Sophos Transparent Authenication Suite 2.5.1.0 STA service wont start

I have installed Sophos Transparent Authenication Suite 2.5.1.0
Where i have followed the guide online on how to configure - https://community.sophos.com/kb/en-us/133531
We have 3 sites with 3 x Sophos XG. 1 site is already running fine with STA.
The other 2 sites (with their own DCs) cannot start the service. User is a domain admin and has logon as local service right


The error i get in the event log is
Faulting application name: stas.exe, version: 2.5.1.0, time stamp: 0x5ddc0897
Faulting module name: stas.exe, version: 2.5.1.0, time stamp: 0x5ddc0897
Exception code: 0xc0000005
Fault offset: 0x00007532
Faulting process id: 0x18cc
Faulting application start time: 0x01d5d231e88fa7b9
Faulting application path: C:\Program Files (x86)\Sophos\Sophos Transparent Authentication Suite\stas.exe
Faulting module path: C:\Program Files (x86)\Sophos\Sophos Transparent Authentication Suite\stas.exe
Report Id: 2645431d-3e25-11ea-8113-000c2911f4e3
Faulting package full name:
Faulting package-relative application ID:

 

I've already logged a case with Sophos - which has been unhelpful thus far.

Any ideas anyone? Thanks in advance

  • I had this issue on one of my DCs a while ago.

    I ended up removing STAS and checked it removed the STAS service also.

     

    Then rebooted and reinstalled STAS and was careful to use a user I created to run the service and STAS.

    So domain\STAS (I created STAS as a domain admin)

     

    Then saved it - service started - then went in and configured all the settings.

    The reboot between install and removal kind of fixed it.

  • Hi  

    Could you please go to Services >> and Open STAS service properties and check click on "logon" and insert domain\administrator credentials and try to restart the service.

  • In reply to M8ey:

    I did the same. Full removal > reboot > reinstall > failed to start service.

    Thanks anyway M8ey

  • In reply to Keyur:

    I'm not sure you read my description correctly..

  • In reply to neckbeard:

    neckbeard
    Full removal > reboot > reinstall > failed to start service

    Bummer - hate it when stuff just wont go.

     

    Another thing (reaching now) is to uninstall then delete all registry keys under HKLM\SOFTWARE\Wow6432Node\Sophos

    Reboot and go again - might be a corrupt registry key remaining after uninstall.

    Maybe try creating AD user called "STAS" or similar and giving it User Rights to logon as a Service and then set that Service to run as the new user.  See below guide about half way down.

     

    https://community.sophos.com/kb/en-us/133531

     

    Sorry I cant really help - just pointing out stuff you may have tried already :-)

  • In reply to neckbeard:

    Hi  

    What does windows event log state when the service tries to start?

    Can you post an excerpt of the STAS log file here?

    Thanks.

  • In reply to KingChris:

    Please see original post - i did a copy and paste there of the event log

     

    STA log = 

    MSG [0x1e48] 29/01/2020 07:53:01 : --------------------------------------------------------------------

    MSG [0x1e48] 29/01/2020 07:53:01 : ----------- Sophos TRANSPARENT AUTHENTICATION SUITE --------------

    MSG [0x1e48] 29/01/2020 07:53:01 : --------------------------------------------------------------------

    MSG [0x1e48] 29/01/2020 07:53:01 : --------------------------------------------------------------------

    MSG [0x1e48] 29/01/2020 07:53:01 : -------------------------- Logging Events --------------------------

    MSG [0x1e48] 29/01/2020 07:53:01 : --------------------------------------------------------------------

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_configfile: SectionName:

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_configfile: SectionName:

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_settings: Key: THREADPOOL-SIZE

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_settings: Value: 64

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_settings: Threadpool Size: 64

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_settings: Key: HOST-DOMAIN

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_settings: Value: 102'0'107'0'

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_settings: Host Domain: fk

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_settings: Key: HOST-DOMAIN-FQDN

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_settings: Value: 102'0'107'0'46'0'105'0'110'0'116'0'101'0'114'0'110'0'97'0'108'0'

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_settings: Host Domain (FQDN): fk.internal

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_settings: Key: DOMAIN-TYPE

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_settings: Value: MSAD

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_settings: Domain Type : fk.internal

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_configfile: SectionName:

