ePO McAfee .dmg install with Casper Policy

vwebb
New Contributor

I get the following error in the policy log when the ePO .dmg installs: Note error at the end..

Verifying DMG...
Installing ePO_Install_v3.dmg...
Closing package...
Running command /Library/Application Support/McAfee/install.sh -i...
Result of command:
space required to copy archive is 32921038 bytes
space available at mfeUsvs5s is 111103070208 bytes
extracting archive to mfeUsvs5s... please wait
204+0 records in
204+0 records out
104448 bytes transferred in 0.000615 secs (169801033 bytes/sec)
31932+1 records in
31932+1 records out
16349435 bytes transferred in 0.099203 secs (164807686 bytes/sec)
Archive: mfeUsvs5s/package.zip
inflating: mfeUsvs5s/MFEcma.dmg inflating: mfeUsvs5s/reqseckey.bin inflating: mfeUsvs5s/srpubkey.bin inflating: mfeUsvs5s/sitelist.xml inflating: mfeUsvs5s/req2048seckey.bin inflating: mfeUsvs5s/sr2048pubkey.bin inflating: mfeUsvs5s/agentfipsmode Checksumming whole disk (Apple_HFS : 0)…
whole disk (Apple_HFS : 0): verified CRC32 $FB12FEF6
verified CRC32 $B160A2BE
/dev/disk1 /Volumes/MFECMA
installer: Package name is McAfee Agent
installer: Certificate used to sign package is not trusted. Use -allowUntrusted to override.
"disk1" unmounted.
"disk1" ejected.

I created this .dmg from scratch to contain just the install.sh file. Thoughts?! :)

Vince

6 REPLIES 6

franton
Valued Contributor III

Is that the latest install.sh from your epo server? There are a few complaints on McAfee forums about it not being signed properly for gatekeeper which is what you're facing here.

vwebb
New Contributor

I was told it was the latest from our server, but it had been zipped and then extracted and dumped into a .dmg by me.

franton
Valued Contributor III

Sounds like they STILL haven't put a Gatekeeper certificate on it.

analog_kid
Contributor

We were having the same issue but upgraded to the MA agent 4.8 which has the proper cert for sure.

JPDyson
Valued Contributor

Last time I got this, I complained to our ePO admin and received a new package that worked fine.

franton
Valued Contributor III

You're lucky. We have to rebuild our ePO server and then upgrade the thing if we want that.