Configure ProfileUnity Client Elevation To Use SHA2 (256) Instead Of Digital Signature

Product: ProfileUnity-FlexApp

Product Version: 6.7.x+

Expires on: 365 days from publish date

Updated: Sept 30, 2021



In certain secure environments it is necessary to configure the ProfileUnity client elevation process to use SHA2 (256) instead of the default Signature based method in order for the Client to work correctly.


ProfileUnity is not running after upgrade or installation. 

Possible Resolution(s): 


You will need the sha2 hash for the client.exe and LwL.ProfileUnity.Client.exe & vhd.exe (and lwl_profile_mgr.exe if using ProfileDisk) from the netlogon from the version of client tools your are running.

  1. Navigate to the ProfileUnity netlogon directory or share and copy the client.exe file to your Desktop.
  2. While in the ProfileUnity netlogon directory find open the file that you copied up from attachement in KB.
  3. Extract the lwl_elevation_service.xml file from file to your Desktop. (If ProfileUnity is not already installed on Parent image or endpoint, modify the default_lwl_elevation_service as well.) 
  4. Navigate back to the main ProfileUnity netlogon directory and open the file.
  5. Extract the LwL.ProfileUnity.Client.exe file from file to your Desktop.
  6. Using a checksum utility of your choice, or the following PowerShell script (change the folder path to match with your environment), to generate and save the SHA2 hash for both client.exe and LwL.ProfileUnity.Client.exe & vhd.exe (as well as lwl_profile_mgr from C:\Program Files\ProfileUnity\FlexApp -if using ProfileDisks).
    Get-ChildItem -Path "C:\Program Files\ProfileUnity" -Recurse -Filter *.exe | Get-FileHash -Algorithm SHA256 | Format-Table -AutoSize
  7. Edit the lwl_elevation_service.xml and locate the section called <whitelist>
  8. Insert both of the SHA2 hashes generated in Step 6 directly beneath <white>, so that your xml now looks similar to this example below:



      <path hash="1CE604D436FB495565A10C5E302D772E369D40D9" />

      <path hash="D11D757BCB04F8F78D325382E275CBD7E0BB7476" />

      <path signed="Liquidware Labs, Inc." />


  1. Save and exit out the lwl_elevation_service.xml.
  2. Open the file from the ProfileUnity netlogon directory and replace the xml with the one you have modified.
  3. The contents will be updated on the clients when the LwL.ProfileUnity.Client.Startup.exe is ran either via GPO (recompose) or the parent is updated.  
  4. For more information on prepping your gold image see ProfileUnity in Gold Image & Upgrading Client Tools
Was this article helpful?
0 out of 0 found this helpful
Have more questions? Submit a request


Article is closed for comments.