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_dca: Key: ENABLED

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_dca: Value: TRUE

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_dca: DC Agent to be Enabled

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_dca: Key: DCA-MODE

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_dca: Value: EVENTLOG

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_dca: dca_mode to be EVENTLOG

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_dca: Key: SERVER-IP

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_dca: Value: 192.168.1.1

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_dca: SERVER-IP: 192.168.1.1

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_dca: Key: SERVER-PORT

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_dca: Value: 5566

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_dca: SERVER-PORT: 5566

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_configfile: SectionName:

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_cidmgr: Key: ENABLED

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_cidmgr: Value: TRUE

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_cidmgr: CID Manager to be Enabled

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_cidmgr: Key: POLLING-MODE

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_cidmgr: Value: WMI

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_cidmgr: POLLING-MODE to be WMI

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_cidmgr: Key: DCASERVER-PORT

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_cidmgr: Value: 5566

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_cidmgr: DCASERVER-PORT: 5566

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_cidmgr: Key: TSSO-SERVER-PORT

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_cidmgr: Value: 6677

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_cidmgr: TSSO-SERVER-PORT: 6677

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_cidmgr: Key: DEAD-ENTRY-TIMEOUT

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_cidmgr: Value: 0

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_cidmgr: DEAD-ENTRY-TIMEOUT: 0

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_configfile: SectionName:

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logoffdetect: Key: ENABLED

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logoffdetect: Value: TRUE

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logoffdetect: Logoff Detector to be Enabled

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logoffdetect: Key: DETECTION-MODE

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logoffdetect: Value: WORKSTATION-POLL

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logoffdetect: DETECTION-MODE to be WORKSTATION-POLL

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logoffdetect: Key: DETECTION-INTERVAL

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logoffdetect: Value: 605

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logoffdetect: DETECTION-INTERVAL: 605

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logoffdetect: Key: DETECTION-RETRY

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logoffdetect: Value: 3

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logoffdetect: DETECTION-RETRY: 3

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_configfile: SectionName:

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logging: Key: LOG-LEVEL

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logging: Value: 5

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logging: LOG-LEVEL: 5

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logging: Key: BUFFER-SIZE

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logging: Value: 10485760

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logging: BUFFER-SIZE: 10485760

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logging: Key: LOGGING-EVENTS-BUFFER-SIZE

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logging: Value: 10485760

    MSG [0x1e48] 29/01/2020 07:53:01 : parse_keyvalue_logging: LOGGING-EVENTS-BUFFER-SIZE: 10485760

    MSG [0x1e48] 29/01/2020 07:53:01 : dca_set_hostdomain: Host Domain set to 'fk'

    MSG [0x1e48] 29/01/2020 07:53:01 : dca_set_hostdomain: Host Domain (FQDN) set to 'fk.internal'

    MSG [0x1e48] 29/01/2020 07:53:01 : config_parse_namefile: parsing NameFile: C:\Program Files (x86)\Sophos\Sophos Transparent Authentication Suite\dc-list.ini

    MSG [0x1e48] 29/01/2020 07:53:01 : config_print_dclist: DC NameList is Empty

    MSG [0x1e48] 29/01/2020 07:53:01 : config_postinit: Threadpool Size Reset to '64' threads

    MSG [0x1e48] 29/01/2020 07:53:01 : config_parse_namefile: parsing NameFile: C:\Program Files (x86)\Sophos\Sophos Transparent Authentication Suite\cr-list.ini

    MSG [0x1e48] 29/01/2020 07:53:01 : config_parse_namefile: Read Data Is Available : 172.16.2.126


    MSG [0x1e48] 29/01/2020 07:53:01 : config_add_names: buffer: 172.16.2.126
    MSG [0x1e48] 29/01/2020 07:53:01 : config_add_names: buffer: 172.16.2.126....

