Microsoft Knowledge Base Article
This article contents is Microsoft Copyrighted material.
©2005-©2007 Microsoft Corporation. All rights reserved.
Terms
of Use |
Trademarks
Article ID: 932450 - Last Review: May 21, 2008 - Revision: 3.0
The installation of the Data Protection Manager agent stops responding (hangs) at 93 percent in System Center Data Protection Manager 2006 and System Center Data Protection Manager 2007
When you try to install a Microsoft System Center Data Protection Manager 2006 agent or a System Center Data Protection Manager 2007 agent on a computer, you experience the following symptoms:
- If you try to deploy the agent to a particular computer from Data Protection Manager 2006 or from Data Protection Manager 2007, the installation of the agent stops responding (hangs) when the installation is at 93 percent.
- If you try to manually install the agent on a particular computer, you receive a message that prompts you to confirm that you want to install an unsigned driver.
Note To manually install the Data Protection Manager agent on a computer, run the MsdpmCloneAgent.msi program on that computer. - If you try to use Microsoft Systems Management Server (SMS) or similar software to install the agent, the installation stops responding (hangs). Additionally, it is reported that the MSI service is still running and is waiting for the installation to be completed.
This problem occurs if root certificates that are contained in the Trusted Publishers container or in the Trusted Root Certification Authority container have expired or are not installed. In this scenario, the Data Protection Manager agent appears to be an unsigned driver. Therefore, the driver signing policy on the affected computer generates a warning message.
To resolve this issue, determine whether any certificates in the Trusted Publishers container or in the Trusted Root Certification Authority container have expired. To do this, follow these steps:
- Click Start, click Run, type certmgr.msc, and then click OK.
- Expand Trusted Root Certification Authorities, and then click Certificates.
- Double-click a certificate, and then click the Certification Path tab. The following information will appear in the Certificate status box if the certificate has not expired:
This certificate is OK.
- Repeat step 3 for each certificate in this container.
- Expand Trusted Publishers, and then click Certificates.
Note The Trusted Publishers container may be empty. In this situation, skip steps 5 and 6. - Repeat step 3 for each certificate in this container.
Additionally, compare the certificates that are installed in these containers to those that are installed on a computer on which you can install the Data Protection Manager agent successfully. This may help you determine whether one or more certificates are missing from the affected computer.
If the missing or the expired certificate is from your organization, contact the administrator who manages the certification authority to renew or to install the appropriate root certificate.
If the missing or the expired certificate is a Windows root certificate, follow the steps in following Microsoft Knowledge Base article to resolve the issue:
317541Â
(http://kbalertz.com/Feedback.aspx?kbNumber=317541/
)
Event ID 8 is logged in the Application log
To work around this issue, configure the driver signing policy to allow for the installation of unsigned drivers.
For more information about how to do this, click the following article number to view the article in the Microsoft Knowledge Base:
298503Â
(http://kbalertz.com/Feedback.aspx?kbNumber=298503/
)
Driver signing registry values cannot be modified directly in Windows
APPLIES TO
- Microsoft System Center Data Protection Manager 2006
- Microsoft System Center Data Protection Manager 2007
Community Feedback System
Very often, it takes hours to solve a problem. Very often, you've looked high
and low, and have tried a lot of solutions. When you finally found it, chances
are, it was because someone else helped you. Here's your chance to give back.
Use our community feedback tool to let others know what worked for you and what
didn't.
Please also understand that the community feedback system is not warranted to be
correct, it's simply a system that we've built to let people try and help each
other. If something in a feedback response doesn't make sense to you, or you're
not comfortable making changes that the feedback talks about (like registry
edits), please consult a professional.
Thank you for using kbAlertz.com Feedback System.
-- Scott Cate