ControlUp Monitor deployment might timeout due CRL validation.

The Issue:

Installing the ControlUp Monitor fails with timeout (screenshot)

After installation of ControlUp or upgrading from previous version, Installation of the Monitor can experience difficulties reaching to the internet to verify the certification and due to that it fails - usually this can happen in closed environment without access to the internet. 

Example:

image002.png

The Cause:

The Monitor issues CRL authentication (click here for more information) to the internet in order to validate the certificate and session runs into a timeout due to no answer and internet unavailability.  

Traced packets can revel connection attempt to cacerts.digicert.com 

Known IP addresses:  104.16.238.184, 104.16.239.184, 104.16.237.184, 104.16.241.184, 104.16.240.184

crl3.digicert.com - aka: cs9.wac.phicdn.net  IP: 72.21.91.29                                              crl4.digicert.com - aka: rvip1.ue.cachefly.net  IP: 66.225.197.197

Suggested Solution:

To update CTL follow instructions here: 

Microsoft Trusted Root Certificate Program Updates

Microsoft Support downloadable packages 

How to update step by step guide 

The suggested workaround to this issue it to bypass the Monitor need to verify the digital signature or update trusted and disallowed CTLs in disconnected environments in Windows.

To manually apply the workaround for this issue: (A text file is downloadable below ready for use.)

  1. Go to ->  C:\program files\controlup monitor\7.0.2.11
  2. on the remote machine create a notepad file and name it: cuMonitor.exe.config with the following text: 

<configuration>

    <runtime>

        <generatePublisherEvidence enabled="false"/>

    </runtime>

</configuration>

 

Example:

2018-01-31_10-20-58.jpg

Basically when the monitor installs, it reaches out to the internet the validate the certificate and this file skips this action.

 *To view similar issue with installing the Agent click here to view the article.  

 

 

 

 

Was this article helpful?
0 out of 0 found this helpful
Have more questions? Submit a request
Powered by Zendesk