    MSG [0x1e48] 29/01/2020 07:53:01 : config_add_names: buffer : 172.16.2.126, Name Type: 3

    MSG [0x1e48] 29/01/2020 07:53:01 : config_addcr_crlist: XG:172.16.2.126:(null)#(null)/(null)

    MSG [0x1e48] 29/01/2020 07:53:01 : config_addcr_crlist: No subnet and mask provided

    MSG [0x1e48] 29/01/2020 07:53:01 : config_addcr_crlist: Subnet/Netmask: 0x00000000/0x00000000

    MSG [0x1e48] 29/01/2020 07:53:01 : config_addcr_crlist: XG '172.16.2.126' added to CR List

    MSG [0x1e48] 29/01/2020 07:53:01 : config_add_names: buffer: 172.16.2.126
    MSG [0x1e48] 29/01/2020 07:53:01 : --------------- XG NAME LIST -----------------

    MSG [0x1e48] 29/01/2020 07:53:01 : CR[0] : 172.16.2.126:0

    MSG [0x1e48] 29/01/2020 07:53:01 : ----------------------------------------------

    MSG [0x1e48] 29/01/2020 07:53:01 : config_parse_namefile: parsing NameFile: C:\Program Files (x86)\Sophos\Sophos Transparent Authentication Suite\authnet-list.ini

    MSG [0x1e48] 29/01/2020 07:53:01 : config_parse_namefile: Read Data Is Available : 172.16.2.0/24


    MSG [0x1e48] 29/01/2020 07:53:01 : config_add_names: buffer: 172.16.2.0/24
    MSG [0x1e48] 29/01/2020 07:53:01 : config_add_names: buffer: 172.16.2.0/24....

    MSG [0x1e48] 29/01/2020 07:53:01 : config_add_names: buffer : 172.16.2.0/24, Name Type: 4

    MSG [0x1e48] 29/01/2020 07:53:01 : dca_addnet_authnetlist: AuthNetwork: 172.16.2.0/24

    MSG [0x1e48] 29/01/2020 07:53:01 : dca_addnet_authnetlist: Netmask: 0xffffff00

    MSG [0x1e48] 29/01/2020 07:53:01 : dca_addnet_authnetlist: Subnet: 0xac100200

    MSG [0x1e48] 29/01/2020 07:53:01 : config_add_names: buffer: 172.16.2.0
    MSG [0x1e48] 29/01/2020 07:53:01 : -------------------- AUTH NETWORK LIST --------------------------

    MSG [0x1e48] 29/01/2020 07:53:01 : SUBNET[0]: 0xac100200 <-> SUBNET-MASK[0]: 0xffffff00

    MSG [0x1e48] 29/01/2020 07:53:01 : -----------------------------------------------------------------

    MSG [0x1e48] 29/01/2020 07:53:01 : config_parse_namefile: parsing NameFile: C:\Program Files (x86)\Sophos\Sophos Transparent Authentication Suite\logoff-exclusion-list.ini

    MSG [0x1e48] 29/01/2020 07:53:01 : dca_print_ipexcllist: IP Exclusion List is Empty

    DEBUG [0x1e48] 29/01/2020 07:53:01 : dca_print_authnetlist: AuthNetwork List is Empty

    MSG [0x1e48] 29/01/2020 07:53:01 : config_parse_namefile: parsing NameFile: C:\Program Files (x86)\Sophos\Sophos Transparent Authentication Suite\login-ip-exclusion-list.ini

    MSG [0x1e48] 29/01/2020 07:53:01 : dca_print_ipexcllist: IP Exclusion List is Empty

    MSG [0x1e48] 29/01/2020 07:53:01 : dca_print_authnetlist: AuthNetwork List is Empty

    ERROR [0x1e48] 29/01/2020 07:53:01 : config_parse_namefile: file C:\Program Files (x86)\Sophos\Sophos Transparent Authentication Suite\domain-list.ini couldn't open: 2

    MSG [0x1e48] 29/01/2020 07:53:01 : dca_print_domainlist: Monitored Domain List is Empty

    MSG [0x1e48] 29/01/2020 07:53:01 : config_parse_unicode_namefile: parsing NameFile: C:\Program Files (x86)\Sophos\Sophos Transparent Authentication Suite\user-exclusion-list.ini

    MSG [0x1e48] 29/01/2020 07:53:01 : dca_print_userexcllist: User Exclusion List is Empty

    MSG [0x1e48] 29/01/2020 07:53:01 : config_parse_namefile: parsing NameFile: C:\Program Files (x86)\Sophos\Sophos Transparent Authentication Suite\coll-list.ini

    MSG [0x1e48] 29/01/2020 07:53:01 : config_print_crlist: XG NameList is Empty

    DEBUG [0x1e48] 29/01/2020 07:53:01 : Starting the service configuration is done now..

