To resolve the ofcsslagent certificate negotiation failed issue:
-
On the server, locate lssacfo2.dat in:
[C:\Program Files (x86)\Trend Micro\Apex One\PCCSRV\Pccnt\Common\]
-
-
If the file lssacfo2.dat is mismatched on the agent and server (In this scenario, this certificate is correct on the server side):
- Unload the agent.
- Rename the lssacfo2.dat to lssacfo2.dat.bak
- Copy the lssacfo2.dat from the server to the agent.
- Reload the agent. When tmlisten.exe starts, it will load ofcsslagent certificate.
- Use the mmc.exe command to check the ofcsslagent on the agent. The thumbprint should be the same as on the server-side.
-
If the file lssacfo2.dat on the server was incorrect, please uses the command to re-create this file.
- Use the command to re-create the certificate file, refer to the KB: Renewing/Regenerating the OfficeScan Server NTSG and ofcsslagent certificates for OfficeScan and Apex One.
- After re-creating this certificate, restart the Server’s master service.
- Unload the agent.
- Rename the lssacfo2.dat to lssacfo2.dat.bak.
- Copy the lssacfo2.dat from the server to the agent.
- Reload the agent.
- Use the mmc.exe command to check the ofcsslagent on the agent. The thumbprint should be the same as on the server-side.
-