To resolve the ofcsslagent certificate negotiation failed issue:
- 
	On the server, locate lssacfo2.dat in: [C:\Program Files (x86)\Trend Micro\Apex One\PCCSRV\Pccnt\Common\] 
- If the file lssacfo2.dat is mismatched on the agent and server (In this scenario, this certificate is correct on the server side):
	- Use the mmc.exe command to check the ofcsslagent on the agent. The thumbprint should be the same as on the server-side.
- Reload the agent. When tmlisten.exe starts, it will load ofcsslagent certificate.
- Copy the lssacfo2.dat from the server to the agent.
- Rename the lssacfo2.dat to lssacfo2.dat.bak
- Unload the agent.
- 
		If the file lssacfo2.dat on the server was incorrect, please uses the command to re-create this file. - Use the command to re-create the certificate file, refer to the KB: Renewing/Regenerating the Trend Micro Apex One Server NTSG and ofcsslagent certificates for Trend Micro Apex One.
- After re-creating this certificate, restart the Server’s master service.
- Unload the agent.
- Rename the lssacfo2.dat to lssacfo2.dat.bak.
- Copy the lssacfo2.dat from the server to the agent.
- Reload the agent.
- Use the mmc.exe command to check the ofcsslagent on the agent. The thumbprint should be the same as on the server-side.
 
 
 
		