    INFO [0x1e48] 29/01/2020 07:53:01 : stas_init: configuration file parsed successfully

    DEBUG [0x1e48] 29/01/2020 07:53:01 : userdb_open_db: USERDB 'C:\Program Files (x86)\Sophos\Sophos Transparent Authentication Suite\stas.db3' opened successfully

    DEBUG [0x1e48] 29/01/2020 07:53:01 : userdb_create_table: create table query: CREATE TABLE IF NOT EXISTS UserInfo (rowid INTEGER PRIMARY KEY AUTOINCREMENT, user TEXT DEFAULT NULL, domain TEXT DEFAULT NULL, usergroup TEXT DEFAULT NULL, wrkst_name TEXT DEFAULT NULL, wrkst_ip TEXT DEFAULT NULL, create_time NUMERIC, expire_time NUMERIC, logon_type INTEGER, flags INTEGER);

    userdb_exec_query: Query:'C'

    userdb_exec_query: Query Executed, ret:101

    DEBUG [0x1e48] 29/01/2020 07:53:01 : userdb_sqlite_prepare: statement to be prepared: INSERT INTO UserInfo (rowid,user,domain,usergroup,wrkst_name,wrkst_ip, create_time, expire_time,logon_type,flags) VALUES (NULL,:user,:domain,:usergroup,:wrkst_name,:wrkst_ip,:create_time,:expire_time,:logon_type,:flags)

    DEBUG [0x1e48] 29/01/2020 07:53:01 : userdb_sqlite_prepare: statement to be prepared: DELETE FROM UserInfo WHERE user=$1

    DEBUG [0x1e48] 29/01/2020 07:53:01 : userdb_sqlite_prepare: statement to be prepared: DELETE FROM UserInfo WHERE user=$1 AND domain=$2

    DEBUG [0x1e48] 29/01/2020 07:53:01 : userdb_sqlite_prepare: statement to be prepared: DELETE FROM UserInfo WHERE user=$1 AND domain=$2 AND wrkst_ip=$3

    DEBUG [0x1e48] 29/01/2020 07:53:01 : userdb_sqlite_prepare: statement to be prepared: DELETE FROM UserInfo WHERE user=$1 AND wrkst_ip=$2

    DEBUG [0x1e48] 29/01/2020 07:53:01 : userinfo_db_init: USERDB Successfully Initialized

    MSG [0x1e48] 29/01/2020 07:53:01 : stas_init: Userinfo Database Initialized

    DEBUG [0x1e48] 29/01/2020 07:53:01 : userdb_validate_all_userinfo: validate query: UPDATE UserInfo SET flags='1';

    userdb_exec_query: Query:'U'

    userdb_exec_query: Query Executed, ret:101

    MSG [0x1e48] 29/01/2020 07:53:01 : stas_init: Userinfo Database Validated

    DEBUG [0x1e48] 29/01/2020 07:53:01 : stas_init: ThreadPool Size: 64

    DEBUG [0x1e48] 29/01/2020 07:53:01 : list_init: list handle allocated

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: function list initialized

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: ThreadData allocated

    DEBUG [0x1e4c] 29/01/2020 07:53:01 : dead_entry_timeout_workerthread: DEAD-ENTRY-TIMEOUT = 0
    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[1] Created: ID: 0x1e58

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[2] Created: ID: 0x1e5c

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[3] Created: ID: 0x1e60

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[4] Created: ID: 0x1e64

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[5] Created: ID: 0x1e68

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: ThreadDevilCreated: ID: 0x1e6c

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[7] Created: ID: 0x1e70

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: ThreadMusicCreated: ID: 0x1e74

