Pushing the Symantec Management Agent to discovered windows computer individually selecting computers through "Rollout Agent to Computers" completes successfully, however the Scheduled Push to computers does not work.
SMP logs (a.log) report "Unable to push agent to newly discovered machines. The key 'NS.ClientCredentials' does not exist."
The file NS.ClientCredentials.kms is missing from \programdata\symantec\smp\kms.
In this case the issue is a missing KMS key.
There are two possible ways to get those missing KMS keys recreated:
A) From the command line prompt, run AeXConfig.exe /configure "<drive>:\Program Files\Altiris\Notification Server\Config\CoreSolution.config". It may take a while to finish but usually after 10min approx. the KMS keys should start appearing on the default location.
B) Use the Migration Tool to import this key from another server. In one particular case the Migration tool (NSUpgradeWizard.exe under the "...\Program Files\Altiris\Upgrade" folder) was used on the parent NS and exported its KMS keys. Then it was imported to the Child NS using the Migration tool as well. Restart the Altiris Services. These are the steps:
Get a working copy of the Upgrade folder:
Zip the upgrade folder from a working install at the following location: Program Files\Altiris.
Copy the file created above to the SMP with the error
Unzip it so that all contents (files and subdirectories) are in \Program Files\Altiris\Upgrade.
Run NSUpgradeWizard.exe from the \program files\altiris\upgrade\ on a working SMP. In the NSUpgradewizard User Interface (UI) do the following:
Select Next to begin the upgrade.
Select Export data from Symantec Notification Server to file store.
Make note of data store name and location.
Ignore creating password, click Next.
It can take 5 to 10 minutes for the system to "Initializing exporters".
Uncheck all products except Notification Server.
Enable only the Symmetric Keys, Export KMS Symmetric cryptographic keys.
Ignore any errors in the readiness check, and click Next.
Note the location and name of the file store file, and click Next.
Message should appear: The data export has completed successfully. Click OK.
Copy the file store file created by the NSUpgradeWizard (*.adb) from the working NS to the non-working SMP.
Run the NSUpgradewizard on the target SMP. From the NSUpgradewizard UI:
Select Import data from a file store into an Symantec Notification Server and Browse to the data store file that was copied over from the working SMP
Select the file in the Import data from file store window, click open.
Ignore the password, unless there was a password created when the data store file on the working SMP was created, click Next. It will take a few minutes to "Initializing importers".
Ignore readiness check failures, if any.
Click Yes to "Do you want to continue?"
Click Ok if you see "Data import completed with errors".
Open the Symantec Management Console, and retry the Scheduled Push to Computers from (Actions>Agents/Plug-ins>Push Symantec Management Agent) Symantec Management Agent Install
Symantec Management Platform 7.1 Service Pack 2
Imported Document ID: TECH188818
Subscribing will provide email updates when this Article is updated. Login is required.