The date of the definitions in Symantec Endpoint Protection clients and Symantec Endpoint Protection Manager remain at Dec 31 2009
Updated: 23 Jul 2010 | 14 comments
Question/Issue:
Current Situation: An issue has been identified in the Symantec Endpoint Protection Management Server (SEPM) whereby all types of SEP definition content [AntiVirus/AntiSpyware, IPS, PTS] with a date greater than 12/31/09 11:59pm are considered to be “out of date”. SEPM will continue to successfully download the antivirus and other definitions, but upon recognizing the definitions as “out of date” they will be purged from the system. The net result is that managed clients dependent on SEPM for definitions will remain on the last definition set prior to 12/31/09 11:59pm (e.g. “12/31/2009 rev. 041” version).
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2010010308571348
Discussion Filed Under:
Comments
yes, there seems to be some
yes, there seems to be some issue. However as per the lionk, the systems are updated. Looks like cosmetic problem.http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2010010308571348
Cheers!
Pete
Help Link: http://www.symantec.com/business/support/overview.jsp?pid=54619
Symantec is aware of this and
Symantec is aware of this and its working on it.
Title: 'The date of the definitions in Symantec Endpoint Protection clients and Symantec Endpoint Protection Manager remain at Dec 31 2009'
Document ID: 2010010308571348
> Web URL: http://service1.symantec.com/support/ent-security.nsf/docid/2010010308571348?Open&seg=ent
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
Definitions stuck on Dev 31 2009 rev 114
hi there, we got the same over here!
Actually SEPM is not stuck
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
OFFICAL STATUS
https://www-secure.symantec.com/connect/forums/official-status-sepm-definitions-stay-31-12-2009-last-updated-04-jan-2010
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
Change Notification Settings
Is it possible to be placed on a list of users to be notified of when this issue is resolved?
if you subscribe to the post
if you subscribe to the post linked to above - the official status thread, then you will get the latest information as and when that is updated.
Paul Murgatroyd
Principal Product Manager, Symantec Endpoint Protection
Endpoint twitter feed: http://twitter.com/symc_endpoint
Hope its fixed soon
So far none of my users have noticed this but its only a matter of time. Wondering what this will do for the alerts when definitions are over x number of days old. I have mine set to 14 days so I have a little time until that hits.
Unmanaged Clients
We are also seeing similar issues on our unmanaged clients. If we use LiveUpdate, they show that the most current definition file is installed, but the client displays the definitions as Thursday, December 31, 2009 r114.
If we download and install the latest updater it will update the definitions to the version of the downloaded updater - currently Monday, January 4, 2010 r4.
Is this to be expected or are we experiencing something different?
No multiple daily updates ?
From what I have seen so far, the multiple daily updates have stopped and the "latest" version of the 12/31/2009 updates is not posted on the Symantec Security Response web page. How can we verfiy that we are getting the latest definitions downloaded and installed?
Is there any ETA on when this
Is there any ETA on when this will be fixed as our remote clients will start to have problems with connections due to host integrity checking.
We have moved to the max on our IVE but that is only 10 days.
There is little information comming from support as to an ETA on this, even with an open call with Symantec.
@wrr123, that is expected
@wrr123, that is expected behaviour, since LiveUpdate is locked to the 2009 definition sets at the moment, whereas IU will force in the latest definitions.
@knightstorm, due to the increased overhead on the response team of creating another definition set, we have had to reduce the frequency temporarily to 1 committed release per day, with the potential for more if the team bandwidth is available. The official thread on the forum (https://www-secure.symantec.com/connect/forums/official-status-sepm-definitions-stay-31-12-2009-last-updated-04-jan-2010) will contain the latest available content information.
@simon.partridge, our engineers are working diligently to release a patch that will resolve this, but coding is just one small part - there is much more work that needs to go into the planning and release of the fix.
For the most up to date information directly from the product team, please continue to reference the post above.
In addition, there is a more active thread being used to discuss this issue, which a number of Symantec Employees are monitoring, please use this to ask questions if required:
https://www-secure.symantec.com/connect/forums/sepm-update
thanks
Paul Murgatroyd
Principal Product Manager, Symantec Endpoint Protection
Endpoint twitter feed: http://twitter.com/symc_endpoint
Hi, I am not able to update
Hi,
I am not able to update the patch in the SEPM Server, neither is the SEPM doing it automatically.
Pls advice.
regards
R. Leonard Martin
How do you subscribe to the post?
How do you subscribe to the post?
Would you like to reply?
Login or Register to post your comment.