2018-03-14T11:52:47.6013557Z INFO : Command line: Overriding computer description: --
2018-03-14T11:52:47.6013557Z INFO : Command line: Overriding domain name: --
2018-03-14T11:52:47.6013557Z INFO : Command line: Language will be set to: --
2018-03-14T11:52:47.6013557Z INFO : Command line: Using message relays: --
2018-03-14T11:52:47.6013557Z INFO : Command line: Proxy address: --
2018-03-14T11:52:47.6013557Z INFO : Command line: Proxy user name: --
2018-03-14T11:52:47.6013557Z INFO : Command line: Using custom customer token: --
2018-03-14T11:52:47.6013557Z INFO : Command line: Using specified products: --
2018-03-14T11:52:47.6013557Z INFO : Command line: Using certificates from the MCS app data folder: 0
2018-03-14T11:52:47.6013557Z INFO : Sending HTTP 'GET' request to: full/central/windows/business/installer/latest.tar.gz
2018-03-14T11:52:47.6169567Z WARNING : WinHttpGetProxyForUrl returned: 12180
2018-03-14T11:52:47.6169567Z INFO : Attempting to connect using proxy '' of type 'Empty Proxy'.
2018-03-14T11:52:47.6169567Z INFO : Set security protocol: 00000800
2018-03-14T11:52:47.6169567Z INFO : Opening connection to downloads.sophos.com
2018-03-14T11:52:47.6169567Z INFO : Opened connection to downloads.sophos.com
2018-03-14T11:52:47.6169567Z INFO : Request content size: 0
2018-03-14T11:52:47.7105627Z INFO : Sending request
2018-03-14T11:52:47.7105627Z INFO : Request sent
2018-03-14T11:52:47.9601787Z INFO : Response status code: 200
2018-03-14T11:52:47.9601787Z INFO : Response data size: 1674811
2018-03-14T11:52:47.9601787Z INFO : trySendRequestThroughPotentialProxy returning response with status code: 200
2018-03-14T11:52:47.9601787Z INFO : Extracting files:
2018-03-14T11:52:47.9601787Z INFO : integrity.dat
2018-03-14T11:52:47.9601787Z INFO : manifest.dat
2018-03-14T11:52:47.9601787Z INFO : rootca.crl
2018-03-14T11:52:47.9601787Z INFO : rootca.crt
2018-03-14T11:52:47.9601787Z INFO : scf.dat
2018-03-14T11:52:47.9601787Z INFO : sof.dat
2018-03-14T11:52:47.9601787Z INFO : SophosSetup_Stage2.exe
2018-03-14T11:52:47.9913807Z INFO : sul.dll
2018-03-14T11:52:48.0069817Z INFO : Management Certs/sophosca1.crl
2018-03-14T11:52:48.0069817Z INFO : Management Certs/sophosca1.crt
2018-03-14T11:52:48.0069817Z INFO : Management Certs/sophosca2.crl
2018-03-14T11:52:48.0225827Z INFO : Management Certs/sophosca2.crt
2018-03-14T11:52:48.0225827Z INFO : Management Certs/Sophos_SHA256_MCS_Root_CA3_exp20380504.crl
2018-03-14T11:52:48.0225827Z INFO : Management Certs/Sophos_SHA256_MCS_Root_CA3_exp20380504.crt
2018-03-14T11:52:48.0225827Z INFO : Management Certs/Sophos_SHA256_MCS_Root_CA4_exp20390504.crl
2018-03-14T11:52:48.0225827Z INFO : Management Certs/Sophos_SHA256_MCS_Root_CA4_exp20390504.crt
2018-03-14T11:52:48.0849867Z INFO : Running setup.
Started C:\Program Files (x86)\Sophos\CloudInstaller\SophosSetup_Stage2.exe
2018-03-14T11:52:48.1161887Z INFO : Setup command line: --mgmtserver="dzr-mcs-amzn-us-west-2-fa88.upe.p.hmr.sophos.com" --logfile="C:\\ProgramData\\Sophos\\CloudInstaller\\Logs\\SophosCloudInstaller_20180314_115247.log" --parentpid="2056" --products="all" --customertoken="263389cb-41da-4e04-bd2e-b239d7317472" --pipewritehandle="1160" --mcscustomerid="710cbe79-4858-b440-6b6b-85b85b34e6be"
2018-03-14T11:52:48.1161887Z INFO : User name: admin-sjw
2018-03-14T11:52:48.1161887Z INFO : NameDnsDomain: FCLLP.LAN\\admin-sjw
2018-03-14T11:52:48.1161887Z INFO : dnsDomain: FCLLP.LAN
2018-03-14T11:52:48.3034007Z INFO : lpProfilePath:
2018-03-14T11:52:48.3346027Z INFO : User profile loaded
2018-03-14T11:52:48.3346027Z INFO : Net API buffer freed
2018-03-14T11:52:48.3346027Z INFO : Model::server value changed to: dzr-mcs-amzn-us-west-2-fa88.upe.p.hmr.sophos.com
2018-03-14T11:52:48.3346027Z INFO : Model::messageRelays value changed to be size: 0
2018-03-14T11:52:48.3346027Z INFO : Model::user value changed to:
2018-03-14T11:52:48.3346027Z INFO : Model::group value changed to:
2018-03-14T11:52:48.3346027Z INFO : Model::parentPid value changed to: 2056
2018-03-14T11:52:48.3346027Z INFO : Model::products changed to: all
2018-03-14T11:52:48.3346027Z INFO : Model::customer token value changed to: 263389cb-41da-4e04-bd2e-b239d7317472
2018-03-14T11:52:48.3346027Z INFO : MCS Crts: C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\sophosca1.crt,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\sophosca2.crt,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\Sophos_SHA256_MCS_Root_CA3_exp20380504.crt,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\Sophos_SHA256_MCS_Root_CA4_exp20390504.crt
2018-03-14T11:52:48.3346027Z INFO : MCS CRLs: C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\sophosca1.crl,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\sophosca2.crl,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\Sophos_SHA256_MCS_Root_CA3_exp20380504.crl,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\Sophos_SHA256_MCS_Root_CA4_exp20390504.crl
2018-03-14T11:52:48.3346027Z INFO : Model:: MCS customer id value changed to: 710cbe79-4858-b440-6b6b-85b85b34e6be
2018-03-14T11:52:48.3346027Z INFO : Beginning command definition.
2018-03-14T11:52:48.3346027Z INFO : Adding competitor detection command.
2018-03-14T11:52:48.3346027Z INFO : Adding command to register with Sophos cloud.
2018-03-14T11:52:48.3346027Z INFO : Adding MCS Override Registry keys if applicable; computer name, computer description, working group/domain name.
2018-03-14T11:52:48.3346027Z INFO : Adding command to download product suite.
2018-03-14T11:52:48.3346027Z INFO : Adding command to retrieve policy.
2018-03-14T11:52:48.3346027Z INFO : Adding command to prepare for installation.
2018-03-14T11:52:48.3346027Z INFO : Adding command to install Sophos cloud.
2018-03-14T11:52:48.3346027Z INFO : Adding command to persist installation and download status.
2018-03-14T11:52:48.3346027Z INFO : Command definition complete.
2018-03-14T11:52:48.3346027Z INFO : Stage 1 version:1.1.19.0
2018-03-14T11:52:48.3346027Z INFO : Stage 2 version:1.2.12
2018-03-14T11:52:48.3346027Z INFO : OS version: 6.1.7601.
2018-03-14T11:52:48.3346027Z INFO : Service pack: 1.0.
2018-03-14T11:52:48.3346027Z INFO : System Language: 1033.
2018-03-14T11:52:48.3346027Z INFO : User Language: 1033.
2018-03-14T11:52:48.3346027Z INFO : 64 bit: yes.
2018-03-14T11:52:48.7870317Z INFO : Running System Property Check: VerifyTrust ...
2018-03-14T11:52:48.8338347Z INFO : System Property Check: VerifyTrust - PASSED
2018-03-14T11:52:48.8962387Z INFO : Running System Property Check: HostnameLength ...
2018-03-14T11:52:48.8962387Z INFO : Initialized Winsock subsystem
2018-03-14T11:52:48.8962387Z INFO : Valid hostname length
2018-03-14T11:52:48.8962387Z INFO : System Property Check: HostnameLength - PASSED
2018-03-14T11:52:48.9586427Z INFO : Running System Property Check: GroupNameLength ...
2018-03-14T11:52:48.9586427Z INFO : System Property Check: GroupNameLength - PASSED
2018-03-14T11:52:49.0210467Z INFO : Running System Property Check: IsAdministrator ...
2018-03-14T11:52:49.0210467Z INFO : System Property Check: IsAdministrator - PASSED
2018-03-14T11:52:49.0834507Z INFO : Running System Property Check: PendingReboots ...
2018-03-14T11:52:49.0834507Z INFO : System Property Check: PendingReboots - PASSED
2018-03-14T11:52:49.1458547Z INFO : Running System Property Check: PrimaryDriveSpace ...
2018-03-14T11:52:49.1458547Z INFO : Enough space: 194964 Mb
2018-03-14T11:52:49.1458547Z INFO : System Property Check: PrimaryDriveSpace - PASSED
2018-03-14T11:52:49.2082587Z INFO : Running System Property Check: MsXml ...
2018-03-14T11:52:49.2082587Z INFO : System Property Check: MsXml - PASSED
2018-03-14T11:52:49.2706627Z INFO : Running System Property Check: NotFirewall ...
2018-03-14T11:52:49.2706627Z INFO : System Property Check: NotFirewall - PASSED
2018-03-14T11:52:49.3330667Z INFO : Running System Property Check: NotHitmanProAlertIncompatible ...
2018-03-14T11:52:49.3330667Z INFO : No HitmanPro.Alert Installed
2018-03-14T11:52:49.3330667Z INFO : System Property Check: NotHitmanProAlertIncompatible - PASSED
2018-03-14T11:52:49.3954707Z INFO : Running System Property Check: NotInvincea ...
2018-03-14T11:52:49.3954707Z INFO : System Property Check: NotInvincea - PASSED
2018-03-14T11:52:49.4578747Z INFO : Running System Property Check: NotMessageRelay ...
2018-03-14T11:52:49.4578747Z INFO : RMS is not installed on the endpoint
2018-03-14T11:52:49.4578747Z INFO : System Property Check: NotMessageRelay - PASSED
2018-03-14T11:52:49.5202787Z INFO : Running System Property Check: NotNac ...
2018-03-14T11:52:49.5202787Z INFO : System Property Check: NotNac - PASSED
2018-03-14T11:52:49.5826827Z INFO : Running System Property Check: NotPatch ...
2018-03-14T11:52:49.5826827Z INFO : System Property Check: NotPatch - PASSED
2018-03-14T11:52:49.6450867Z INFO : Running System Property Check: NotPureMessageDomino ...
2018-03-14T11:52:49.6450867Z INFO : System Property Check: NotPureMessageDomino - PASSED
2018-03-14T11:52:49.7074907Z INFO : Running System Property Check: NotPureMessageExchangeWithAntiSpam ...
2018-03-14T11:52:49.7074907Z INFO : System Property Check: NotPureMessageExchangeWithAntiSpam - PASSED
2018-03-14T11:52:49.7698947Z INFO : Running System Property Check: NotSharePoint ...
2018-03-14T11:52:49.7698947Z INFO : System Property Check: NotSharePoint - PASSED
2018-03-14T11:52:49.8322987Z INFO : Running System Property Check: NotSecServer ...
2018-03-14T11:52:49.8322987Z INFO : System Property Check: NotSecServer - PASSED
2018-03-14T11:52:49.8947027Z INFO : Running System Property Check: NotSum ...
2018-03-14T11:52:49.8947027Z INFO : System Property Check: NotSum - PASSED
2018-03-14T11:52:49.9571067Z INFO : Running System Property Check: NotTamperProtected ...
2018-03-14T11:52:49.9571067Z INFO : Sophos Endpoint Defense is not installed
2018-03-14T11:52:49.9571067Z INFO : System Property Check: NotTamperProtected - PASSED
2018-03-14T11:52:50.0195107Z INFO : Running System Property Check: RAMSize ...
2018-03-14T11:52:50.0195107Z INFO : System Property Check: RAMSize - PASSED
2018-03-14T11:52:50.0819147Z INFO : Running System Property Check: SupportedOS ...
2018-03-14T11:52:50.0819147Z INFO : Running on workstation.
2018-03-14T11:52:50.0819147Z INFO : System Property Check: SupportedOS - PASSED
2018-03-14T11:52:50.1443187Z INFO : Running System Property Check: ValidTempDirectory ...
2018-03-14T11:52:50.1443187Z INFO : Temp folder exists.
2018-03-14T11:52:50.1443187Z INFO : System Property Check: ValidTempDirectory - PASSED
2018-03-14T11:52:50.2067227Z INFO : Running System Property Check: ValidServer ...
2018-03-14T11:52:50.2067227Z INFO : System Property Check: ValidServer - PASSED
2018-03-14T11:52:50.2691267Z INFO : Running System Property Check: ValidDeploymentInfo ...
2018-03-14T11:52:50.2691267Z INFO : Current Time: 2018-03-14T11:52:50.269000
2018-03-14T11:52:50.2691267Z INFO : This computer is part of the domain FCLLP
2018-03-14T11:52:50.2691267Z INFO : Domain Name: FCLLP
2018-03-14T11:52:50.2691267Z INFO : Computer Name: FCCL52VN
