<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AppLocker blocked WebEx.exe although exception in Webex Administration</title>
    <link>https://community.cisco.com/t5/webex-administration/applocker-blocked-webex-exe-although-exception/m-p/3916387#M88</link>
    <description>&lt;P&gt;I'm finding the same issue you are, but *only* with WebEx. The Get-AppLockerFileInformation is reporting no publisher info on the machines having trouble. On machines without AppLocker activated I'm able to get the info and test-applocker... works fine including Test-Applocker. On my test machine I stopped the Application Identity service waited 30 or so seconds, started it again (I may have done this 2x). Then it started seeing the publisher again. I rebooted the machine after, and it continued to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Users reporting the issue have rebooted their computers, so I'm not sure a simple restart of the computer is sufficient nor am I completely certain why the service restarts seem to have fixed this test machine, at least temporarily.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Aug 2019 23:30:45 GMT</pubDate>
    <dc:creator>will.schroeder</dc:creator>
    <dc:date>2019-08-29T23:30:45Z</dc:date>
    <item>
      <title>AppLocker blocked WebEx.exe although exception</title>
      <link>https://community.cisco.com/t5/webex-administration/applocker-blocked-webex-exe-although-exception/m-p/3860792#M85</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WebEx-Team, for a few days AppLocker blocked Webex.exe although an exception has been set up.&lt;/P&gt;&lt;P&gt;Windows does not recognize a publisher of the Webex.exe file. The digital signature SHA256 has been updated.&lt;/P&gt;&lt;P&gt;AppLocker can not cope with this yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please change this to old SHA so that we can continue to use webex in the organization.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GPO Rule: O=CISCO WEBEX LLC, L=SAN JOSE, S=CALIFORNIA, C=US&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now: Publisher is missing:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;Current Issue:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;TimeCreated : 22.05.2019 13:00:57&lt;BR /&gt;UserName : Org.\User&lt;BR /&gt;PolicyName : EXE&lt;BR /&gt;FilePath : %OSDRIVE%\USERS\User\DOWNLOADS\WEBEX.EXE&lt;BR /&gt;Publisher : -&lt;BR /&gt;FileHash : 3964C9A1424D9DB7F4E2EDAB623716E05F7AC4F176CEA1A77C26395EF8C0DA81&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 11:16:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/webex-administration/applocker-blocked-webex-exe-although-exception/m-p/3860792#M85</guid>
      <dc:creator>virenschutz</dc:creator>
      <dc:date>2019-05-22T11:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: AppLocker blocked WebEx.exe although exception</title>
      <link>https://community.cisco.com/t5/webex-administration/applocker-blocked-webex-exe-although-exception/m-p/3863498#M86</link>
      <description>That isn’t going to happen. SHA1 has been widely discredited at this point.</description>
      <pubDate>Mon, 27 May 2019 19:29:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/webex-administration/applocker-blocked-webex-exe-although-exception/m-p/3863498#M86</guid>
      <dc:creator>Jonathan Schulenberg</dc:creator>
      <dc:date>2019-05-27T19:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: AppLocker blocked WebEx.exe although exception</title>
      <link>https://community.cisco.com/t5/webex-administration/applocker-blocked-webex-exe-although-exception/m-p/3915727#M87</link>
      <description>&lt;P&gt;I have the same issue you do but I don't think it's SHA1 vs SHA256. I have plenty of exes that I added publisher certs that were SHA256 and still worked. WebEx is the only one I've seen, to date, that I can't seem to get anything cert related added that works. I've been using App Locker for years too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I find a resolution, I'll post it.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 22:33:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/webex-administration/applocker-blocked-webex-exe-although-exception/m-p/3915727#M87</guid>
      <dc:creator>will.schroeder</dc:creator>
      <dc:date>2019-08-28T22:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: AppLocker blocked WebEx.exe although exception</title>
      <link>https://community.cisco.com/t5/webex-administration/applocker-blocked-webex-exe-although-exception/m-p/3916387#M88</link>