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[9] Created: ID: 0x1e78

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[10] Created: ID: 0x1e7c

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[11] Created: ID: 0x1e80

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[12] Created: ID: 0x1e84

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[13] Created: ID: 0x1e88

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[14] Created: ID: 0x1e8c

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[15] Created: ID: 0x1e90

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[16] Created: ID: 0x1e94

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[17] Created: ID: 0x1e98

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[18] Created: ID: 0x1e9c

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[19] Created: ID: 0x1ea0

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[20] Created: ID: 0x1ea4

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[21] Created: ID: 0x1ea8

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[22] Created: ID: 0x1eac

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[23] Created: ID: 0x1eb0

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[24] Created: ID: 0x1eb4

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[25] Created: ID: 0x1eb8

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[26] Created: ID: 0x1ebc

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[27] Created: ID: 0x1ec0

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[28] Created: ID: 0x1ec4

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[29] Created: ID: 0x1ec8

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[30] Created: ID: 0x1ecc

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[31] Created: ID: 0x1ed0

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[32] Created: ID: 0x1ed4

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[33] Created: ID: 0x1ed8

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[34] Created: ID: 0x1edc

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[35] Created: ID: 0x1ee0

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[36] Created: ID: 0x1ee4

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[37] Created: ID: 0x1ee8

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[38] Created: ID: 0x1eec

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[39] Created: ID: 0x1ef0

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[40] Created: ID: 0x1ef4

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[41] Created: ID: 0x1ef8

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[42] Created: ID: 0x1efc

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[43] Created: ID: 0x1f00

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[44] Created: ID: 0x1f04

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[45] Created: ID: 0x1f08

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[46] Created: ID: 0x1f0c

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[47] Created: ID: 0x1f10

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[48] Created: ID: 0x1f14

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[49] Created: ID: 0x1f18

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[50] Created: ID: 0x1f1c

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[51] Created: ID: 0x1f20

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[52] Created: ID: 0x1f24

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[53] Created: ID: 0x1f28

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[54] Created: ID: 0x1f2c

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[55] Created: ID: 0x1f30

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[56] Created: ID: 0x1f34

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[57] Created: ID: 0x1f38

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[58] Created: ID: 0x1f3c

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[59] Created: ID: 0x1f40

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[60] Created: ID: 0x1f44

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[61] Created: ID: 0x1f48

    INFO [0x1e54] 29/01/2020 07:53:01 : Connectivity Thread running

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[62] Created: ID: 0x1f4c

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[63] Created: ID: 0x1f50

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread[64] Created: ID: 0x1f54

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_create: Thread added to thread map

    DEBUG [0x1e48] 29/01/2020 07:53:01 : stas_init: ThreadPool Initialized

    DEBUG [0x1e48] 29/01/2020 07:53:01 : list_init: list handle allocated

    DEBUG [0x1e48] 29/01/2020 07:53:01 : cr_update_queue_init: XG Update Queue Initialized

    MSG [0x1e48] 29/01/2020 07:53:01 : stas_init: XG Update Queue Initializated

    NOTICE [0x1e48] 29/01/2020 07:53:01 : SSOclient_thread: SSO Client Init

    MSG [0x1e48] 29/01/2020 07:53:01 : stas_init: XG SSO Client Initialized

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: Submitting Function 0x450eb0

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: adding function at tail

    DEBUG [0x1e48] 29/01/2020 07:53:01 : list_add_tail: first element added

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: get free thread: ThreadID: 0x1e58

    MSG [0x1e48] 29/01/2020 07:53:01 : stas_init: Sophos SSO Client started

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: Submitting Function 0x450790

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: adding function at tail

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: get free thread: ThreadID: 0x1e5c

    MSG [0x1e48] 29/01/2020 07:53:01 : stas_init: Sophos SSO Client started

    MSG [0x1e48] 29/01/2020 07:53:01 : wrkstpoll_init: polling mode: 1

    DEBUG [0x1e5c] 29/01/2020 07:53:01 : threadpool_threadproc: New Function added

    DEBUG [0x1e5c] 29/01/2020 07:53:01 : threadpool_get_threadproc: Function 0x450eb0

    DEBUG [0x1e5c] 29/01/2020 07:53:01 : threadpool_threadproc: Executing Function 0x450eb0

    ERROR [0x1e5c] 29/01/2020 07:53:01 : GETTING (USERINFO) FROM QUEUE
    DEBUG [0x1e5c] 29/01/2020 07:53:01 : list_remove_head: list is Empty

    DEBUG [0x1e58] 29/01/2020 07:53:01 : threadpool_threadproc: New Function added

    DEBUG [0x1e58] 29/01/2020 07:53:01 : list_remove_head: last element removed

    DEBUG [0x1e58] 29/01/2020 07:53:01 : threadpool_get_threadproc: Function 0x450790

    DEBUG [0x1e58] 29/01/2020 07:53:01 : threadpool_threadproc: Executing Function 0x450790