2018-03-14T11:52:50.2691267Z INFO : Computer Description is not available.
2018-03-14T11:52:50.2691267Z INFO : Operating System: WIN7
2018-03-14T11:52:50.2691267Z INFO : ProductType: 48
2018-03-14T11:52:50.2691267Z INFO : Last logged on user was: FCLLP\\admin-sjw
2018-03-14T11:52:50.2691267Z INFO : Fully Qualified Domain Name: FCCL52VN.fcllp.lan
2018-03-14T11:52:50.2691267Z INFO : Processor architecture: x64
2018-03-14T11:52:50.2691267Z INFO : OS Major Version: 6 and OS Minor Version: 1
2018-03-14T11:52:50.2691267Z INFO : Friendly OS Name: WIN7
2018-03-14T11:52:50.2691267Z INFO : Is server?: 0
2018-03-14T11:52:50.2691267Z INFO : Sending HTTP 'POST' request to: sophos/management/ep/install/deployment-info
2018-03-14T11:52:50.2847277Z WARNING : WinHttpGetProxyForUrl returned: 12180
2018-03-14T11:52:50.2847277Z INFO : Attempting to connect using proxy '' of type 'Empty Proxy'.
2018-03-14T11:52:50.2847277Z INFO : Set security protocol: 00000800
2018-03-14T11:52:50.2847277Z INFO : Opening connection to dzr-mcs-amzn-us-west-2-fa88.upe.p.hmr.sophos.com
2018-03-14T11:52:50.2847277Z INFO : Sending request for connection confirmation through potential proxy
2018-03-14T11:52:50.2847277Z INFO : Request content size: 0
2018-03-14T11:52:50.8775657Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
2018-03-14T11:52:50.8775657Z INFO : Certificate check succeeded
2018-03-14T11:52:50.8775657Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
2018-03-14T11:52:51.0491767Z INFO : Response status code: 200
2018-03-14T11:52:51.0491767Z INFO : Response data size: 168
2018-03-14T11:52:51.0491767Z INFO : trySendRequestThroughPotentialProxy returning response with status code: 200
2018-03-14T11:52:51.0491767Z INFO : Request content size: 1106
2018-03-14T11:52:51.0491767Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
2018-03-14T11:52:51.0491767Z INFO : Certificate check succeeded
2018-03-14T11:52:51.0491767Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
2018-03-14T11:52:51.2207877Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
2018-03-14T11:52:51.2363887Z INFO : Certificate check succeeded
2018-03-14T11:52:51.2363887Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
2018-03-14T11:52:51.2363887Z INFO : Response status code: 200
2018-03-14T11:52:51.2363887Z INFO : Response data size: 390
2018-03-14T11:52:51.2363887Z INFO : Parsing message received for deployment token: {"registrationToken":"33951144eeea23aa1812336a29a7670a11ec80042dd580c7b2d5db63b77dbea5","products":[{"product":"ENDPOINT_ADVANCED","supported":true,"reasons":[]},{"product":"INTERCEPT","supported":true,"reasons":[]},{"product":"DEVICE_ENCRYPTION","supported":false,"reasons":["UNLICENSED","UNSUPPORTED_OS_VERSION"]},{"product":"FILE_ENCRYPTION","supported":false,"reasons":["UNLICENSED"]}]}
2018-03-14T11:52:51.2363887Z INFO : Model::token value changed to: 33951144eeea23aa1812336a29a7670a11ec80042dd580c7b2d5db63b77dbea5
2018-03-14T11:52:51.2363887Z INFO : Licenses available: ENDPOINT_ADVANCED INTERCEPT
2018-03-14T11:52:51.2987927Z INFO : Running System Property Check: InstallationInProgress ...
2018-03-14T11:52:51.2987927Z INFO : System Property Check: InstallationInProgress - PASSED
2018-03-14T11:52:51.3611967Z INFO : Running System Property Check: SafeGuardEncryption ...
2018-03-14T11:52:51.3611967Z INFO : Entered installedProductCode, upgradeCode={BA2F47D3-1C17-40E7-8DE7-1CD733442B6C}
2018-03-14T11:52:51.3611967Z INFO : Product is not installed
2018-03-14T11:52:51.3611967Z INFO : Entered installedProductCode, upgradeCode={C48CCEDE-A264-411F-AB82-BC9D67B8344B}
2018-03-14T11:52:51.3611967Z INFO : Product is not installed
2018-03-14T11:52:51.3611967Z INFO : licensesContainFeature(FILE_ENCRYPTION): false
2018-03-14T11:52:51.3611967Z INFO : licensesContainFeature(DEVICE_ENCRYPTION): false
2018-03-14T11:52:51.3611967Z INFO : System Property Check: SafeGuardEncryption - PASSED
2018-03-14T11:53:20.6286727Z INFO : Starting installation process.
2018-03-14T11:53:20.6286727Z INFO : About to execute command: CompetitorDetector
2018-03-14T11:53:20.6442737Z INFO : Command 'CompetitorDetector' completed with success with reboot code '0' and error message ''.
2018-03-14T11:53:20.6442737Z INFO : About to execute command: Register
2018-03-14T11:53:20.6442737Z INFO : Sending HTTP 'POST' request to: sophos/management/ep/install/register
2018-03-14T11:53:20.6442737Z WARNING : WinHttpGetProxyForUrl returned: 12180
2018-03-14T11:53:20.6442737Z INFO : Attempting to connect using proxy '' of type 'Empty Proxy'.
2018-03-14T11:53:20.6442737Z INFO : Set security protocol: 00000800
2018-03-14T11:53:20.6442737Z INFO : Opening connection to dzr-mcs-amzn-us-west-2-fa88.upe.p.hmr.sophos.com
2018-03-14T11:53:20.6442737Z INFO : Sending request for connection confirmation through potential proxy
2018-03-14T11:53:20.6442737Z INFO : Request content size: 0
2018-03-14T11:53:20.6442737Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
2018-03-14T11:53:20.6442737Z INFO : Certificate check succeeded
2018-03-14T11:53:20.6442737Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
2018-03-14T11:53:20.8158847Z INFO : Response status code: 200
2018-03-14T11:53:20.8158847Z INFO : Response data size: 168
2018-03-14T11:53:20.8158847Z INFO : trySendRequestThroughPotentialProxy returning response with status code: 200
2018-03-14T11:53:20.8158847Z INFO : Request content size: 1106
2018-03-14T11:53:20.8158847Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
2018-03-14T11:53:20.8314857Z INFO : Certificate check succeeded
2018-03-14T11:53:20.8314857Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
2018-03-14T11:53:21.1123037Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
2018-03-14T11:53:21.1123037Z INFO : Certificate check succeeded
2018-03-14T11:53:21.1123037Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
2018-03-14T11:53:21.1123037Z INFO : Response status code: 200
2018-03-14T11:53:21.1123037Z INFO : Response data size: 72
2018-03-14T11:53:21.1123037Z INFO : Retrieved endpoint id: cbf33cc6-ff98-b478-2b24-6942e66b4a5b
2018-03-14T11:53:21.1123037Z INFO : MCS Endpoint folder: C:\\ProgramData\\Sophos\\Management Communications System\\Endpoint\\
2018-03-14T11:53:21.1123037Z INFO : MCS Endpoint folder: C:\\ProgramData\\Sophos\\Management Communications System\\Endpoint\\
2018-03-14T11:53:21.1123037Z INFO : Retrieved customer id: 710cbe79-4858-b440-6b6b-85b85b34e6be
2018-03-14T11:53:21.1123037Z INFO : MCS Endpoint folder: C:\\ProgramData\\Sophos\\Management Communications System\\Endpoint\\
2018-03-14T11:53:22.1263687Z INFO : Sending HTTP 'PUT' request to: sophos/management/ep/install/statuses/endpoint/cbf33cc6-ff98-b478-2b24-6942e66b4a5b
2018-03-14T11:53:22.1263687Z INFO : Request content size: 952
2018-03-14T11:53:22.1263687Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
2018-03-14T11:53:22.1263687Z INFO : Certificate check succeeded
2018-03-14T11:53:22.1263687Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
2018-03-14T11:53:22.3291817Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
2018-03-14T11:53:22.3291817Z INFO : Certificate check succeeded
2018-03-14T11:53:22.3291817Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
2018-03-14T11:53:22.3291817Z INFO : Response status code: 200
2018-03-14T11:53:22.3291817Z INFO : Response data size: 0
2018-03-14T11:53:22.3291817Z INFO : Attempt to retrieve policy.
2018-03-14T11:53:22.3291817Z INFO : Sending HTTP 'GET' request to: sophos/management/ep/install/commands/applications/APPSPROXY;ALC/endpoint/cbf33cc6-ff98-b478-2b24-6942e66b4a5b
2018-03-14T11:53:22.3291817Z INFO : Request content size: 0
2018-03-14T11:53:22.3291817Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
2018-03-14T11:53:22.3291817Z INFO : Certificate check succeeded
2018-03-14T11:53:22.3447827Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
2018-03-14T11:53:22.5163937Z INFO : Response status code: 200
2018-03-14T11:53:22.5163937Z INFO : Response data size: 725
2018-03-14T11:53:22.5163937Z INFO : Successfully retrieved policy: commandID='64' policyId='369eed2f8e3e0aeef289cb8a7a91c9c229485eeb0946bd9a991d0256772d9c88'.
2018-03-14T11:53:22.5163937Z INFO : Sending HTTP 'DELETE' request to: sophos/management/ep/install/commands/endpoint/cbf33cc6-ff98-b478-2b24-6942e66b4a5b/64
2018-03-14T11:53:22.5163937Z INFO : Request content size: 0
2018-03-14T11:53:22.5163937Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
2018-03-14T11:53:22.5163937Z INFO : Certificate check succeeded
2018-03-14T11:53:22.5163937Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
2018-03-14T11:53:22.7036057Z INFO : Response status code: 200
2018-03-14T11:53:22.7036057Z INFO : Response data size: 0
2018-03-14T11:53:22.7036057Z INFO : Sending HTTP 'GET' request to: sophos/management/ep/install/policy/application/ALC/369eed2f8e3e0aeef289cb8a7a91c9c229485eeb0946bd9a991d0256772d9c88
2018-03-14T11:53:22.7036057Z INFO : Request content size: 0
2018-03-14T11:53:22.7036057Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
2018-03-14T11:53:22.7036057Z INFO : Certificate check succeeded
2018-03-14T11:53:22.7036057Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
2018-03-14T11:53:22.9376207Z INFO : Response status code: 200
2018-03-14T11:53:22.9376207Z INFO : Response data size: 8016
2018-03-14T11:53:22.9376207Z INFO : OverwritingSAUPolicy file C:\\ProgramData\\Sophos\\Remote Management System\\3\\Agent\\AdapterStorage\\ALC\\SAUPolicy
2018-03-14T11:53:22.9376207Z INFO : New SAU, assume obfuscated password
2018-03-14T11:53:23.2808427Z INFO : Updating subscription created with id: Base, rigidname: WindowsCloudNextGen, baseversion: 11, tag: RECOMMENDED, fixedversion:
2018-03-14T11:53:23.2808427Z INFO : Updating subscription created with id: Clean, rigidname: WindowsCloudClean, baseversion: 1, tag: RECOMMENDED, fixedversion:
2018-03-14T11:53:23.2808427Z INFO : Updating subscription created with id: CloudAV, rigidname: WindowsCloudAV, baseversion: 11, tag: RECOMMENDED, fixedversion:
2018-03-14T11:53:23.2808427Z INFO : Updating subscription created with id: HitmanProAlert, rigidname: WindowsCloudHitmanProAlert, baseversion: 1, tag: RECOMMENDED, fixedversion:
2018-03-14T11:53:23.2808427Z INFO : Features: APPCNTRL
2018-03-14T11:53:23.2808427Z INFO : Features: AV
2018-03-14T11:53:23.2808427Z INFO : Features: CLEAN
2018-03-14T11:53:23.2808427Z INFO : Features: CORE
2018-03-14T11:53:23.2808427Z INFO : Features: DLP
2018-03-14T11:53:23.2808427Z INFO : Features: DVCCNTRL
2018-03-14T11:53:23.2808427Z INFO : Features: EFW
2018-03-14T11:53:23.2808427Z INFO : Features: HBT
2018-03-14T11:53:23.2808427Z INFO : Features: NTP
2018-03-14T11:53:23.2808427Z INFO : Features: SAV
2018-03-14T11:53:23.2808427Z INFO : Features: SDU
2018-03-14T11:53:23.2808427Z INFO : Features: WEBCNTRL
2018-03-14T11:53:23.2808427Z INFO : Features: XPD
2018-03-14T11:53:23.2808427Z INFO : Setting https download to: false
2018-03-14T11:53:23.2808427Z INFO : Updating credentials created with username: 6YABHIO3MX
