During the activation of DSA in Deep Security Manager (DSM), you receive the following error message:
Error: Unable to load agent private key.
Error: 0906A068: PEM routines: PEM_do_header: bad password read 
Unable to connect to the agent on the local machine.
You also see the following symptoms:
- Trend Micro Deep Security Agent service will not start by either using the services MMC or by issuing the "dsa_config/e" command.
- The Notifier shows an "Unknown/Unreachable" agent status.
This error is caused by a multiple reboot during the activation process of DSA. This interrupted the download of relevant files such as *.db files, config.bin (compiled DSA confirmation) and certificate files from the DSM server.
Reinstalling the DSA will fix the issue, but it is not applicable if you have an automated VM provisioning process.
To resolve the issue:
- Delete the following files from C:\Program Files\Trend Micro\Deep Security Agent\:
- *.ini except patch.ini
- Start the Trend Micro Deep Security Agent service by running this command:
net start ds_agent
- Run the following command to restart the activation:
dsa_control /a dsm://4120/
Note: If you are using automated VM provisioning, put the command above at the end of the script to make sure that the reboot is completed and the DSA activation will not be interrupted.