Article ID: 932450
Article Last Modified on 11/27/2007
APPLIES TO
- Microsoft System Center Data Protection Manager 2006
- Microsoft System Center Data Protection Manager 2007
SYMPTOMS
When you try to install a Microsoft System Center Data Protection Manager 2006 agent or a System Center Data Protection Manager 2007 agent on a computer, you experience the following symptoms:
- If you try to deploy the agent to a particular computer from Data Protection Manager 2006 or from Data Protection Manager 2007, the installation of the agent stops responding (hangs) when the installation is at 93 percent.
- If you try to manually install the agent on a particular computer, you receive a message that prompts you to confirm that you want to install an unsigned driver.
Note To manually install the Data Protection Manager agent on a computer, run the MsdpmCloneAgent.msi program on that computer.
CAUSE
This problem occurs if root certificates that are contained in the Trusted Publishers container or in the Trusted Root Certification Authority container have expired or are not installed. In this scenario, the Data Protection Manager agent appears to be an unsigned driver. Therefore, the driver signing policy on the affected computer generates a warning message.
RESOLUTION
To resolve this issue, determine whether any certificates in the Trusted Publishers container or in the Trusted Root Certification Authority container have expired. To do this, follow these steps:
- Click Start, click Run, type certmgr.msc, and then click OK.
- Expand Trusted Root Certification Authorities, and then click Certificates.
- Double-click a certificate, and then click the Certification Path tab. The following information will appear in the Certificate status box if the certificate has not expired:
This certificate is OK.
- Repeat step 3 for each certificate in this container.
- Expand Trusted Publishers, and then click Certificates.
Note The Trusted Publishers container may be empty. In this situation, skip steps 5 and 6. - Repeat step 3 for each certificate in this container.
Additionally, compare the certificates that are installed in these containers to those that are installed on a computer on which you can install the Data Protection Manager agent successfully. This may help you determine whether one or more certificates are missing from the affected computer.
If the missing or the expired certificate is from your organization, contact the administrator who manages the certification authority to renew or to install the appropriate root certificate.
If the missing or the expired certificate is a Windows root certificate, follow the steps in following Microsoft Knowledge Base article to resolve the issue:
317541 Event ID 8 is logged in the Application log
WORKAROUND
To work around this issue, configure the driver signing policy to allow for the installation of unsigned drivers. For more information about how to do this, click the following article number to view the article in the Microsoft Knowledge Base:
298503 Driver signing registry values cannot be modified directly in Windows
Additional query words: DPM
Keywords: kbtshoot kbprb KB932450