2018-03-14T11:53:23.2808427Z INFO : MCS Endpoint folder: C:\\ProgramData\\Sophos\\Management Communications System\\Endpoint\\
2018-03-14T11:53:23.2808427Z INFO : Command 'Register' completed with success with reboot code '0' and error message ''.
2018-03-14T11:53:23.2808427Z INFO : About to execute command: StoreMcsRegistryKeys
2018-03-14T11:53:23.2808427Z INFO : Command 'StoreMcsRegistryKeys' completed with success with reboot code '0' and error message ''.
2018-03-14T11:53:23.2808427Z INFO : About to execute command: Download
2018-03-14T11:53:23.2808427Z INFO : Update Cache Cert Path folder: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
2018-03-14T11:53:23.2808427Z INFO : About to create directory: C:\\ProgramData\\Sophos\\CloudInstaller\\AutoUpdatePreparation\\Cache\\decoded
2018-03-14T11:53:23.2808427Z INFO : Created directory: C:\\ProgramData\\Sophos\\CloudInstaller\\AutoUpdatePreparation\\Cache\\decoded
2018-03-14T11:53:23.2808427Z INFO : About to set security DACL on: C:\\ProgramData\\Sophos\\CloudInstaller\\AutoUpdatePreparation\\Cache\\decoded
2018-03-14T11:53:23.2808427Z INFO : Set security DACL on: C:\\ProgramData\\Sophos\\CloudInstaller\\AutoUpdatePreparation\\Cache\\decoded
2018-03-14T11:53:23.2808427Z INFO : About to create directory: C:\\ProgramData\\Sophos\\CloudInstaller\\AutoUpdatePreparation\\data\\Warehouse
2018-03-14T11:53:23.2808427Z INFO : Created directory: C:\\ProgramData\\Sophos\\CloudInstaller\\AutoUpdatePreparation\\data\\Warehouse
2018-03-14T11:53:23.2808427Z INFO : About to set security DACL on: C:\\ProgramData\\Sophos\\CloudInstaller\\AutoUpdatePreparation\\data
2018-03-14T11:53:23.2808427Z INFO : Set security DACL on: C:\\ProgramData\\Sophos\\CloudInstaller\\AutoUpdatePreparation\\data
2018-03-14T11:53:23.2808427Z INFO : About to create directory: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
2018-03-14T11:53:23.2808427Z INFO : Created directory: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
2018-03-14T11:53:23.2808427Z INFO : About to set security DACL on: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
2018-03-14T11:53:23.2808427Z INFO : Set security DACL on: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
2018-03-14T11:53:23.2808427Z INFO : Update Cache Cert Path folder: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
2018-03-14T11:53:23.2808427Z INFO : Update Cache Cert Path folder: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
2018-03-14T11:53:23.2808427Z INFO : Writing cert: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache\\1323c8d6ae076942b89d7580ee4f630e2d8ffd4c.crt.crt
2018-03-14T11:53:23.2808427Z INFO : Writing cert: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache\\23337756cd0b3478acd0475de4fd89976e779a63.crt.crt
2018-03-14T11:53:23.2808427Z INFO : Writing cert: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache\\33d6a435957397fc9336c8633445aa33e1774500.crt.crt
2018-03-14T11:53:23.2808427Z INFO : Analyzing whether to update from Sophos CDN or update cache
2018-03-14T11:53:23.2808427Z WARNING : Warning no ipv6 addresses found for fcbfmps1.fcllp.lan:8191.
2018-03-14T11:53:23.2808427Z WARNING : Warning no ipv6 addresses found for fccfmps1.fcllp.lan:8191.
2018-03-14T11:53:23.2808427Z WARNING : Warning no ipv6 addresses found for fcdfmps1.fcllp.lan:8191.
2018-03-14T11:53:23.2808427Z WARNING : Warning no ipv6 addresses found for fcleefmps1.fcllp.lan:8191.
2018-03-14T11:53:23.2808427Z WARNING : Warning no ipv6 addresses found for fclfmps1.fcllp.lan:8191.
2018-03-14T11:53:23.2964437Z WARNING : Warning no ipv6 addresses found for fclonfmps1.fcllp.lan:8191.
2018-03-14T11:53:23.2964437Z WARNING : Warning no ipv6 addresses found for fcmfmps1.fcllp.lan:8191.
2018-03-14T11:53:23.2964437Z WARNING : Warning no ipv6 addresses found for fcmkfmps1.fcllp.lan:8191.
2018-03-14T11:53:23.2964437Z WARNING : Warning no ipv6 addresses found for fcoxfmps1.fcllp.lan:8191.
2018-03-14T11:53:23.2964437Z WARNING : Warning no ipv6 addresses found for fcshfmps1.fcllp.lan:8191.
2018-03-14T11:53:23.2964437Z WARNING : Warning no ipv6 addresses found for fcstfmps1.fcllp.lan:8191.
2018-03-14T11:53:23.2964437Z INFO : Checking access to update cache: fccfmps1.fcllp.lan:8191
2018-03-14T11:53:23.2964437Z INFO : Updating configured to use: HTTPS
2018-03-14T11:53:23.2964437Z INFO : Update Cache Cert Path folder: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
2018-03-14T11:53:23.3120447Z INFO : Successfully connected to cache
2018-03-14T11:53:23.3120447Z INFO : Cache response time: 25ms
2018-03-14T11:53:23.3120447Z INFO : Analysis complete - Using update cache: fccfmps1.fcllp.lan:8191
2018-03-14T11:53:23.3120447Z INFO : Updating from cache: fccfmps1.fcllp.lan:8191
2018-03-14T11:53:23.3120447Z INFO : Updating configured to use: HTTPS
2018-03-14T11:53:23.3276457Z INFO : Initial download: attempting to use bulk metadata
2018-03-14T11:53:23.3276457Z INFO : Calling SULDownloader addGlobalFilter...
2018-03-14T11:53:23.3276457Z INFO : Subscription: Base
2018-03-14T11:53:23.3276457Z INFO : SUL info: [T46381] SU::Handle::readRemoteMetadata + SU::Handle::readRemoteMetadata()
2018-03-14T11:53:23.3276457Z INFO : SUL info: [T75884] SU::Metadata::readRemoteMetadata SU::Metadata::readRemoteMetadata()
2018-03-14T11:53:23.3276457Z INFO : SUL info: [I40394] Downloading customer file from sophos:1:1
2018-03-14T11:53:23.3276457Z INFO : SUL info: [T81533] SU::createCachedPackageSource creating cached package source for sophos:1:1: url=sophos
2018-03-14T11:53:23.3276457Z INFO : SUL info: [T81533] SU::createCachedPackageSource creating http_source_specific_data to download customer file
2018-03-14T11:53:23.3276457Z INFO : SUL info: [T81533] SU::createCachedPackageSource creating package source to download customer file
2018-03-14T11:53:23.3276457Z INFO : SUL info: [T81533] SU::createCachedPackageSource creating cached package source
2018-03-14T11:53:23.3276457Z INFO : SUL info: [I40395] Downloaded customer file; fetching catalogues from sophos:1:1...
2018-03-14T11:53:23.3276457Z INFO : SUL info: [T31993] SU::internal::CustomerFile::getWarehousesFromSophosUpdateSource Getting catalogues
2018-03-14T11:53:23.3276457Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: catalogue/sdds.CEPNG_1081.6.xml
2018-03-14T11:53:23.3276457Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Success: catalogue/sdds.CEPNG_1081.6.xml: 0 ms
2018-03-14T11:53:23.3276457Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: catalogue/sdds.CEP_11014.2.xml
2018-03-14T11:53:23.3276457Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Success: catalogue/sdds.CEP_11014.2.xml: 0 ms
2018-03-14T11:53:23.3276457Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: catalogue/sdds.CIX_2-0-0.3.xml
2018-03-14T11:53:23.3432467Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Success: catalogue/sdds.CIX_2-0-0.3.xml: 16 ms
2018-03-14T11:53:23.3432467Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: catalogue/sdds.Cloud-SVE1113692.1.xml
2018-03-14T11:53:23.3432467Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Success: catalogue/sdds.Cloud-SVE1113692.1.xml: 0 ms
2018-03-14T11:53:23.3432467Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: catalogue/sdds.CloudEnc_1-3-90.1.xml
2018-03-14T11:53:23.3432467Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Success: catalogue/sdds.CloudEnc_1-3-90.1.xml: 0 ms
2018-03-14T11:53:23.3432467Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: catalogue/sdds.CloudOSX_966_973.6.xml
2018-03-14T11:53:23.3432467Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Success: catalogue/sdds.CloudOSX_966_973.6.xml: 0 ms
2018-03-14T11:53:23.3432467Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: catalogue/sdds.CloudVirt-VS21113692.2.xml
2018-03-14T11:53:23.3432467Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Success: catalogue/sdds.CloudVirt-VS21113692.2.xml: 0 ms
2018-03-14T11:53:23.3432467Z INFO : SUL info: [T31993] SU::internal::CustomerFile::getWarehousesFromSophosUpdateSource Getting warehouses
2018-03-14T11:53:23.3432467Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: bulk/sdds.CEPNG_1081.6.xml.zip
2018-03-14T11:53:24.1232967Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Failure: bulk/sdds.CEPNG_1081.6.xml.zip: 780 ms
2018-03-14T11:53:24.1232967Z INFO : SUL info: [WARN] cached_package_source::copy_from_upstream copy from upstream failed: 500 Internal Server Error: error fetching fccfmps1.fcllp.lan:8191/.../sdds.CEPNG_1081.6.xml.zip
2018-03-14T11:53:24.1232967Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 7193 bytes
2018-03-14T11:53:24.1232967Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Failure: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 0 ms
2018-03-14T11:53:24.1232967Z INFO : SUL info: [WARN] cached_package_source::copy_from_upstream copy from upstream failed: Cannot read remote resource: fccfmps1.fcllp.lan:8191/.../94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 404 Not Found
2018-03-14T11:53:24.1857007Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 7193 bytes
2018-03-14T11:53:24.1857007Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Failure: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 0 ms
2018-03-14T11:53:24.1857007Z INFO : SUL info: [WARN] cached_package_source::copy_from_upstream copy from upstream failed: Cannot read remote resource: fccfmps1.fcllp.lan:8191/.../94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 404 Not Found
2018-03-14T11:53:24.2949077Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 7193 bytes
2018-03-14T11:53:24.2949077Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Failure: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 0 ms
2018-03-14T11:53:24.2949077Z INFO : SUL info: [WARN] cached_package_source::copy_from_upstream copy from upstream failed: Cannot read remote resource: fccfmps1.fcllp.lan:8191/.../94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 404 Not Found
2018-03-14T11:53:24.4977207Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 7193 bytes
2018-03-14T11:53:24.4977207Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Failure: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 0 ms
2018-03-14T11:53:24.4977207Z INFO : SUL info: [WARN] cached_package_source::copy_from_upstream copy from upstream failed: Cannot read remote resource: fccfmps1.fcllp.lan:8191/.../94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 404 Not Found
2018-03-14T11:53:24.9033467Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 7193 bytes
2018-03-14T11:53:24.9033467Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Failure: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 0 ms
2018-03-14T11:53:24.9033467Z INFO : SUL info: [WARN] cached_package_source::copy_from_upstream copy from upstream failed: Cannot read remote resource: fccfmps1.fcllp.lan:8191/.../94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 404 Not Found
2018-03-14T11:53:24.9033467Z WARNING : SUL error: [E79514] Cannot read resource: fccfmps1.fcllp.lan:8191/.../94667e07e7c4dc93f4855b549d8b6d5cx000.xml
