The Configuration Storage Server Certificate is expired

Answered The Configuration Storage Server Certificate is expired

  • Monday, December 10, 2012 8:53 AM
     
     

    Hello,

    my certificate for EMS to communicate with TMG (workgroup) array members has expired.

    What is the procedure to replace the certificate?

    Tnx

All Replies

  • Monday, December 10, 2012 12:02 PM
     
     

    Hey Shuki tnx, but I know this.

    I just need to know is it just enough to replace old with new cert.

    I replaced it, but still I'm out of sync with members. Also ISASTGCTRL is started.

    Any Ideas?

  • Monday, December 10, 2012 5:31 PM
     
     

    Hi,

    I recommend to use the ISACERTTOOL to Change/renew the certificate:
    http://www.microsoft.com/en-us/download/details.aspx?id=4535


    regards Marc Grote aka Jens Baier - www.it-training-grote.de - www.forefront-tmg.de - www.nt-faq.de

  • Tuesday, December 11, 2012 1:47 PM
     
     Answered

    Wow Marc Grote replied. An honor sir.

    Anyway, I found out that I had the "A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d."

    So I added Network Service to the key that I was using and everything works now.

    Shuki, you don't need to dis-join EMS, that would be serious mistake in my opinion.


     
  • Wednesday, December 26, 2012 2:03 PM
     
     

    hi......this is farooq

    we have the same scenario

    we have ISA configuration server(ISACS01) and two ISA array members( ISA01 & ISA02)

    few days back one of the certificate in the ISA configuration server got  expired and i renews it perfectly and placed on the certicate personal store on the ISACS01 but the daily reports on the ISA is getting failed( geting " generating" continously

     and also when iam trying to communicate with ISACS01( ISA configuration server using the troubleshooting tab( Traffic simulator) in the ISA console in ISA array member) i am getting the following error.

    "Traffic simulator cannot be completed.
    The configuration of the selected server is not syncronized with the configuration storage server.check synchonization tab of moniroting node in ISA
    Server management."

    Kindly let me know whether iam missing something

    yOUR REPLY IS HIGLHLY APPRECIATED...........

  • Wednesday, February 13, 2013 10:38 AM
     
     
    Look at Event viewer and see if you have any errors. If you have  "A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d.", I already answered it :)