The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Vulnerability Manager - Certificate Sync and FC Agent issues

Prev Next
Problem Solution
FC Agent service doesn't get installed while installing the Manager To install FCAgent service:
  1. Download the software vcredist_x86.exe and run it in that host.
  2. Download link: https://www.microsoft.com/en-us/download/details.aspx?id=26999
  3. At the command prompt, go to c:\Program Files (x86)\foundstone\FCM and run the command fcagent -i to install the service.
When you click on API tab in the Manager, internal server error is displayed This issue might be seen in some systems when the command sc query FCAgent is executed internally in the Manager. To run this command, the server in which manager is deployed might not have the right permission settings. The administrator has to provide permission to run sc.exe.

To change permission settings for sc.exe:

  1. Go to //windows/system32/sc.exe.
  2. Right-click sc.exe and select Properties.
  3. Click the Security tab.
  4. Add a local service and provide full permission.
FCAgent service doesn't start in Manager server To integrate with Vulnerability Manager, the Manager must update the Windows registry. However, the user account used to run the Manager service will not have permissions to write to the Windows registry if the Manager is fully locked down. To give that user account the required permissions, follow these steps:
  1. On the server running the Manager, run regedit.exe.
  2. Change the permissions on registry and allow Full Control to 'Local Service' for the following keys:
    • HKLM
    • HKLM\Software
    • HKLM\Software\Foundstone
  3. Right-click on these keys and choose Permissions.
  4. Add the user account used to run the Manager service (likely LOCAL SERVICE).
  5. Give that user account Full Control over the key.
  6. Click OK.

    Note

    Changes take effect immediately. A reboot is not required.

  7. In the API Server page, click Save.

    Note

    If the operating system is 64-bit, perform this procedure for the following keys:

    • HKLM
    • HKLM\Software
    • HKLM\Software\wow6432Node
    • HKLM\Software\wow6432Node\Foundstone
You are able to start the FC Agent service, clicking on 'Retrieve MVM Certificate' returns error message. It might be because port 3801 is not enabled in the API server. Check if port 3801 has been enabled.

Vulnerability Manager could be deployed in distributed mode where FCM Server could be in one server, and the API Server, DB, Enterprise Manager, and Scan Engines could be in another server. In the API server page, try configuring the FCM Server IP address and port 3801. Try clicking the Retrieve MVM Certificate button. If the OnDemand scan fails, try changing the port back to 3800.

Retrieve MVM certificate is failing even though the SSHStauscache and Statuscache keys are present in the registry This might occur if C:\Program Files\Foundstone or C:\Program Files(x86)\Foundstone does not have write permission for Local Service.
  1. Add local service and give full permission to local service.
  2. Click Retrieve MVM Certificate again after giving the required permissions.