2018-03-14T11:53:24.9033467Z INFO : SUL info: [I79514] No proxy was used.
2018-03-14T11:53:24.9033467Z INFO : SUL info: [I40394] Downloading customer file from sophos:1:2
2018-03-14T11:53:24.9033467Z INFO : SUL info: [T81533] SU::createCachedPackageSource creating cached package source for sophos:1:2: url=sophos
2018-03-14T11:53:24.9033467Z INFO : SUL info: [T81533] SU::createCachedPackageSource creating http_source_specific_data to download customer file
2018-03-14T11:53:24.9033467Z INFO : SUL info: [T81533] SU::createCachedPackageSource creating package source to download customer file
2018-03-14T11:53:24.9189477Z INFO : SUL info: [T81533] SU::createCachedPackageSource creating cached package source
2018-03-14T11:53:24.9189477Z INFO : SUL info: [I40395] Downloaded customer file; fetching catalogues from sophos:1:2...
2018-03-14T11:53:24.9189477Z INFO : SUL info: [T31993] SU::internal::CustomerFile::getWarehousesFromSophosUpdateSource Getting catalogues
2018-03-14T11:53:24.9189477Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: catalogue/sdds.CEPNG_1081.6.xml
2018-03-14T11:53:24.9189477Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Success: catalogue/sdds.CEPNG_1081.6.xml: 0 ms
2018-03-14T11:53:24.9189477Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: catalogue/sdds.CEP_11014.2.xml
2018-03-14T11:53:24.9189477Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Success: catalogue/sdds.CEP_11014.2.xml: 0 ms
2018-03-14T11:53:24.9189477Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: catalogue/sdds.CIX_2-0-0.3.xml
2018-03-14T11:53:24.9189477Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Success: catalogue/sdds.CIX_2-0-0.3.xml: 0 ms
2018-03-14T11:53:24.9189477Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: catalogue/sdds.Cloud-SVE1113692.1.xml
2018-03-14T11:53:24.9345487Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Success: catalogue/sdds.Cloud-SVE1113692.1.xml: 16 ms
2018-03-14T11:53:24.9345487Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: catalogue/sdds.CloudEnc_1-3-90.1.xml
2018-03-14T11:53:24.9345487Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Success: catalogue/sdds.CloudEnc_1-3-90.1.xml: 0 ms
2018-03-14T11:53:24.9345487Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: catalogue/sdds.CloudOSX_966_973.6.xml
2018-03-14T11:53:24.9345487Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Success: catalogue/sdds.CloudOSX_966_973.6.xml: 0 ms
2018-03-14T11:53:24.9345487Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: catalogue/sdds.CloudVirt-VS21113692.2.xml
2018-03-14T11:53:24.9345487Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Success: catalogue/sdds.CloudVirt-VS21113692.2.xml: 0 ms
2018-03-14T11:53:24.9345487Z INFO : SUL info: [T31993] SU::internal::CustomerFile::getWarehousesFromSophosUpdateSource Getting warehouses
2018-03-14T11:53:24.9345487Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: bulk/sdds.CEPNG_1081.6.xml.zip
2018-03-14T11:53:25.7145987Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Failure: bulk/sdds.CEPNG_1081.6.xml.zip: 780 ms
2018-03-14T11:53:25.7145987Z INFO : SUL info: [WARN] cached_package_source::copy_from_upstream copy from upstream failed: 500 Internal Server Error: error fetching fccfmps1.fcllp.lan:8191/.../sdds.CEPNG_1081.6.xml.zip
2018-03-14T11:53:25.7145987Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 7193 bytes
2018-03-14T11:53:25.7145987Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Failure: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 0 ms
2018-03-14T11:53:25.7145987Z INFO : SUL info: [WARN] cached_package_source::copy_from_upstream copy from upstream failed: Cannot read remote resource: fccfmps1.fcllp.lan:8191/.../94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 404 Not Found
2018-03-14T11:53:25.7770027Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 7193 bytes
2018-03-14T11:53:25.7770027Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Failure: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 0 ms
2018-03-14T11:53:25.7770027Z INFO : SUL info: [WARN] cached_package_source::copy_from_upstream copy from upstream failed: Cannot read remote resource: fccfmps1.fcllp.lan:8191/.../94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 404 Not Found
2018-03-14T11:53:25.8862097Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 7193 bytes
2018-03-14T11:53:25.8862097Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Failure: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 0 ms
2018-03-14T11:53:25.8862097Z INFO : SUL info: [WARN] cached_package_source::copy_from_upstream copy from upstream failed: Cannot read remote resource: fccfmps1.fcllp.lan:8191/.../94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 404 Not Found
2018-03-14T11:53:26.0890227Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 7193 bytes
2018-03-14T11:53:26.0890227Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Failure: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 0 ms
2018-03-14T11:53:26.0890227Z INFO : SUL info: [WARN] cached_package_source::copy_from_upstream copy from upstream failed: Cannot read remote resource: fccfmps1.fcllp.lan:8191/.../94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 404 Not Found
2018-03-14T11:53:26.4946487Z INFO : SUL info: [T52614] SU::LoggingAdvisor::start_file [metadata] Syncing: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 7193 bytes
2018-03-14T11:53:26.4946487Z INFO : SUL info: [T52615] SU::LoggingAdvisor::end_file [metadata] Failure: 94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 0 ms
2018-03-14T11:53:26.4946487Z INFO : SUL info: [WARN] cached_package_source::copy_from_upstream copy from upstream failed: Cannot read remote resource: fccfmps1.fcllp.lan:8191/.../94667e07e7c4dc93f4855b549d8b6d5cx000.xml: 404 Not Found
2018-03-14T11:53:26.4946487Z WARNING : SUL error: [E79514] Cannot read resource: fccfmps1.fcllp.lan:8191/.../94667e07e7c4dc93f4855b549d8b6d5cx000.xml
2018-03-14T11:53:26.4946487Z INFO : SUL info: [I79514] No proxy was used.
2018-03-14T11:53:26.4946487Z INFO : SUL info: [I40394] Downloading customer file from sophos:1:3
2018-03-14T11:53:26.4946487Z INFO : SUL info: [T81533] SU::createCachedPackageSource creating cached package source for sophos:1:3: url=sophos
2018-03-14T11:53:26.4946487Z INFO : SUL info: [T81533] SU::createCachedPackageSource creating http_source_specific_data to download customer file
2018-03-14T11:53:26.4946487Z INFO : SUL info: [T81533] SU::createCachedPackageSource creating package source to download customer file
2018-03-14T11:53:26.5102497Z WARNING : SUL error: [E73334] Ran out of URLs in customer file, switching to next sophos alias
2018-03-14T11:53:26.5102497Z INFO : SUL info: [I73334] No proxy was used.
2018-03-14T11:53:26.5102497Z INFO : SUL info: [I40394] Downloading customer file from sophos:2:1
2018-03-14T11:53:26.5102497Z INFO : SUL info: [T81533] SU::createCachedPackageSource creating cached package source for sophos:2:1: url=sophos
2018-03-14T11:53:26.5102497Z INFO : SUL info: [T81533] SU::createCachedPackageSource creating http_source_specific_data to download customer file
2018-03-14T11:53:26.5102497Z INFO : SUL info: [T81533] SU::createCachedPackageSource creating package source to download customer file
2018-03-14T11:53:26.5102497Z WARNING : SUL error: [E75373] Ran out of sophos aliases for this update source
2018-03-14T11:53:26.5102497Z WARNING : SUL error: [E35369] Out of update sources
2018-03-14T11:53:26.5102497Z WARNING : SUL error: [E99999] Out of sources
2018-03-14T11:53:26.5102497Z ERROR : DownloadCommand::onRun() failed with std::exception: MetaDataScope::MetaDataScope failed with error code 4
2018-03-14T11:53:26.5102497Z INFO : Command 'Download' completed with failure with reboot code '0' and error message 'Could not download software'.
2018-03-14T11:53:26.5102497Z ERROR : Installation failed.
2018-03-14T11:53:26.5102497Z INFO : Sending HTTP 'POST' request to: sophos/management/ep/install/events/endpoint/cbf33cc6-ff98-b478-2b24-6942e66b4a5b
2018-03-14T11:53:26.5102497Z WARNING : WinHttpGetProxyForUrl returned: 12180
2018-03-14T11:53:26.5102497Z INFO : Attempting to connect using proxy '' of type 'Empty Proxy'.
2018-03-14T11:53:26.5102497Z INFO : Set security protocol: 00000800
2018-03-14T11:53:26.5102497Z INFO : Opening connection to dzr-mcs-amzn-us-west-2-fa88.upe.p.hmr.sophos.com
2018-03-14T11:53:26.5102497Z INFO : Sending request for connection confirmation through potential proxy
2018-03-14T11:53:26.5102497Z INFO : Request content size: 0
2018-03-14T11:53:26.5102497Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
2018-03-14T11:53:26.5102497Z INFO : Certificate check succeeded
2018-03-14T11:53:26.5102497Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
2018-03-14T11:53:26.6818607Z INFO : Response status code: 200
2018-03-14T11:53:26.6818607Z INFO : Response data size: 168
2018-03-14T11:53:26.6818607Z INFO : trySendRequestThroughPotentialProxy returning response with status code: 200
2018-03-14T11:53:26.6818607Z INFO : Request content size: 1150
2018-03-14T11:53:26.6818607Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
2018-03-14T11:53:26.6818607Z INFO : Certificate check succeeded
2018-03-14T11:53:26.6974617Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
2018-03-14T11:53:26.9470777Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
2018-03-14T11:53:26.9470777Z INFO : Certificate check succeeded
2018-03-14T11:53:26.9470777Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
2018-03-14T11:53:26.9470777Z INFO : Response status code: 200
2018-03-14T11:53:26.9470777Z INFO : Response data size: 0
2018-03-14T12:14:39.0879574Z INFO : Data folder: C:\\ProgramData\\Sophos\\AutoUpdate\\data
2018-03-14T12:14:39.0879574Z INFO : Data folder: C:\\ProgramData\\Sophos\\AutoUpdate\\data
2018-03-14T12:14:39.0879574Z INFO : Sending HTTP 'PUT' request to: prod/2018-03-14T12:14:39Z-2018-03-14T12:14:39Z-11888ea5-5517-57d2-8554-62cceb61b84d.json
2018-03-14T12:14:39.0879574Z WARNING : WinHttpGetProxyForUrl returned: 12180
2018-03-14T12:14:39.0879574Z INFO : Attempting to connect using proxy '' of type 'Empty Proxy'.
2018-03-14T12:14:39.0879574Z INFO : Set security protocol: 00000800
2018-03-14T12:14:39.0879574Z INFO : Opening connection to t1.sophosupd.com
2018-03-14T12:14:39.0879574Z INFO : Request content size: 2692
2018-03-14T12:14:39.1347580Z INFO : Sending request
2018-03-14T12:14:39.1347580Z INFO : Request sent
2018-03-14T12:14:39.1815586Z INFO : Sending request
2018-03-14T12:14:39.1815586Z INFO : Request sent
2018-03-14T12:14:39.1815586Z INFO : Response status code: 200
2018-03-14T12:14:39.1815586Z INFO : Response data size: 0
2018-03-14T12:14:39.1815586Z INFO : trySendRequestThroughPotentialProxy returning response with status code: 200
2018-03-14T12:14:39.1815586Z INFO : Telemetry Response:
2018-03-14T12:14:39.1815586Z INFO : User profile unloaded
2018-03-14T12:14:39.1971588Z INFO : Cleaning up extracted files
2018-03-14T12:14:39.2439594Z ERROR : Exception: Setup program failed with code: 1

