Endpoint Protection

 View Only
  • 1.  Will Endpoint contact certificate servers?

    Posted Aug 28, 2016 10:59 AM

    We have a customer who is using our software on a machine using an unmanaged EndPoint installation. When we monitor the process created by our software on the customer machines, we can see that it contacts a certificate server - even though our application does not contain code which would do so. We don't see this activity on other machines. It is clear that the Sysfer.dll is being injected into this process. Is it possible that Endpoint is the source of this activity? If so, would there be Endpoint configuration settings which would control this?

    Thanks for any insight!



  • 2.  RE: Will Endpoint contact certificate servers?

    Posted Aug 28, 2016 11:09 AM

    Sysfer.dll is the Application and Device Control driver.

    Since this is an unmanaged client, you can either disable it or remove the component.

    This article briefly talks about it but this only applies to the managed version:

    How to create an Application Control exception or stop sysfer.dll injection into a process with SEP



  • 3.  RE: Will Endpoint contact certificate servers?

    Posted Aug 29, 2016 08:36 AM

    Yes - I understand, but is it expected that Sysfer.dll would contact a certificate server? The customer is currently unable to disable it.



  • 4.  RE: Will Endpoint contact certificate servers?

    Posted Aug 29, 2016 08:38 AM

    ADC shouldn't but SONAR or Download Insight may.



  • 5.  RE: Will Endpoint contact certificate servers?

    Posted Aug 29, 2016 01:12 PM

    But then I shouldn't see that coming from my process, right?



  • 6.  RE: Will Endpoint contact certificate servers?

    Posted Aug 29, 2016 02:01 PM

    There isn't documentation that I can find to confirm this. I would suggest disabling or removing the component to see what the result is.



  • 7.  RE: Will Endpoint contact certificate servers?

    Posted Aug 30, 2016 03:52 PM

    Yes - ideally that's what I would do, but I don't control our customers machine. Thanks for the thoughts.