Content Analysis AV's are unavailable after license is installed
search cancel

Content Analysis AV's are unavailable after license is installed

book

Article ID: 172121

calendar_today

Updated On:

Products

Content Analysis Software - CA

Issue/Introduction

You have a valid AV license, the license is uploaded manually or downloading online successfully. However, the AV(s) are still displaying unavailable on the Content Analysis (CA) Management Console > System > Licensing

 

In var/log/clp_services.log:

[Thread0.3683253355830637] WARN  com.bluecoat.clp.downloadutil.httpclient.SslUtil- SVR_CERT_VALIDATION: CertPathValidatorException
[Thread0.3683253355830637] WARN  com.bluecoat.clp.downloadutil.httpclient.SingleHttpClient- SVR_CERT_VALIDATION: SslUtil.validateCertificatePath: exception = 

...truncated

 [Thread0.3683253355830637] WARN  com.bluecoat.clp.downloadutil.DownloadThread- Executing head request failed with SSLPeerUnverifiedException for service name : SubscriptionService, url : /cylance/engine, DownloadResponse:   URI = https://subscription.es.bluecoat.com/cylance/engine?device=2214320020, StatusCode = 0, StatusMessage = null, ReasonMessage = null, AmountDownloaded = 0, DownloadDate = 2018-07-08T03:41:25.461+0400, CurrentlyDownloading = false, StartTime = null, EndTime = null, RequestToken = null, ETag = null

localhost.localdomain javax.net.ssl.SSLPeerUnverifiedException: peer not authenticated

...truncated

 CAS2-AMF avwatchdog[11061]: Subscription download state 500 : Error peer not authenticated https://subscription.es.bluecoat.com/islicense/database
 CAS2-AMF avservice[11088]: Subscription download state 500 : Error peer not authenticated https://subscription.es.bluecoat.com/cylance/engine

Environment

CAS is accessing internet directly without going through Proxy.

Cause

The Firewall performs SSL Intercept on CAS.

Resolution

Configure the Firewal to exempt CAS from SSL Intercept.