 

This seems to stand out from the log:

ERROR : DownloadCommand::onRun() failed with std::exception: MetaDataScope::MetaDataScope failed with error code 4

 

But I have no idea what that means. Is anyone else having the same issue? Any suggestions would be greatly appreciated.

 

Thanks, Simon

 




[locked by: SupportFlo at 2:53 PM (GMT -7) on 26 Sep 2018]
Parents
  • Can anyone who has similar/or this issue please direct message me the Sophos case reference you have so I can review these cases?

    I would like to do a comprehensive review of this issue and progress these cases/find a solution as soon as possible.

    Kind Regards.

  • Hi,

    It seems that installing from existing cache server is not working and the error message we found within the install logs are identical to OP's logs. We have confirmed that the issue is already happening to one of our current customer, a prospective customer, and in our own lab. 

    The issue only happens when trying to install with --messagerelays switch and when client pc has no access to the internet. Installation is find when directly install from Sophos.  

     

    Started C:\Users\rd\AppData\Local\Temp\sfl-fae13500\Setup.exe
    2018-09-14T08:36:24.6103515Z INFO : SophosInstall command line: "C:\\Users\\rd\\AppData\\Local\\Temp\\sfl-fae13500\\Setup.exe" --messagerelays=172.16.9.37:8190
    2018-09-14T08:36:24.6103515Z INFO : Command line: Quiet mode on: 0
    2018-09-14T08:36:24.6103515Z INFO : Command line: Automatic Proxy detection disabled: 0
    2018-09-14T08:36:24.6103515Z INFO : Command line: No feedback mode on: 0
    2018-09-14T08:36:24.6103515Z INFO : Command line: Dump feedback enabled: 0
    2018-09-14T08:36:24.6103515Z INFO : Command line: Bypass competitor removal: 0
    2018-09-14T08:36:24.6103515Z INFO : Command line: Using CRT catalog file path: --
    2018-09-14T08:36:24.6103515Z INFO : Command line: Only register endpoint with Central: 0
    2018-09-14T08:36:24.6103515Z INFO : Command line: Using custom server: --
    2018-09-14T08:36:24.6103515Z INFO : Command line: Using custom stage 2 filename: --
    2018-09-14T08:36:24.6103515Z INFO : Command line: Using cloud user: --
    2018-09-14T08:36:24.6103515Z INFO : Command line: Using cloud group: --
    2018-09-14T08:36:24.6103515Z INFO : Command line: Overriding computer name: --
    2018-09-14T08:36:24.6103515Z INFO : Command line: Overriding computer description: --
    2018-09-14T08:36:24.6103515Z INFO : Command line: Overriding domain name: --
    2018-09-14T08:36:24.6103515Z INFO : Command line: Language will be set to: --
    2018-09-14T08:36:24.6103515Z INFO : Command line: Using message relays: 172.16.9.37:8190
    2018-09-14T08:36:24.6103515Z INFO : Command line: Proxy address: --
    2018-09-14T08:36:24.6103515Z INFO : Command line: Proxy user name: --
    2018-09-14T08:36:24.6103515Z INFO : Command line: Using custom customer token: --
    2018-09-14T08:36:24.6103515Z INFO : Command line: Using specified products: --
    2018-09-14T08:36:24.6103515Z INFO : Command line: Using certificates from the MCS app data folder: 0
    2018-09-14T08:36:24.6259765Z INFO : Sending HTTP 'GET' request to: full/central/windows/business/installer/latest.tar.gz
    2018-09-14T08:36:24.6259765Z WARNING : WinHttpGetProxyForUrl returned: 12180
    2018-09-14T08:36:24.6416015Z INFO : Attempting to connect using proxy '172.16.9.37:8190' of type 'Message Relay'.
    2018-09-14T08:36:24.6416015Z INFO : Set security protocol: 00000800
    2018-09-14T08:36:24.6416015Z INFO : Opening connection to downloads.sophos.com
    2018-09-14T08:36:24.6416015Z INFO : Opened connection to downloads.sophos.com
    2018-09-14T08:36:24.6416015Z INFO : Request content size: 0
    2018-09-14T08:36:25.5791015Z INFO : Request sent
    2018-09-14T08:36:25.6259765Z INFO : Sending request
    2018-09-14T08:36:25.6259765Z INFO : Request sent
    2018-09-14T08:36:27.4072265Z INFO : Response status code: 200
    2018-09-14T08:36:27.4072265Z INFO : Response data size: 1722651
    2018-09-14T08:36:27.4072265Z INFO : trySendRequestThroughPotentialProxy returning response with status code: 200
    2018-09-14T08:36:27.4072265Z INFO : Extracting files:
    2018-09-14T08:36:27.4072265Z INFO : integrity.dat
    2018-09-14T08:36:27.4072265Z INFO : manifest.dat
    2018-09-14T08:36:27.4072265Z INFO : rootca.crl
    2018-09-14T08:36:27.4072265Z INFO : rootca.crt
    2018-09-14T08:36:27.4072265Z INFO : scf.dat
    2018-09-14T08:36:27.4072265Z INFO : sof.dat
    2018-09-14T08:36:27.4072265Z INFO : SophosSetup_Stage2.exe
    2018-09-14T08:36:27.4541015Z INFO : sul.dll
    2018-09-14T08:36:27.4853515Z INFO : Management Certs/sophosca1.crl
    2018-09-14T08:36:27.4853515Z INFO : Management Certs/sophosca1.crt
    2018-09-14T08:36:27.4853515Z INFO : Management Certs/sophosca2.crl
    2018-09-14T08:36:27.4853515Z INFO : Management Certs/sophosca2.crt
    2018-09-14T08:36:27.4853515Z INFO : Management Certs/Sophos_SHA256_MCS_Root_CA3_exp20380504.crl
    2018-09-14T08:36:27.4853515Z INFO : Management Certs/Sophos_SHA256_MCS_Root_CA3_exp20380504.crt
    2018-09-14T08:36:27.5009765Z INFO : Management Certs/Sophos_SHA256_MCS_Root_CA4_exp20390504.crl
    2018-09-14T08:36:27.5009765Z INFO : Management Certs/Sophos_SHA256_MCS_Root_CA4_exp20390504.crt
    2018-09-14T08:36:27.5634765Z INFO : Running setup.
    Started C:\Program Files (x86)\Sophos\CloudInstaller\SophosSetup_Stage2.exe
    2018-09-14T08:36:27.6416015Z INFO : Stage 2 command-line options:
    2018-09-14T08:36:27.6416015Z INFO : ---
    2018-09-14T08:36:27.6416015Z INFO : Parent PID: 5044
    2018-09-14T08:36:27.6416015Z INFO : Server: mcs-cloudstation-eu-central-1.prod.hydra.sophos.com
    2018-09-14T08:36:27.6416015Z INFO : Message relays: 172.16.9.37:8190
    2018-09-14T08:36:27.6416015Z INFO : Suppressing feedback: 0
    2018-09-14T08:36:27.6416015Z INFO : Dump feedback to disk: 0
    2018-09-14T08:36:27.6416015Z INFO : Register only: 0
    2018-09-14T08:36:27.6416015Z INFO : Trail logging: 0
    2018-09-14T08:36:27.6416015Z INFO : Command-line logging: 0
    2018-09-14T08:36:27.6416015Z INFO : Bypassing competitor removal: 0
    2018-09-14T08:36:27.6416015Z INFO : CRT catalog: --
    2018-09-14T08:36:27.6416015Z INFO : Language: --
    2018-09-14T08:36:27.6416015Z INFO : Log files: C:\\ProgramData\\Sophos\\CloudInstaller\\Logs\\SophosCloudInstaller_20180914_083624.log
    2018-09-14T08:36:27.6416015Z INFO : User: --
    2018-09-14T08:36:27.6416015Z INFO : Group: --
    2018-09-14T08:36:27.6416015Z INFO : Quiet: 0
    2018-09-14T08:36:27.6416015Z INFO : Virtual appliance: 0
    2018-09-14T08:36:27.6416015Z INFO : Proxy address: --
    2018-09-14T08:36:27.6416015Z INFO : Proxy user: --
    2018-09-14T08:36:27.6416015Z INFO : Overriding computer name: --
    2018-09-14T08:36:27.6416015Z INFO : Overriding computer description: --
    2018-09-14T08:36:27.6416015Z INFO : Overriding domain: --
    2018-09-14T08:36:27.6416015Z INFO : Disable proxy detection: 0
    2018-09-14T08:36:27.6416015Z INFO : Customer Token Specified: f716ec48-f93b-4db0-98e9-d9a3aa7b72dd
    2018-09-14T08:36:27.6416015Z INFO : Products: all
    2018-09-14T08:36:27.6416015Z INFO : Pipe write handle: 1476
    2018-09-14T08:36:27.6416015Z INFO : MCS Certificates Folder: 0
    2018-09-14T08:36:27.6416015Z INFO : MCS Customer Id: da674e0b-1c18-14a3-da0f-4c80e72c85dc
    2018-09-14T08:36:27.6416015Z INFO : Partner Id: --
    2018-09-14T08:36:27.6416015Z INFO : Customer Estate Id: --
    2018-09-14T08:36:27.6416015Z INFO : ---
    2018-09-14T08:36:27.6416015Z INFO : User name: rd
    2018-09-14T08:36:27.6416015Z INFO : GetUserNameEx/NameDnsDomain: The user name is not available in the specified format. Assuming non-Domain computer.
    2018-09-14T08:36:27.6884765Z INFO : User profile loaded
    2018-09-14T08:36:27.6884765Z INFO : Model::server value changed to: mcs-cloudstation-eu-central-1.prod.hydra.sophos.com
    2018-09-14T08:36:27.6884765Z INFO : Model::messageRelays value changed to be size: 1
    2018-09-14T08:36:27.6884765Z INFO : Model::user value changed to:
    2018-09-14T08:36:27.6884765Z INFO : Model::group value changed to:
    2018-09-14T08:36:27.6884765Z INFO : Model::parentPid value changed to: 5044
    2018-09-14T08:36:27.6884765Z INFO : Model::products changed to: all
    2018-09-14T08:36:27.6884765Z INFO : Model::customer token value changed to: f716ec48-f93b-4db0-98e9-d9a3aa7b72dd
    2018-09-14T08:36:27.6884765Z INFO : MCS Crts: C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\sophosca1.crt,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\sophosca2.crt,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\Sophos_SHA256_MCS_Root_CA3_exp20380504.crt,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\Sophos_SHA256_MCS_Root_CA4_exp20390504.crt
    2018-09-14T08:36:27.6884765Z INFO : MCS CRLs: C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\sophosca1.crl,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\sophosca2.crl,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\Sophos_SHA256_MCS_Root_CA3_exp20380504.crl,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\Sophos_SHA256_MCS_Root_CA4_exp20390504.crl
    2018-09-14T08:36:27.7041015Z INFO : Model:: MCS customer id value changed to: da674e0b-1c18-14a3-da0f-4c80e72c85dc
    2018-09-14T08:36:27.7041015Z INFO : Sophos Endpoint Defense is not installed
    2018-09-14T08:36:27.7041015Z INFO : detectedMsiInstalledMcs.installed: 0
    2018-09-14T08:36:27.7041015Z INFO : Beginning command definition.
    2018-09-14T08:36:27.7041015Z INFO : Adding competitor detection command.
    2018-09-14T08:36:27.7041015Z INFO : Adding command to register with Sophos cloud.
    2018-09-14T08:36:27.7041015Z INFO : Adding command to download product suite.
    2018-09-14T08:36:27.7041015Z INFO : Adding commands to uninstall existing products.
    2018-09-14T08:36:27.7041015Z INFO : Adding command to retrieve policy.
    2018-09-14T08:36:27.7041015Z INFO : Adding command to prepare for installation.
    2018-09-14T08:36:27.7041015Z INFO : Adding command to install Sophos cloud.
    2018-09-14T08:36:27.7041015Z INFO : Command definition complete.
    2018-09-14T08:36:27.7041015Z INFO : Stage 1 version:1.1.19.0
    2018-09-14T08:36:27.7041015Z INFO : Stage 2 version:1.5.70
    2018-09-14T08:36:27.7041015Z INFO : OS version: 6.1.7601.
    2018-09-14T08:36:27.7041015Z INFO : Service pack: 1.0.
    2018-09-14T08:36:27.7041015Z INFO : System Language: 1028.
    2018-09-14T08:36:27.7041015Z INFO : User Language: 1028.
    2018-09-14T08:36:27.7041015Z INFO : 64 bit: yes.
    2018-09-14T08:36:27.7041015Z INFO : FindMainWindow: pid=5044
    2018-09-14T08:36:27.7041015Z INFO : Found window for process
    2018-09-14T08:36:27.7041015Z INFO : Window is main window of process
    2018-09-14T08:36:27.7041015Z INFO : ::EnumWindows stopped early; window found
    2018-09-14T08:36:27.7041015Z INFO : _bestHandle=00110292
    2018-09-14T08:36:28.4072265Z INFO : Running System Property Check: VerifyTrust ...
    2018-09-14T08:36:28.4384765Z INFO : System Property Check: VerifyTrust - PASSED
    2018-09-14T08:36:28.5009765Z INFO : Running System Property Check: HostnameLength ...
    2018-09-14T08:36:28.5009765Z INFO : Initialized Winsock subsystem
    2018-09-14T08:36:28.5009765Z INFO : Valid hostname length
    2018-09-14T08:36:28.5009765Z INFO : System Property Check: HostnameLength - PASSED
    2018-09-14T08:36:28.5634765Z INFO : Running System Property Check: GroupNameLength ...
    2018-09-14T08:36:28.5634765Z INFO : System Property Check: GroupNameLength - PASSED
    2018-09-14T08:36:28.6259765Z INFO : Running System Property Check: IsAdministrator ...
    2018-09-14T08:36:28.6259765Z INFO : System Property Check: IsAdministrator - PASSED
    2018-09-14T08:36:28.6884765Z INFO : Running System Property Check: PendingReboots ...
    2018-09-14T08:36:28.6884765Z INFO : System Property Check: PendingReboots - PASSED
    2018-09-14T08:36:28.7509765Z INFO : Running System Property Check: PrimaryDriveSpace ...
    2018-09-14T08:36:28.7509765Z INFO : Enough space: 5234 Mb
    2018-09-14T08:36:28.7509765Z INFO : System Property Check: PrimaryDriveSpace - PASSED
    2018-09-14T08:36:28.8134765Z INFO : Running System Property Check: MsXml ...