    DEBUG [0x1e58] 29/01/2020 07:53:01 : threadpool_run: Submitting Function 0x4504c0

    DEBUG [0x1e58] 29/01/2020 07:53:01 : threadpool_run: adding function at tail

    DEBUG [0x1e58] 29/01/2020 07:53:01 : list_add_tail: first element added

    DEBUG [0x1e58] 29/01/2020 07:53:01 : threadpool_run: get free thread: ThreadID: 0x1e60

    MSG [0x1e58] 29/01/2020 07:53:01 : SSO_client_update_heartbeat: cr_node:172.16.2.126 is_active:0

    DEBUG [0x1e60] 29/01/2020 07:53:01 : threadpool_threadproc: New Function added

    DEBUG [0x1e60] 29/01/2020 07:53:01 : list_remove_head: last element removed

    DEBUG [0x1e60] 29/01/2020 07:53:01 : threadpool_get_threadproc: Function 0x4504c0

    DEBUG [0x1e60] 29/01/2020 07:53:01 : threadpool_threadproc: Executing Function 0x4504c0

    ERROR [0x1e60] 29/01/2020 07:53:01 : SSOclient_update_active_cr_file: updated successfully

    DEBUG [0x1e60] 29/01/2020 07:53:01 : threadpool_finishnotify: Thread ID: 0x1e60

    DEBUG [0x1e60] 29/01/2020 07:53:01 : threadpool_finishnotify: Reset Event

    MSG [0x1e48] 29/01/2020 07:53:01 : stas_init: Workstation Polling Module Initialized

    DEBUG [0x1e48] 29/01/2020 07:53:01 : logoff_detector_init: Detection Mode: 2

    DEBUG [0x1e48] 29/01/2020 07:53:01 : logoff_detector_init: Detection Interval: 605

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: Submitting Function 0x412ac0

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: adding function at tail

    DEBUG [0x1e48] 29/01/2020 07:53:01 : list_add_tail: first element added

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: get free thread: ThreadID: 0x1e60

    DEBUG [0x1e48] 29/01/2020 07:53:01 : stas_init: User Logoff Detector Thread started

    DEBUG [0x1e60] 29/01/2020 07:53:01 : threadpool_threadproc: New Function added

    DEBUG [0x1e60] 29/01/2020 07:53:01 : list_remove_head: last element removed

    DEBUG [0x1e60] 29/01/2020 07:53:01 : threadpool_get_threadproc: Function 0x412ac0

    ERROR [0x1e48] 29/01/2020 07:53:01 : stas_init: DC Agent is Active directory

    DEBUG [0x1e60] 29/01/2020 07:53:01 : threadpool_threadproc: Executing Function 0x412ac0

    DEBUG [0x1e60] 29/01/2020 07:53:01 : logoff_detector: Passive Collector skipping logoff 22413180

    DEBUG [0x1e48] 29/01/2020 07:53:01 : crypto_open: crypto context has been acquired

    DEBUG [0x1e48] 29/01/2020 07:53:01 : crypto_open: hash object has been created

    DEBUG [0x1e48] 29/01/2020 07:53:01 : crypto_open: password has been added to the hash

    DEBUG [0x1e48] 29/01/2020 07:53:01 : crypto_open: encryption key is derived successfully

    DEBUG [0x1e48] 29/01/2020 07:53:01 : crypto_open: Cryptographic context established

    DEBUG [0x1e48] 29/01/2020 07:53:01 : dcaserver_crypto_init: cryptographic context initialized

    DEBUG [0x1e48] 29/01/2020 07:53:01 : dcaserver_net_init: network context initialized

    DEBUG [0x1e48] 29/01/2020 07:53:01 : stas_init: DC Agent Server Initialized

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: Submitting Function 0x40eb10

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: adding function at tail

    DEBUG [0x1e48] 29/01/2020 07:53:01 : list_add_tail: first element added

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: get free thread: ThreadID: 0x1e64

    MSG [0x1e48] 29/01/2020 07:53:01 : stas_init: DC Agent Server started

    MSG [0x1e48] 29/01/2020 07:53:01 : tsso_server_net_init: network context initialized

    DEBUG [0x1e64] 29/01/2020 07:53:01 : threadpool_threadproc: New Function added

    DEBUG [0x1e48] 29/01/2020 07:53:01 : stas_init: Transparent SSO Server Initialized

