• 1.6 Migration via new Install with no DB Transfer

    Unsolved FOG Problems
    2
    0 Votes
    2 Posts
    61 Views
    Tom ElliottT

    @Coolguy3289 Thanks for the log line. It points at a bug, not at your approach.

    The installer creates a “FOG Agent CA” under the server root CA. It only creates it when the file is missing. If the root CA changes later (for example, you copy the old server’s /opt/fog/snapins/ssl onto the new box so existing clients keep trusting it), the agent CA stays signed by the first root. Every enrollment then fails with the error you see, and the agent gets a 503.

    The fix is in PR #1810: the installer now re-creates the agent CA when the current root did not sign it.

    To fix your server now, without waiting for the PR:

    sudo grep PKI_AGENT_CA_CERT /opt/fog/.fog-pki

    Move the .fogAgentCA.pem and .fogAgentCA.key files in that directory to a backup location. Then re-run the installer. It creates a new agent CA under your current root, and enrollment works.

    You do not need your internal PKI for this. The FOG-generated root is fine for production.

  • Disable snapin hashing

    Solved FOG Problems
    15
    0 Votes
    15 Posts
    7k Views
    mparletteM

    @Sebastian-Roth OK. I just didn’t wait long enough sorry to rattle your cage. Thanks for the help it did the hash just waited a while and it’s working now.

  • 0 Votes
    5 Posts
    3k Views
    J

    This issue only appears to happen on windows 10 installations. It would seem the legacy client uninstaller is not fully compatible (of sorts) with windows 10.

  • 0 Votes
    9 Posts
    6k Views
    JJ FullmerJ

    @Wayne-Workman But sharing is caring. And it’s so much easier to maintain just one file in a shared location.