    2018-09-14T08:36:28.8134765Z INFO : System Property Check: MsXml - PASSED
    2018-09-14T08:36:28.8759765Z INFO : Running System Property Check: NotFirewall ...
    2018-09-14T08:36:28.8759765Z INFO : System Property Check: NotFirewall - PASSED
    2018-09-14T08:36:28.9384765Z INFO : Running System Property Check: NotHitmanProAlertIncompatible ...
    2018-09-14T08:36:28.9384765Z INFO : No HitmanPro.Alert Installed
    2018-09-14T08:36:28.9384765Z INFO : System Property Check: NotHitmanProAlertIncompatible - PASSED
    2018-09-14T08:36:29.0009765Z INFO : Running System Property Check: NotInvincea ...
    2018-09-14T08:36:29.0009765Z INFO : System Property Check: NotInvincea - PASSED
    2018-09-14T08:36:29.0634765Z INFO : Running System Property Check: NotMessageRelay ...
    2018-09-14T08:36:29.0634765Z INFO : RMS is not installed on the endpoint
    2018-09-14T08:36:29.0634765Z INFO : System Property Check: NotMessageRelay - PASSED
    2018-09-14T08:36:29.1259765Z INFO : Running System Property Check: NotNac ...
    2018-09-14T08:36:29.1259765Z INFO : System Property Check: NotNac - PASSED
    2018-09-14T08:36:29.1884765Z INFO : Running System Property Check: NotPatch ...
    2018-09-14T08:36:29.1884765Z INFO : System Property Check: NotPatch - PASSED
    2018-09-14T08:36:29.2509765Z INFO : Running System Property Check: NotPureMessageDomino ...
    2018-09-14T08:36:29.2509765Z INFO : System Property Check: NotPureMessageDomino - PASSED
    2018-09-14T08:36:29.3134765Z INFO : Running System Property Check: NotPureMessageExchangeWithAntiSpam ...
    2018-09-14T08:36:29.3134765Z INFO : System Property Check: NotPureMessageExchangeWithAntiSpam - PASSED
    2018-09-14T08:36:29.3759765Z INFO : Running System Property Check: NotSharePoint ...
    2018-09-14T08:36:29.3759765Z INFO : System Property Check: NotSharePoint - PASSED
    2018-09-14T08:36:29.4384765Z INFO : Running System Property Check: NotSecServer ...
    2018-09-14T08:36:29.4384765Z INFO : System Property Check: NotSecServer - PASSED
    2018-09-14T08:36:29.5009765Z INFO : Running System Property Check: NotSum ...
    2018-09-14T08:36:29.5009765Z INFO : System Property Check: NotSum - PASSED
    2018-09-14T08:36:29.5634765Z INFO : Running System Property Check: NotBlockedByTamperProtection ...
    2018-09-14T08:36:29.5634765Z INFO : Not tamper protected
    2018-09-14T08:36:29.5634765Z INFO : System Property Check: NotBlockedByTamperProtection - PASSED
    2018-09-14T08:36:29.6259765Z INFO : Running System Property Check: RAMSize ...
    2018-09-14T08:36:29.6259765Z INFO : System Property Check: RAMSize - PASSED
    2018-09-14T08:36:29.6884765Z INFO : Running System Property Check: SupportedOS ...
    2018-09-14T08:36:29.6884765Z INFO : Running on workstation.
    2018-09-14T08:36:29.6884765Z INFO : System Property Check: SupportedOS - PASSED
    2018-09-14T08:36:29.7509765Z INFO : Running System Property Check: ValidTempDirectory ...
    2018-09-14T08:36:29.7509765Z INFO : Temp folder exists.
    2018-09-14T08:36:29.7509765Z INFO : System Property Check: ValidTempDirectory - PASSED
    2018-09-14T08:36:29.8134765Z INFO : Running System Property Check: ValidServer ...
    2018-09-14T08:36:29.8134765Z INFO : System Property Check: ValidServer - PASSED
    2018-09-14T08:36:29.8759765Z INFO : Running System Property Check: ValidDeploymentInfo ...
    2018-09-14T08:36:29.8759765Z INFO : Current Time: 2018-09-14T08:36:29.875000
    2018-09-14T08:36:29.8759765Z INFO : This computer is part of the workgroup: WORKGROUP
    2018-09-14T08:36:29.8759765Z INFO : Domain Name: WORKGROUP
    2018-09-14T08:36:29.8759765Z INFO : Computer Name: rd-PC
    2018-09-14T08:36:29.8759765Z INFO : Computer Description is not available.
    2018-09-14T08:36:29.8759765Z INFO : Operating System: WIN7
    2018-09-14T08:36:29.8759765Z INFO : ProductType: 4
    2018-09-14T08:36:29.8759765Z INFO : Last logged on user was: rd-PC\\rd
    2018-09-14T08:36:29.8759765Z INFO : Fully Qualified Domain Name: rd-PC
    2018-09-14T08:36:29.8759765Z INFO : Processor architecture: x64
    2018-09-14T08:36:29.8759765Z INFO : OS Major Version: 6 and OS Minor Version: 1
    2018-09-14T08:36:29.8759765Z INFO : Friendly OS Name: WIN7
    2018-09-14T08:36:29.8759765Z INFO : Is server?: 0
    2018-09-14T08:36:29.8759765Z INFO : Sending HTTP 'POST' request to: sophos/management/ep/install/deployment-info
    2018-09-14T08:36:29.8916015Z WARNING : WinHttpGetProxyForUrl returned: 12180
    2018-09-14T08:36:29.8916015Z INFO : Attempting to connect using proxy '172.16.9.37:8190' of type 'Message Relay'.
    2018-09-14T08:36:29.8916015Z INFO : Set security protocol: 00000800
    2018-09-14T08:36:29.8916015Z INFO : Opening connection to mcs-cloudstation-eu-central-1.prod.hydra.sophos.com
    2018-09-14T08:36:29.8916015Z INFO : Sending request for connection confirmation through potential proxy
    2018-09-14T08:36:29.8916015Z INFO : Request content size: 0
    2018-09-14T08:36:30.8291015Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
    2018-09-14T08:36:31.7666015Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
    2018-09-14T08:36:31.7666015Z INFO : Certificate check succeeded
    2018-09-14T08:36:31.7666015Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
    2018-09-14T08:36:32.0478515Z INFO : Response status code: 200
    2018-09-14T08:36:32.0478515Z INFO : Response data size: 168
    2018-09-14T08:36:32.0478515Z INFO : trySendRequestThroughPotentialProxy returning response with status code: 200
    2018-09-14T08:36:32.0478515Z INFO : Request content size: 990
    2018-09-14T08:36:32.0478515Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
    2018-09-14T08:36:32.0634765Z INFO : Certificate check succeeded
    2018-09-14T08:36:32.0634765Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
    2018-09-14T08:36:32.3603515Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
    2018-09-14T08:36:32.3603515Z INFO : Certificate check succeeded
    2018-09-14T08:36:32.3603515Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
    2018-09-14T08:36:32.3603515Z INFO : Response status code: 200
    2018-09-14T08:36:32.3603515Z INFO : Response data size: 292
    2018-09-14T08:36:32.3603515Z INFO : Parsing message received for deployment token: {"registrationToken":"4002bdc3bb982ba93eea00d222c763ef0a9f8fc7bd8d0465a6831d1e28731188","products":[{"product":"ENDPOINT_ADVANCED","supported":true,"reasons":[]},{"product":"INTERCEPT","supported":true,"reasons":[]},{"product":"DEVICE_ENCRYPTION","supported":false,"reasons":["UNLICENSED"]}]}
    2018-09-14T08:36:32.3603515Z INFO : Model::token value changed to: 4002bdc3bb982ba93eea00d222c763ef0a9f8fc7bd8d0465a6831d1e28731188
    2018-09-14T08:36:32.3603515Z INFO : Licenses available: ENDPOINT_ADVANCED INTERCEPT
    2018-09-14T08:36:32.4384765Z INFO : Running System Property Check: InstallationInProgress ...
    2018-09-14T08:36:32.4384765Z INFO : System Property Check: InstallationInProgress - PASSED
    2018-09-14T08:36:32.5009765Z INFO : Running System Property Check: SafeGuardEncryption ...
    2018-09-14T08:36:32.5009765Z INFO : Entered installedProductCode, upgradeCode={BA2F47D3-1C17-40E7-8DE7-1CD733442B6C}
    2018-09-14T08:36:32.5009765Z INFO : Product is not installed
    2018-09-14T08:36:32.5009765Z INFO : licensesContainFeature(DEVICE_ENCRYPTION): false
    2018-09-14T08:36:32.5009765Z INFO : System Property Check: SafeGuardEncryption - PASSED
    2018-09-14T08:36:34.1103515Z INFO : Starting installation process.
    2018-09-14T08:36:34.1103515Z INFO : About to execute command: CompetitorDetector
    2018-09-14T08:36:34.1259765Z INFO : Command 'CompetitorDetector' completed with success with reboot code '0' and error message ''.
    2018-09-14T08:36:34.1259765Z INFO : About to execute command: Register
    2018-09-14T08:36:34.1259765Z INFO : Ensuring any MCS client service is stopped to prevent race for policy retrieval
    2018-09-14T08:36:34.1259765Z INFO : Sending HTTP 'POST' request to: sophos/management/ep/install/register
    2018-09-14T08:36:34.1416015Z WARNING : WinHttpGetProxyForUrl returned: 12180
    2018-09-14T08:36:34.1416015Z INFO : Attempting to connect using proxy '172.16.9.37:8190' of type 'Message Relay'.
    2018-09-14T08:36:34.1416015Z INFO : Set security protocol: 00000800
    2018-09-14T08:36:34.1416015Z INFO : Opening connection to mcs-cloudstation-eu-central-1.prod.hydra.sophos.com
    2018-09-14T08:36:34.1416015Z INFO : Sending request for connection confirmation through potential proxy
    2018-09-14T08:36:34.1416015Z INFO : Request content size: 0
    2018-09-14T08:36:34.1416015Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
    2018-09-14T08:36:34.1416015Z INFO : Certificate check succeeded
    2018-09-14T08:36:34.1416015Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
    2018-09-14T08:36:34.4384765Z INFO : Response status code: 200
    2018-09-14T08:36:34.4384765Z INFO : Response data size: 168
    2018-09-14T08:36:34.4384765Z INFO : trySendRequestThroughPotentialProxy returning response with status code: 200
    2018-09-14T08:36:34.4384765Z INFO : Request content size: 990
    2018-09-14T08:36:34.4384765Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
    2018-09-14T08:36:34.4541015Z INFO : Certificate check succeeded
    2018-09-14T08:36:34.4541015Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
    2018-09-14T08:36:34.9384765Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
    2018-09-14T08:36:34.9384765Z INFO : Certificate check succeeded
    2018-09-14T08:36:34.9384765Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
    2018-09-14T08:36:34.9541015Z INFO : Response status code: 200
    2018-09-14T08:36:34.9541015Z INFO : Response data size: 72
    2018-09-14T08:36:34.9541015Z INFO : Retrieved endpoint id: ae9c9961-1a97-340f-e9e1-fadc20de8f8d
    2018-09-14T08:36:35.9541015Z INFO : Sending HTTP 'PUT' request to: sophos/management/ep/install/statuses/endpoint/ae9c9961-1a97-340f-e9e1-fadc20de8f8d
    2018-09-14T08:36:35.9541015Z INFO : Request content size: 953
    2018-09-14T08:36:35.9541015Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
    2018-09-14T08:36:35.9541015Z INFO : Certificate check succeeded
    2018-09-14T08:36:35.9541015Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
    2018-09-14T08:36:36.2666015Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
    2018-09-14T08:36:36.2666015Z INFO : Certificate check succeeded
    2018-09-14T08:36:36.2666015Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
    2018-09-14T08:36:36.2666015Z INFO : Response status code: 200
    2018-09-14T08:36:36.2666015Z INFO : Response data size: 0
    2018-09-14T08:36:36.2666015Z INFO : Attempt to retrieve policy.
    2018-09-14T08:36:36.2666015Z INFO : Sending HTTP 'GET' request to: sophos/management/ep/install/commands/applications/APPSPROXY;ALC/endpoint/ae9c9961-1a97-340f-e9e1-fadc20de8f8d
    2018-09-14T08:36:36.2666015Z INFO : Request content size: 0
    2018-09-14T08:36:36.2666015Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
    2018-09-14T08:36:36.2666015Z INFO : Certificate check succeeded
    2018-09-14T08:36:36.2666015Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
    2018-09-14T08:36:36.5634765Z INFO : Response status code: 200
    2018-09-14T08:36:36.5634765Z INFO : Response data size: 725
    2018-09-14T08:36:36.5634765Z INFO : Successfully retrieved policy: commandID='23' policyId='214b2786fb2267fc6193edabbc295af4c7b5e1bfd8f7168fb75e99770ada8f00'.
    2018-09-14T08:36:36.5634765Z INFO : Sending HTTP 'DELETE' request to: sophos/management/ep/install/commands/endpoint/ae9c9961-1a97-340f-e9e1-fadc20de8f8d/23
    2018-09-14T08:36:36.5634765Z INFO : Request content size: 0
    2018-09-14T08:36:36.5634765Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
    2018-09-14T08:36:36.5634765Z INFO : Certificate check succeeded
    2018-09-14T08:36:36.5791015Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
    2018-09-14T08:36:36.8603515Z INFO : Response status code: 200
    2018-09-14T08:36:36.8603515Z INFO : Response data size: 0
    2018-09-14T08:36:36.8759765Z INFO : Sending HTTP 'GET' request to: sophos/management/ep/install/policy/application/ALC/214b2786fb2267fc6193edabbc295af4c7b5e1bfd8f7168fb75e99770ada8f00
