After installing Symantec Endpoint Protection Manager (SEPM) to an existing site, logging on to the console generates a "Failed to connect to the server" error message.
The Symantec Endpoint Protection Manager service starts, a "Failed to connect to the server" error message is generated when logging on
- The "
<Install Dir>\Tomcat\Logs\catalina.out" log file displays the following error message: "java.io.FileNotFoundException: C:\Program Files\Symantec Endpoint Protection Manager\tomcat\etc\keystore.jks (The system cannot find the file specified)"
Managed clients cannot connect to the Symantec Endpoint Protection Manager server and display the error message "<ParseHTTPStatusCode:>503=>503 SERVICE NOT AVAILABLE" in the sylink.log file.
After installing, recovering, or reinstalling Symantec Endpoint Protection Manager on the same computer, or on a different computer, with the same host name as the previous computer name and you are using the same database.
A copy of the server certificate will be required to accomplish this work around.
If a copy of the server certificate is not available and this is a clean install on a system with the same host name as a previous system, copy the certificate files from the previous computer.
The two certificate files are:
- Stop the Symantec Endpoint Protection Manager service.
- Copy the backup "keystore.jks" file into "
<Install Dir>\Tomcat\etc" folder.
- Open the "
<Install Dir>\Tomcat\conf" folder.
- Rename the "server.xml" file to "server.old.xml".
- Copy the backup "server.xml" file into this folder.
- Open the "server.old.xml" file.
- Copy the path in the "keystoreFile" value under the "Factory" tag.
Example: <FactoryclassName="org.apache.coyote.tomcat4.CoyoteServerSocketFactory" clientAuth="false" keystoreFile="C:\Program Files\Symantec Endpoint Protection Manager\tomcat\etc\keystroke.jks" keystorePass="changeit" protocol="TLS"/>
- Copy "C:\Program Files\Symantec\Symantec Endpoint Protection Manager\tomcat\etc\keystore.jks".
- Open the "server.xml" file.
- Paste the "KeystoreFile" path of the "server.old.xml" file into the "KeystoreFile" path of the current "server.xml" file.
- Save the "server.xml" file.
- Start the Symantec Endpoint Protection Manager service.
If a backup of the previous server certificate cannot be obtained, the SEPM install must be accomplished with a different host name. This will force Symantec Endpoint Protection Manager to generate a new server certificate, which will also cause communication between the server and the clients to break.
To prevent this issue the future, accomplish the following steps before moving the Symantec Endpoint Protection Manager server. (This will require at least two servers in the site.)
Note: If the Embedded database is being used, there cannot be two servers in a site.
- Back up the server certificate.
- Uninstall the Symantec Endpoint Protection Manager to be moved.
- Using a running Symantec Endpoint Protection Manager server, log into Symantec Endpoint Protection Manager and delete the server entry of the server being moved from the "Admin > Servers" screen.
- Install the Symantec Endpoint Protection Manager (SEPM) server on the new computer.
- Use the "Add this server to an existing site" configuration option.
- Login to the SEPM console of the newly installed Symantec Endpoint Protection Manager server
- Restore the server certificate using the backup certificate (Admin > Server screen).
Imported Document Id