    DEBUG [0x1e64] 29/01/2020 07:53:01 : list_remove_head: last element removed

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: Submitting Function 0x451940

    DEBUG [0x1e64] 29/01/2020 07:53:01 : threadpool_get_threadproc: Function 0x40eb10

    DEBUG [0x1e64] 29/01/2020 07:53:01 : threadpool_threadproc: Executing Function 0x40eb10

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: adding function at tail

    DEBUG [0x1e48] 29/01/2020 07:53:01 : list_add_tail: first element added

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: get free thread: ThreadID: 0x1e68

    MSG [0x1e48] 29/01/2020 07:53:01 : stas_init: Transparent SSO Server started

    DEBUG [0x1e48] 29/01/2020 07:53:01 : dca_set_local_cidmgr: Central ID Manager is LOCAL to DC Agent

    DEBUG [0x1e68] 29/01/2020 07:53:01 : threadpool_threadproc: New Function added

    DEBUG [0x1e68] 29/01/2020 07:53:01 : list_remove_head: last element removed

    DEBUG [0x1e68] 29/01/2020 07:53:01 : threadpool_get_threadproc: Function 0x451940

    DEBUG [0x1e68] 29/01/2020 07:53:01 : threadpool_threadproc: Executing Function 0x451940

    DEBUG [0x1e48] 29/01/2020 07:53:01 : crypto_open: crypto context has been acquired

    DEBUG [0x1e48] 29/01/2020 07:53:01 : crypto_open: hash object has been created

    DEBUG [0x1e48] 29/01/2020 07:53:01 : crypto_open: password has been added to the hash

    DEBUG [0x1e48] 29/01/2020 07:53:01 : crypto_open: encryption key is derived successfully

    DEBUG [0x1e48] 29/01/2020 07:53:01 : crypto_open: Cryptographic context established

    DEBUG [0x1e48] 29/01/2020 07:53:01 : dcaclient_crypto_init: cryptographic context initialized

    DEBUG [0x1e48] 29/01/2020 07:53:01 : dcaclient_net_init: network context initialized

    DEBUG [0x1e48] 29/01/2020 07:53:01 : dca_client_init: DCA Client Initialized

    DEBUG [0x1e48] 29/01/2020 07:53:01 : stas_init: DC Agent Initialized

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: Submitting Function 0x407fd0

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: adding function at tail

    DEBUG [0x1e48] 29/01/2020 07:53:01 : list_add_tail: first element added

    DEBUG [0x1e48] 29/01/2020 07:53:01 : threadpool_run: get free thread: ThreadID: 0x1e6c

    DEBUG [0x1e48] 29/01/2020 07:53:01 : stas_init: DC Agent Initialized

    DEBUG [0x1e6c] 29/01/2020 07:53:01 : threadpool_threadproc: New Function added

    DEBUG [0x1e6c] 29/01/2020 07:53:01 : list_remove_head: last element removed

    DEBUG [0x1e6c] 29/01/2020 07:53:01 : threadpool_get_threadproc: Function 0x407fd0

    DEBUG [0x1e6c] 29/01/2020 07:53:01 : threadpool_threadproc: Executing Function 0x407fd0

  • In reply to neckbeard:

    Hi  

    This line:  ERROR [0x1e48] 29/01/2020 07:53:01 : config_parse_namefile: file C:\Program Files (x86)\Sophos\Sophos Transparent Authentication Suite\domain-list.ini couldn't open: 2

    This line appears to be the issue here for you.  For some reason it seems that the user or process is not able to access this file.

    Could you DM me the configuration screenshots of the STAS config?

  • In reply to KingChris:

    Yeah i noticed that too - good spot

    That file doesnt exist. However i do have 'dc-list.ini' in that location - which is empty.

    On the DC that IS working - again that file doesnt exist, only 'dc-list.ini'

  • In reply to neckbeard:

    I can also confirm I only have a dc-list.ini and is also blank.

    My STAS works fine

    I wonder what may happen if you copied the dc-list.ini and renamed it domain-list.ini

  • In reply to M8ey:

    Thanks M8ey

    I'm on 2.5.1.0, same for you too?

  • In reply to neckbeard:

    neckbeard
    I'm on 2.5.1.0,

     

    No I am on 2.5.0.0