    2018-09-14T08:36:36.8759765Z INFO : Request content size: 0
    2018-09-14T08:36:36.8759765Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
    2018-09-14T08:36:36.8759765Z INFO : Certificate check succeeded
    2018-09-14T08:36:36.8759765Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
    2018-09-14T08:36:37.2197265Z INFO : Response status code: 200
    2018-09-14T08:36:37.2197265Z INFO : Response data size: 7550
    2018-09-14T08:36:37.2197265Z INFO : Restarting any stopped services
    2018-09-14T08:36:37.2197265Z INFO : New SAU, assume obfuscated password
    2018-09-14T08:36:37.7353515Z INFO : Updating subscription created with id: Base, rigidname: WindowsCloudNextGen, baseversion: 11, tag: RECOMMENDED, fixedversion:
    2018-09-14T08:36:37.7353515Z INFO : Updating subscription created with id: Clean, rigidname: WindowsCloudClean, baseversion: 1, tag: RECOMMENDED, fixedversion:
    2018-09-14T08:36:37.7353515Z INFO : Updating subscription created with id: CloudAV, rigidname: WindowsCloudAV, baseversion: 11, tag: RECOMMENDED, fixedversion:
    2018-09-14T08:36:37.7353515Z INFO : Updating subscription created with id: HitmanProAlert, rigidname: WindowsCloudHitmanProAlert, baseversion: 1, tag: RECOMMENDED, fixedversion:
    2018-09-14T08:36:37.7353515Z INFO : Features: APPCNTRL
    2018-09-14T08:36:37.7353515Z INFO : Features: AV
    2018-09-14T08:36:37.7353515Z INFO : Features: CLEAN
    2018-09-14T08:36:37.7353515Z INFO : Features: CORE
    2018-09-14T08:36:37.7353515Z INFO : Features: DLP
    2018-09-14T08:36:37.7353515Z INFO : Features: DVCCNTRL
    2018-09-14T08:36:37.7353515Z INFO : Features: EFW
    2018-09-14T08:36:37.7509765Z INFO : Features: HBT
    2018-09-14T08:36:37.7509765Z INFO : Features: NTP
    2018-09-14T08:36:37.7509765Z INFO : Features: SAV
    2018-09-14T08:36:37.7509765Z INFO : Features: SDU
    2018-09-14T08:36:37.7509765Z INFO : Features: WEBCNTRL
    2018-09-14T08:36:37.7509765Z INFO : Features: XPD
    2018-09-14T08:36:37.7509765Z INFO : Setting https download to: false
    2018-09-14T08:36:37.7509765Z INFO : Updating credentials created with username: V38S16CDYX
    2018-09-14T08:36:37.7509765Z INFO : Command 'Register' completed with success with reboot code '0' and error message ''.
    2018-09-14T08:36:37.7509765Z INFO : About to execute command: Download
    2018-09-14T08:36:37.7509765Z INFO : Update Cache Cert Path folder: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
    2018-09-14T08:36:37.7509765Z INFO : About to create directory: C:\\ProgramData\\Sophos\\CloudInstaller\\AutoUpdatePreparation\\Cache\\decoded
    2018-09-14T08:36:37.7509765Z INFO : Created directory: C:\\ProgramData\\Sophos\\CloudInstaller\\AutoUpdatePreparation\\Cache\\decoded
    2018-09-14T08:36:37.7509765Z INFO : About to set security DACL on: C:\\ProgramData\\Sophos\\CloudInstaller\\AutoUpdatePreparation\\Cache\\decoded
    2018-09-14T08:36:37.7509765Z INFO : Set security DACL on: C:\\ProgramData\\Sophos\\CloudInstaller\\AutoUpdatePreparation\\Cache\\decoded
    2018-09-14T08:36:37.7509765Z INFO : About to create directory: C:\\ProgramData\\Sophos\\CloudInstaller\\AutoUpdatePreparation\\data\\Warehouse
    2018-09-14T08:36:37.7509765Z INFO : Created directory: C:\\ProgramData\\Sophos\\CloudInstaller\\AutoUpdatePreparation\\data\\Warehouse
    2018-09-14T08:36:37.7509765Z INFO : About to set security DACL on: C:\\ProgramData\\Sophos\\CloudInstaller\\AutoUpdatePreparation\\data
    2018-09-14T08:36:37.7509765Z INFO : Set security DACL on: C:\\ProgramData\\Sophos\\CloudInstaller\\AutoUpdatePreparation\\data
    2018-09-14T08:36:37.7509765Z INFO : About to create directory: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
    2018-09-14T08:36:37.7509765Z INFO : Created directory: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
    2018-09-14T08:36:37.7509765Z INFO : About to set security DACL on: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
    2018-09-14T08:36:37.7509765Z INFO : Set security DACL on: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
    2018-09-14T08:36:37.7509765Z INFO : Update Cache Cert Path folder: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
    2018-09-14T08:36:37.7509765Z INFO : Update Cache Cert Path folder: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
    2018-09-14T08:36:37.7509765Z INFO : Writing cert: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache\\24a3ac9789d050935f40e5cb1611b56afe7c9c16.crt.crt
    2018-09-14T08:36:37.7509765Z INFO : Writing cert: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache\\51311cf9fe97724798d65f69c97c968e4b783f47.crt.crt
    2018-09-14T08:36:37.7509765Z INFO : Writing cert: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache\\ef3f816368de8e7e109f5ecbb29abdcc306c6bfc.crt.crt
    2018-09-14T08:36:37.7509765Z INFO : Analyzing whether to update from Sophos CDN or update cache
    2018-09-14T08:36:37.7509765Z INFO : Checking access to update cache: sophoscache:8191
    2018-09-14T08:36:37.7509765Z INFO : Updating configured to use: HTTPS
    2018-09-14T08:36:37.7509765Z INFO : Update Cache Cert Path folder: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
    2018-09-14T08:37:04.9384765Z INFO : Could not reach cache
    2018-09-14T08:37:04.9384765Z INFO : Analysis complete - Using Sophos CDN
    2018-09-14T08:37:04.9384765Z WARNING : WinHttpGetProxyForUrl returned: 12180
    2018-09-14T08:37:04.9384765Z INFO : Updating configured to use: HTTP
    2018-09-14T08:37:04.9384765Z INFO : Initial download: attempting to use bulk metadata
    2018-09-14T08:37:04.9384765Z INFO : Calling SULDownloader addGlobalFilter...
    2018-09-14T08:37:04.9384765Z INFO : Subscription: Base
    2018-09-14T08:37:04.9384765Z INFO : SUL info: [V46381] SU::Handle::readRemoteMetadata + SU::Handle::readRemoteMetadata()
    2018-09-14T08:37:04.9384765Z INFO : SUL info: [V75884] SU::Metadata::readRemoteMetadata SU::Metadata::readRemoteMetadata()
    2018-09-14T08:37:04.9384765Z INFO : SUL info: [I40394] Downloading customer file from sophos:1:1
    2018-09-14T08:37:04.9384765Z INFO : SUL info: [V81533] SU::createCachedPackageSource creating cached package source for sophos:1:1: url=sophos
    2018-09-14T08:37:04.9384765Z INFO : SUL info: [V81533] SU::createCachedPackageSource creating http_source_specific_data to download customer file
    2018-09-14T08:37:04.9384765Z INFO : SUL info: [V81533] SU::createCachedPackageSource creating package source to download customer file
    2018-09-14T08:38:21.0009765Z WARNING : SUL error: [E26245] 502 Connection refused: dci.sophosupd.com/.../5524ebf979804dbe786bd09d13c6df8c.dat
    2018-09-14T08:38:21.0009765Z INFO : SUL info: [I26245] No proxy was used.
    2018-09-14T08:38:21.0009765Z INFO : SUL info: [I40394] Downloading customer file from sophos:2:1
    2018-09-14T08:38:21.0009765Z INFO : SUL info: [V81533] SU::createCachedPackageSource creating cached package source for sophos:2:1: url=sophos
    2018-09-14T08:38:21.0009765Z INFO : SUL info: [V81533] SU::createCachedPackageSource creating http_source_specific_data to download customer file
    2018-09-14T08:38:21.0009765Z INFO : SUL info: [V81533] SU::createCachedPackageSource creating package source to download customer file
    2018-09-14T08:39:36.9287109Z WARNING : SUL error: [E26245] 502 Connection refused: dci.sophosupd.net/.../5524ebf979804dbe786bd09d13c6df8c.dat
    2018-09-14T08:39:36.9287109Z INFO : SUL info: [I26245] No proxy was used.
    2018-09-14T08:39:36.9287109Z INFO : SUL info: [I40394] Downloading customer file from sophos:3:1
    2018-09-14T08:39:36.9287109Z INFO : SUL info: [V81533] SU::createCachedPackageSource creating cached package source for sophos:3:1: url=sophos
    2018-09-14T08:39:36.9287109Z INFO : SUL info: [V81533] SU::createCachedPackageSource creating http_source_specific_data to download customer file
    2018-09-14T08:39:36.9287109Z INFO : SUL info: [V81533] SU::createCachedPackageSource creating package source to download customer file
    2018-09-14T08:39:36.9287109Z WARNING : SUL error: [E75373] Ran out of sophos aliases for this update source
    2018-09-14T08:39:36.9287109Z WARNING : SUL error: [E35369] Out of update sources
    2018-09-14T08:39:36.9287109Z WARNING : SUL error: [E99999] Out of sources
    2018-09-14T08:39:36.9287109Z ERROR : DownloadCommand::onRun() failed with std::exception: MetaDataScope::MetaDataScope failed with error code 4
    2018-09-14T08:39:36.9287109Z INFO : Command 'Download' completed with failure with reboot code '0' and error message 'Could not download software'.
    2018-09-14T08:39:36.9287109Z ERROR : Installation failed.
    2018-09-14T08:39:36.9287109Z INFO : Sending HTTP 'POST' request to: sophos/management/ep/install/events/endpoint/ae9c9961-1a97-340f-e9e1-fadc20de8f8d
    2018-09-14T08:39:36.9443359Z WARNING : WinHttpGetProxyForUrl returned: 12180
    2018-09-14T08:39:36.9443359Z INFO : Attempting to connect using proxy '172.16.9.37:8190' of type 'Message Relay'.
    2018-09-14T08:39:36.9443359Z INFO : Set security protocol: 00000800
    2018-09-14T08:39:36.9443359Z INFO : Opening connection to mcs-cloudstation-eu-central-1.prod.hydra.sophos.com
    2018-09-14T08:39:36.9443359Z INFO : Sending request for connection confirmation through potential proxy
    2018-09-14T08:39:36.9443359Z INFO : Request content size: 0
    2018-09-14T08:39:36.9443359Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
    2018-09-14T08:39:37.8349609Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
    2018-09-14T08:39:37.8349609Z INFO : Certificate check succeeded
    2018-09-14T08:39:37.8349609Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
    2018-09-14T08:39:38.1318359Z INFO : Response status code: 200
    2018-09-14T08:39:38.1318359Z INFO : Response data size: 168
    2018-09-14T08:39:38.1318359Z INFO : trySendRequestThroughPotentialProxy returning response with status code: 200
    2018-09-14T08:39:38.1318359Z INFO : Request content size: 1135
    2018-09-14T08:39:38.1318359Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
    2018-09-14T08:39:38.1318359Z INFO : Certificate check succeeded
    2018-09-14T08:39:38.1318359Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
    2018-09-14T08:39:38.4912109Z INFO : ValidateFileCertificateCheck: Validate certificate against file on WINHTTP_CALLBACK_STATUS_SENDING_REQUEST
    2018-09-14T08:39:38.5068359Z INFO : Certificate check succeeded
    2018-09-14T08:39:38.5068359Z INFO : ValidateFileCertificateCheck: Ignore WINHTTP_CALLBACK_STATUS_REQUEST_SENT
    2018-09-14T08:39:38.5068359Z INFO : Response status code: 200
    2018-09-14T08:39:38.5068359Z INFO : Response data size: 0
    2018-09-14T08:40:24.7568359Z INFO : Data folder: C:\\ProgramData\\Sophos\\AutoUpdate\\data
    2018-09-14T08:40:24.7568359Z INFO : Data folder: C:\\ProgramData\\Sophos\\AutoUpdate\\data
    2018-09-14T08:40:24.7568359Z INFO : Sending HTTP 'PUT' request to: prod/2018-09-14T08:40:24Z-2018-09-14T08:40:24Z-1652f2a1-a31e-577a-9539-41fb404688ed.json
    2018-09-14T08:40:24.7568359Z WARNING : WinHttpGetProxyForUrl returned: 12180
    2018-09-14T08:40:24.7568359Z INFO : Attempting to connect using proxy '172.16.9.37:8190' of type 'Message Relay'.
    2018-09-14T08:40:24.7724609Z INFO : Set security protocol: 00000800
    2018-09-14T08:40:24.7724609Z INFO : Opening connection to t1.sophosupd.com
    2018-09-14T08:40:24.7724609Z INFO : Request content size: 2540
    2018-09-14T08:40:24.7724609Z INFO : Request sent
    2018-09-14T08:40:25.2568359Z INFO : Sending request
    2018-09-14T08:40:25.2568359Z INFO : Request sent
    2018-09-14T08:40:25.5537109Z INFO : Sending request
    2018-09-14T08:40:25.5537109Z INFO : Request sent
    2018-09-14T08:40:25.5537109Z INFO : Response status code: 200
    2018-09-14T08:40:25.5537109Z INFO : Response data size: 0
    2018-09-14T08:40:25.5537109Z INFO : trySendRequestThroughPotentialProxy returning response with status code: 200
    2018-09-14T08:40:25.5693359Z INFO : Telemetry Response:
    2018-09-14T08:40:25.5693359Z INFO : User profile unloaded
    2018-09-14T08:40:25.5849609Z INFO : Cleaning up extracted files
    2018-09-14T08:40:25.6005859Z ERROR : Exception: Setup program failed with code: 1