      <description>&lt;P&gt;I'm finding the same issue you are, but *only* with WebEx. The Get-AppLockerFileInformation is reporting no publisher info on the machines having trouble. On machines without AppLocker activated I'm able to get the info and test-applocker... works fine including Test-Applocker. On my test machine I stopped the Application Identity service waited 30 or so seconds, started it again (I may have done this 2x). Then it started seeing the publisher again. I rebooted the machine after, and it continued to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Users reporting the issue have rebooted their computers, so I'm not sure a simple restart of the computer is sufficient nor am I completely certain why the service restarts seem to have fixed this test machine, at least temporarily.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 23:30:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/webex-administration/applocker-blocked-webex-exe-although-exception/m-p/3916387#M88</guid>
      <dc:creator>will.schroeder</dc:creator>
      <dc:date>2019-08-29T23:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: AppLocker blocked WebEx.exe although exception</title>
      <link>https://community.cisco.com/t5/webex-administration/applocker-blocked-webex-exe-although-exception/m-p/3916410#M89</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Resolution Found&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The intermediate cert authority cert wasn't on my machines, root was though. I'm not sure how but it ended up on my test machine at one point (maybe I tested running webex as admin and that auto-installed it). What made me check it was this thread:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://social.technet.microsoft.com/Forums/en-US/1468bd38-6d71-4fdd-a1d5-fc8cbf8ac156/applocker-wont-detect-publisher-of-an-exe-on-random-computers" target="_blank" rel="noopener"&gt;https://social.technet.microsoft.com/Forums/en-US/1468bd38-6d71-4fdd-a1d5-fc8cbf8ac156/applocker-wont-detect-publisher-of-an-exe-on-random-computers&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Strangely after adding the intermediate cert to Intermediate Certificate Authorities the get-applockerfileinformation showed the publisher and a test-applockerpolicy now showed it should be allowed, but the previously downloaded temp webex app was still blocked. Subsequent fresh downloads were good though.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: I saw an install that's been on one of my machines for a long while and it had a Symantec cert chain instead of a DigiCert (fresh temp apps downloaded). I'm guessing the problem occurred when they switched.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2019 01:16:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/webex-administration/applocker-blocked-webex-exe-although-exception/m-p/3916410#M89</guid>
      <dc:creator>will.schroeder</dc:creator>
      <dc:date>2019-08-30T01:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: AppLocker blocked WebEx.exe although exception</title>
      <link>https://community.cisco.com/t5/webex-administration/applocker-blocked-webex-exe-although-exception/m-p/3916564#M91</link>
      <description>&lt;P&gt;We had the same behavior in AppLocker (publisher not visible).&lt;/P&gt;&lt;P&gt;The intermediate certificate was in the certificate store but not the root one.&lt;/P&gt;&lt;P&gt;We performed an update via certutil and everything is back to normal&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Download &lt;A href="http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab" target="_blank" rel="noopener"&gt;http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab&lt;/A&gt; and extract authroot.stl&lt;BR /&gt;Download &lt;A href="http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab" target="_blank" rel="noopener"&gt;http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab&lt;/A&gt; and extract disallowedcert.stl&lt;/P&gt;&lt;P&gt;Check the files, they shall be signed by Microsoft&lt;/P&gt;&lt;P&gt;As admin, execute the following 2 commands&lt;/P&gt;&lt;P&gt;certutil -addstore -f root authroot.stl&lt;BR /&gt;certutil -addstore -f disallowed disallowedcert.stl&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As mentioned above, this is surely linked to the switch from Symantec to DigiCert&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2019 08:41:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/webex-administration/applocker-blocked-webex-exe-although-exception/m-p/3916564#M91</guid>
      <dc:creator>mkutilek</dc:creator>
      <dc:date>2019-08-30T08:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: AppLocker blocked WebEx.exe although exception</title>
      <link>https://community.cisco.com/t5/webex-administration/applocker-blocked-webex-exe-although-exception/m-p/3916867#M93</link>
      <description>&lt;P&gt;FYI, I used a GPO to deploy it to all the computers.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2019 17:02:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/webex-administration/applocker-blocked-webex-exe-although-exception/m-p/3916867#M93</guid>
      <dc:creator>will.schroeder</dc:creator>
      <dc:date>2019-08-30T17:02:24Z</dc:date>
    </item>
  </channel>
</rss>

