Koozali.org: home of the SME Server

Contribs.org Forums => General Discussion => Topic started by: Peasant on February 03, 2016, 10:14:32 AM

Title: ESET v9 product and Windows update
Post by: Peasant on February 03, 2016, 10:14:32 AM
Hi Folks,

I've hit a snag running ESET v9 products with SME in server/gateway mode. I've raised a bug (9205), but I'm not sure if the problem is to do with my setup so wanted to check to see if anyone else had come across it.

Basically, where I am running Windows 8.1 or 10 with either ESET Smart Security v9 or NOD32 v9, and SSL/TLS protocol filtering is enabled, then Windows update can error out with error 0x80245006. It doesn't happen on all machines, I've one Windows 10 box working fine, but I've one Windows 10 and an 8.1 where it is an issue. Disabling SSL/TLS protocol filtering allows Windows update to run.

Thanks.
Title: Re: ESET v9 product and Windows update
Post by: Stefano on February 03, 2016, 11:15:38 AM
looks like an external issue, not a SME related one..

anyway, ssl/tls filtering is a good example of how "man in the middle" attack works :-)
Title: Re: ESET v9 product and Windows update
Post by: Stefano on February 03, 2016, 11:16:26 AM
moving to General Discussion
Title: Re: ESET v9 product and Windows update
Post by: Peasant on February 03, 2016, 12:34:50 PM
looks like an external issue, not a SME related one..

anyway, ssl/tls filtering is a good example of how "man in the middle" attack works :-)

I'd agree it looks like an external issue, and I spent a day with ESET support trying to solve it. However, if I connect through another network using a different router, then everything works fine. I've a bit more testing to do to make sure though, I will admit  :-)
Title: Re: ESET v9 product and Windows update
Post by: Daniel B. on February 03, 2016, 12:51:24 PM
Have you tried to disable squid on SME to see if it can be a bad interaction with it ?
Title: Re: ESET v9 product and Windows update
Post by: Peasant on February 03, 2016, 02:05:11 PM
Have you tried to disable squid on SME to see if it can be a bad interaction with it ?

Not yet, no. It's my production server, which I don't want to muck about with. Plan at the moment is to build a test server, and try it on the spare broadband connection I have. That's looking like next week's job at the moment. Once I'm set up and testing I'll report back here, and in the bug.