Security Compliance

SEM: Issues due to revoked code signing certificates

We have made the decision to digitally re-sign SEM; the existing certificate is currently scheduled to be revoked on March 8, 2021. Installation of affected versions of the SEM may be forbidden by system policy. This article describes steps to address the possible issues in SEM.

First published date

12/21/2020 9:51 PM

Last published date

1/25/2021 6:06 AM

Overview

As a best practice and to further enhance the security of our products, we have retained third-party cybersecurity experts to assist us in these matters, guiding us in improving our processes and controls.

To that end and to provide additional assurance to all of our customers, we have made the decision to digitally re-sign our products and have requested (and received) a new digital certificate, which reflects a recertification of the authenticity of SolarWinds products, both current and future.

What to expect next:
  • We will be issuing a new product release for Security Event Monitor (SEM) containing the updated certificate.
  • The existing certificate is currently scheduled to be revoked on March 8, 2021.
If you fail to upgrade to the newest version, SEM users might notice the following issues: 
  • EXE download will not unzip
  • Windows agents will not install
  • Installed agents will not restart if stopped
  • Agents can’t be automatically upgraded
  • Remote windows installation/section blocked


Affected versions

  • 2020.2
  • 2020.2.1
  • 2020.4

Product section

Security Event Manager

Cause

Revoked code signing certificates.

Resolution

If SEM users are experiencing any of these issues, SolarWinds strongly recommends upgrading to the latest available version

SEM 2020.4.1: If agents are not able to start due to compromised certificate, reinstall agents by running RemoteAgentInstaller 2020.4.1. (Run installation again without executing the uninstall.)

If issues persist, contact Support.