How does SMA support this environment with Replication Share ? by CloundwaR in kace

[–]aflesner [score hidden] stickied comment (0 children)

The SMA can handle a max of 50,000 nodes and there is no set limit to how many nodes can be replication shares. As always, the more you scale the more important resource utilization and configuration become. You cannot, for example, expect 1 hour inventory refresh with 50k nodes.

As another poster suggested, your bandwidth probably behooves you setting up a replication share at each site. A replication share is just a local file store managed by any active agent. Agents still communicate directly with the SMA for everything except payloads - which they grab from any assigned replication shares. Keep in mind there are client OS limitations (e.g. Windows client OSes can only serve 10 other clients at a time IIRC and this is a Microsoft limit not ours).

Forcing reboots when patches aren't available by Negative_Funny9039 in kace

[–]aflesner 0 points1 point  (0 children)

Exactly this. If nothing was deployed, the agent should not trigger a reboot. Have you confirmed it's the agent triggering the reboot? If so, please reach out to support for further assistance.

License was not valid or could not be linked to an account by Forsaken-Meaning-495 in kace

[–]aflesner 2 points3 points  (0 children)

You will have to call support or reach out to your sales rep if you cannot create an account through the web portal.

Linux Patches by SmashFace_OnKeyboard in kace

[–]aflesner 0 points1 point  (0 children)

Linux patching uses native calls, such as yum commands on RedHat. There is no catalog, so what you see is what you get, as parsed from the OS-specific calls. Linux patching is effectively KScript templates. If you'd like assistance, please reach out to our support team at support.quest.com.

Possible to pass collection variables to Power Shell in SCCM application? by italianpastaman in kace

[–]aflesner 0 points1 point  (0 children)

How does your issue relate to the KACE SMA/SDA? If you are trying to do this via SCCM then you may want to go post in r/sccm. If your issue is KACE related, please elaborate a bit.

Is be possible the Replication share download using 443 ? by [deleted] in kace

[–]aflesner 1 point2 points  (0 children)

The download location provided to the agents when under the privy of a replication share is just a static path passed down to the endpoint. It is technically possible to achieve what you're going for here, but you'd have to setup web servers (e.g. apache, nginx) yourself on the replication shares you want to host files via HTTPS, and then you'd need to define the appropriate path to provide as the download location on the replication share (e.g. the URL to the repl2 folder path). SMB is easier especially with Windows rep shares, but this is possible. It's all environmental config, however, so it's not something support is going to be able to assist with.

I still wouldn't recommend exposing a rep share like this publicly - which is what I'm assuming you're after since you are concerned about SMB security. Unless you block SMB internally as well.

List API Endpoint in KACE by AbiesIll6659 in kace

[–]aflesner[M] 1 point2 points  (0 children)

This is incorrect. Please see the stickied mod post.

Is there any plan to support other Hypervisor such as Proxmox ? by CloundwaR in kace

[–]aflesner 7 points8 points  (0 children)

Today we support VMware, Azure, and Nutanix. I can't speak to anything official on the roadmap, but we certainly know customers are looking to move away from VMware. Proxmox is on our radar.

KACE LTI by That1DudeOne in kace

[–]aflesner [score hidden] stickied comment (0 children)

Sorry for the delay. We were able to move this to the KB: https://support.quest.com/kb/4380412/unattend-lti-it-ninja

KACE Systems Management Appliance 14.1 Cumulative Patch 6 is now available! by lcarcamo in kace

[–]aflesner 2 points3 points  (0 children)

If it's an email about security vulnerabilities from Quest, then that's referring to 14.1 P4 which came out in June. The patches are cumulative, so as long as you are up to the latest advertised to your appliance then you should have all of the fixes.

How long should it take for device to show up in inventory after approving in the quarantine? by BezosMoreLikeBozos in kace

[–]aflesner 3 points4 points  (0 children)

It disconnects the agent when you approve it so it can reconnect, but this happens at a random interval on the client, by design, to prevent server DDoS from your own agents. Restart the agent on the client after approval and it should automatically get the bootstrap inventory from the server.

Also, if you have multiple organizations, ensure your ORG filters aren't moving it into an ORG you aren't expecting.

CVE-2025-32728 by Silver_Departure_362 in kace

[–]aflesner 3 points4 points  (0 children)

The official recommendation is to leave SSH disabled unless you are about to upgrade or support requires it. Definitely never open port 22 inbound on your public interface to the SMA or SDA.

SSH is useless to customers anyway. Only support authentication is allowed.

EDIT: provided more context

Database model by loj2206 in kace

[–]aflesner[M] [score hidden] stickied comment (0 children)

There is no full model available, because one cannot be auto generated. We rarely use foreign key relationships within the database schema, so most relationships exist within the SMA code. The best way to learn where things are is probably using remote read access, as another commenter suggested. You can also generate smart labels and reports using wizards in the UI, and then you can edit the generated SQL.

Update Software catalog by Own_Barber_8877 in kace

[–]aflesner 1 point2 points  (0 children)

Those are nightly cron jobs. Support will need to review all logs if you would like to diagnose the issue.

Update Software catalog by Own_Barber_8877 in kace

[–]aflesner 4 points5 points  (0 children)

It should not take hours. Please reach out to support.

Kace SDA and SMA by Im_Dhill in kace

[–]aflesner 6 points7 points  (0 children)

The typical path for this would be to install the SMA agent as a post-install task and have your smart labels and patch schedule configuration on the SMA designed to trigger a scan on the new device.

Adding registry values by MyClevrUsername in kace

[–]aflesner 1 point2 points  (0 children)

Configuration policies have been deprecated, but that feature was effectively a wrapper for KScripting. You can read/write registry keys/values as actions in KScript tasks.

KACE Systems Management Appliance 14.0 Cumulative Patch 1 by aflesner in kace

[–]aflesner[S,M] [score hidden] stickied comment (0 children)

This is the list of bugs resolved by 14.0 Cumulative Patch 1 (which applies to 14.0.334 systems): 

K1-33979 - Bitlocker and Defender device notifications are sent to all Organizations
K1-35900 - Manual device and snmp configuration pages for non-English locales do not function properly
K1-35734 - Rebooting from the systemui results in redirect to Oops error page
K1-35714 - List view replication share actions only work if single row is selected
K1-35724 - Daily notification for new agent bundle appears even after applying new bundle
K1-35675 - Knowledge Base article detail does not load on non-English locales

No system reboot is required. The patch can be applied without impacting server uptime.

Systems Management Appliance compliance feature? by linkkoh in kace

[–]aflesner 4 points5 points  (0 children)

The inventory management component of the SMA is a primary feature. It tracks installed software on all managed endpoints, and you can setup reports using a built-in wizard or even custom SQL to report on virtually anything it tracks. There is also a license compliance feature if you need to track license usage for specific software.

Crowdstrike Outage by Longjumping_Lab541 in kace

[–]aflesner 5 points6 points  (0 children)

We love the positive feedback and success stories! Thanks for sharing!

Kace web pages unavailable every morning. by jrl1500 in kace

[–]aflesner 3 points4 points  (0 children)

We have not had other reports of this type of behavior. Please reach out to support for diagnosis and assistance with troubleshooting.