Cain Manor

Your Guide To All Things Cain™

SAV Client Rescue

Last week I did an upgrade to our SAV server that failed. This fail­ure resulted in the SAV server being unable to talk to the clients. The new server install laid down a new PKI folder, which is the pub­lic key for the server. Once I recov­ered the old PKI file, the old clients were able to talk to the new server. How­ever, a few boxes were built dur­ing that time, and expected the tem­po­rary PKI folder that had been replaced. This is how to fix the issue. This pro­ce­dure should also help you migrate from an old server to a new server (other things being equal.)

From your server, copy c:\program files\Symantec AntiVirus\grc.dat to C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Cor­po­rate Edition\7.5\ on your client. Within 20 sec­onds, that file will dis­ap­pear (Magic!!) You Now need to copy over the cor­rect root cer­tifi­cate. On the server, it lives in c:\Program Files\Symantec AntiVirus\pki\roots, and the name is a long string of num­bers, fol­lowed by .servergroupca.cer. Note that this file may live under­neath \SAV instead of \Syman­tec AntiVirus. Copy the file from the server to the same folder in the client (be is SAV or Syman­tec Antivirus)

Stop and restart the Syman­tec Anti-Virus ser­vice on the client. This forces the client to talk to the Sys­tem Cen­ter Con­sole (SSC). Your may not see the client imme­di­ately on your SSC, but should within a few min­utes. You can check the last time a server talked to the client by using the Default Con­sole View (under View -> Default Con­sole View.)

The only vari­a­tion I’ve had from these steps is that I have needed to stop and start the ser­vices to get the grc.dat file to disappear.

Comments are closed.