     

  • Hello ecompo ,

    Are you using a UTM ? If yes, please try these steps first

    From your log:

    2018-09-14T08:36:37.7509765Z INFO : Checking access to update cache: sophoscache:8191
    2018-09-14T08:36:37.7509765Z INFO : Updating configured to use: HTTPS
    2018-09-14T08:36:37.7509765Z INFO : Update Cache Cert Path folder: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
    2018-09-14T08:37:04.9384765Z INFO : Could not reach cache

    Can you please review this documentation and ensure your cache/relay is properly set up?
    Can you reach the server from the affected computer?


    Regards,

    Barb@Sophos
    Community Support Engineer | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

     

  • Hi Barb thanks for replying.

     

    No Sophos UTM is involved. 

     

    In fact, we have a Sophos XG in our environment and caching is off.

    We have checked with both customers that caching feature is off as well on their gateway appliance. 

  • Hi ecompo,

    Thank you for the update.

    Could you please try these and post the outcome?:

    Can you please review this documentation and ensure your cache/relay is properly set up?
    Can you reach the server from the affected computer?

    Regards,

    Barb@Sophos
    Community Support Engineer | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

     

  • Hi ecompo,

    Thank you for the update.

    Could you please try these and post the outcome?:

    Can you please review this documentation and ensure your cache/relay is properly set up?
    Can you reach the server from the affected computer?

    Regards,

     

     

    We have eliminated networking issue. The communications between client PC and the cache server is fine. In fact we even verified it with wireshark  and netstat. TCP handshake was completed and session established. Sophos Installer would fail midway through installation and produce error logs I provided earlier. This is happening in my lab and 2 of my customers' environment.

    Let me know if you need more information.

  • Hi ecompo,

    Per your logs:
    2018-09-14T08:36:37.7509765Z INFO : Update Cache Cert Path folder: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
    2018-09-14T08:37:04.9384765Z INFO : Could not reach cache

    Per your previous screenshots, looks like the relay is fine, but have you checked the cache and ensured that port 8191  is accessible?
    If your cache is correctly set up as per this documentation , then I would recommend to check if the cache server is healthy and updated, and if needed reinstall the cache,  and retry the endpoint installation.

    If the issues persist, please file a case with support for further investigation.

    Thank you

    Barb@Sophos
    Community Support Engineer | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

     

  • Hi ecompo,

    Per your logs:
    2018-09-14T08:36:37.7509765Z INFO : Update Cache Cert Path folder: C:\\ProgramData\\Sophos\\Certificates\\AutoUpdate\\Cache
    2018-09-14T08:37:04.9384765Z INFO : Could not reach cache

    Per your previous screenshots, looks like the relay is fine, but have you checked the cache and ensured that port 8191  is accessible?
    If your cache is correctly set up as per this documentation , then I would recommend to check if the cache server is healthy and updated, and if needed reinstall the cache,  and retry the endpoint installation.

    If the issues persist, please file a case with support for further investigation.

    Thank you

     

    8191 and 8190 are accessible and listening on the cache server. No firewall in between clients and the cache server.

    The cache server is healthy and endpoints can successfully update from cache server.

    Our issue is that for those endpoints that do not have internet access are unable to install from cache server.

  • Hello ecompo,

    Thank you for the update. Are there any network differences between the computers that can update from the cache VS. the ones that cannot reach it?  (Or is it just the fact that they have internet access? Can you please confirm that the other machines are updating from the cache and not the internet? ) .

    Please check that Port 8190 and 8191 are available and accessible to computers that will update from the cache and use the relays.

    If the above doesn't help solving the problem, I recommend to file a case with support for further investigation. (If you do file a case, please send me a PM with the ticket number so that we can follow-up). 

    Regards,

     

    Barb@Sophos
    Community Support Engineer | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

     

  •  

     

    We've just opened a ticket #8370060. 

    Below is our problem description: 

    We have setup cache server and message relays on a Windows Server 2008 R2. We followed this guide, https://docs.sophos.com/central/Customer/help/en-us/central/Customer/concepts/UpdateCaches.html, to complete the setup.

     

    We observed that existing endpoint would automatically get their updates from the cache server but the messages between endpoint and the central dashboard is not relaying through the same server even after confirming message relay is up and running via services.msc.

    1. Endpoints are able to update from cache server.
    2. Endpoints are not able to message relay, including cache server itself.
    3. Message Relays service is up and running and restarting the service doesn’t resolve the issue.
    4. Manual assignment forcing endpoint using relay doesn’t resolve the issue.  
    5. Can confirm the following firewall rules:
      1. Inbound: TCP 8190, 8191 Allow
      2. Outbound: TCP 80, 443 Allow
    6. DNS name resolutions is working fine.
    7. Network routing is fine.
    8. Removing and reinstalling Cache Server, Message Relays, and Sophos Central Agent doesn’t help either.

     

    From an endpoint’s \ProgramData\Sophos\Management Communications System\Endpoint\Logs\McsClient.log, we see the endpoint has the correct FQDN and port number for message relay:

    2018-09-20T01:06:17.235Z [ 7724] INFO  [connect] trying server https://mcs-cloudstation-eu-central-1.prod.hydra.sophos.com/sophos/management/ep

    2018-09-20T01:06:17.235Z [ 7724] INFO  [connect: configured message relay] trying message relay sophoscache.domain.local:8190

     

    But for unknown reason failing to get WinHttpReeceiveResponse, then proceed to configure a proxy and fail for the same reason again.

    2018-09-20T01:06:17.859Z [ 7724] ERROR Request: WinHttpReceiveResponse failed: 12152 (mcs-cloudstation-eu-central-1.prod.hydra.sophos.com:443)

    2018-09-20T01:06:17.859Z [ 7724] INFO  GET https://mcs-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep

    2018-09-20T01:06:17.875Z [ 7724] ERROR Request: WinHttpReceiveResponse failed: 12152 (mcs-cloudstation-eu-central-1.prod.hydra.sophos.com:443)

    2018-09-20T01:06:17.875Z [ 7724] INFO  [connect: configured proxy] trying proxy http://192.168.1.209:8190

    2018-09-20T01:06:17.875Z [ 7724] INFO  GET https://mcs-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep

    2018-09-20T01:06:17.875Z [ 7724] ERROR Request: WinHttpReceiveResponse failed: 12152 (mcs-cloudstation-eu-central-1.prod.hydra.sophos.com:443)

     

     

    From the Cache Server’s \ProgramData\Sophos\MessageRelay\Logs\httpd.log, we have many of the following entry:

     

    [2018-09-21 09:29:23.831526] [69308:121368] error: [access_compat:mod_access_compat.c(347)] [client=192.168.1.209:60873] [server=192.168.1.209:8190] [R:W6RJc8CoAdEAAQ68HeEAADqO] [C:5rLLkf84PVw] AH01797: client denied by server configuration: proxy:dci.sophosupd.com:443

     

    Note: 192.168.1.209 is the ip of the cache server.

     

    Not even the cache server itself is using the message relay. We suspect there’s a misconfiguration with the httpd services preventing endpoints relaying through 192.168.1.209:8190 but there’s so little reference for direction to identify the real cause.

     

    We looked into \ProgramData\Sophos\MessageRelay\Config\config.xml and we noticed a proxy setting has been configured even though no proxy is running on the cache server itself.

    <proxy>

            <location>192.168.1.209:8190</location>

            <credentials>xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx</credentials>

          </proxy>

     

    We have eliminated possibility for networking misconfiguration, please kindly give us some advice to identify the root cause for our issue.

Reply
  •  

     

    We've just opened a ticket #8370060. 

    Below is our problem description: 

    We have setup cache server and message relays on a Windows Server 2008 R2. We followed this guide, https://docs.sophos.com/central/Customer/help/en-us/central/Customer/concepts/UpdateCaches.html, to complete the setup.

     

    We observed that existing endpoint would automatically get their updates from the cache server but the messages between endpoint and the central dashboard is not relaying through the same server even after confirming message relay is up and running via services.msc.

    1. Endpoints are able to update from cache server.
    2. Endpoints are not able to message relay, including cache server itself.
    3. Message Relays service is up and running and restarting the service doesn’t resolve the issue.
    4. Manual assignment forcing endpoint using relay doesn’t resolve the issue.  
    5. Can confirm the following firewall rules:
      1. Inbound: TCP 8190, 8191 Allow
      2. Outbound: TCP 80, 443 Allow
    6. DNS name resolutions is working fine.
    7. Network routing is fine.
    8. Removing and reinstalling Cache Server, Message Relays, and Sophos Central Agent doesn’t help either.

     

    From an endpoint’s \ProgramData\Sophos\Management Communications System\Endpoint\Logs\McsClient.log, we see the endpoint has the correct FQDN and port number for message relay:

    2018-09-20T01:06:17.235Z [ 7724] INFO  [connect] trying server https://mcs-cloudstation-eu-central-1.prod.hydra.sophos.com/sophos/management/ep

    2018-09-20T01:06:17.235Z [ 7724] INFO  [connect: configured message relay] trying message relay sophoscache.domain.local:8190

     

    But for unknown reason failing to get WinHttpReeceiveResponse, then proceed to configure a proxy and fail for the same reason again.

    2018-09-20T01:06:17.859Z [ 7724] ERROR Request: WinHttpReceiveResponse failed: 12152 (mcs-cloudstation-eu-central-1.prod.hydra.sophos.com:443)

    2018-09-20T01:06:17.859Z [ 7724] INFO  GET https://mcs-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep

    2018-09-20T01:06:17.875Z [ 7724] ERROR Request: WinHttpReceiveResponse failed: 12152 (mcs-cloudstation-eu-central-1.prod.hydra.sophos.com:443)

    2018-09-20T01:06:17.875Z [ 7724] INFO  [connect: configured proxy] trying proxy http://192.168.1.209:8190

    2018-09-20T01:06:17.875Z [ 7724] INFO  GET https://mcs-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep

    2018-09-20T01:06:17.875Z [ 7724] ERROR Request: WinHttpReceiveResponse failed: 12152 (mcs-cloudstation-eu-central-1.prod.hydra.sophos.com:443)

     

     

    From the Cache Server’s \ProgramData\Sophos\MessageRelay\Logs\httpd.log, we have many of the following entry:

     

    [2018-09-21 09:29:23.831526] [69308:121368] error: [access_compat:mod_access_compat.c(347)] [client=192.168.1.209:60873] [server=192.168.1.209:8190] [R:W6RJc8CoAdEAAQ68HeEAADqO] [C:5rLLkf84PVw] AH01797: client denied by server configuration: proxy:dci.sophosupd.com:443

     

    Note: 192.168.1.209 is the ip of the cache server.

     

    Not even the cache server itself is using the message relay. We suspect there’s a misconfiguration with the httpd services preventing endpoints relaying through 192.168.1.209:8190 but there’s so little reference for direction to identify the real cause.

     

    We looked into \ProgramData\Sophos\MessageRelay\Config\config.xml and we noticed a proxy setting has been configured even though no proxy is running on the cache server itself.

    <proxy>

            <location>192.168.1.209:8190</location>

            <credentials>xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx</credentials>

          </proxy>

     

    We have eliminated possibility for networking misconfiguration, please kindly give us some advice to identify the root cause for our issue.

Children
  • Hi ecompo,

    At this point, it will better to allow Sophos Support side to review the full logs for further steps.

    However, here are some additional suggestions if you wish to try them:

    Use telnet via one of the affected systems:
    Open a command prompt and telnet 192.168.1.209:8191

    You mentioned you are behind a Sophos XG firewall, is ssl scanning enabled?
    We can have an XG tech review the configuration for your XG firewall. Enable remote access using this article and send me a Private Message with the Access ID, as well as the results from running Telnet.

    We are going to lock this thread as some of the replies are not related and contain different issues. Ideally, we strive to have 1 issue per thread, so that everything is easier to read. If needed, we can work with you to create a new thread for your particular problem. Please, send me all the information via Private message so that we can continue assisting you.

    Thank you!

    Barb@Sophos
    Community Support Engineer | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.