Quantcast
Channel: THWACK: Message List
Viewing all articles
Browse latest Browse all 22513

Re: Untrusted certificate presented by PM console

$
0
0

This is a normal-and-expected dialog, and no, you cannot use a certificate from ADCS for this purpose.

 

The Patch Manager PAS is the Certificate Authority for the certificate system used within the entire Patch Manager infrastructure owned by that PAS. All secondary PM servers, and all console connections, are secured, authenticated, and encrypted via certificates. The PAS issues those certificates. This ensures that only servers and consoles 'registered' with that PAS can actually establish a communications channel with the PAS. You get this dialog because the Patch Manager ROOT CA is not yet in the Certificate store of this particular system.

 

Understand that an "untrusted certificate" or "untrusted CA" is just a euphamism for a certificate that "this computer doesn't know about yet". But in reality, the Root CA is "trusted", because you own the computer system where that Root CA was created. The "Certificate Authority" is unique to each PAS installed globally; it's not a certificate held by SolarWinds. That is to say, the "Root CA" on your PAS is a completely different certificate than the "Root CA" on my PAS.

 

You can view the certificates on the "Server Certificates" tab of the Security and User Management node of the console. (They're stored in the Certificate Store of the PAS, and they can also be viewed with the Microsoft Certificiates MMC snap-in.)

 

If you select "Yes" on this dialog (the recommended action), the Patch Manager Root Certificate and the Application Server's server certificate will be added to this system's trusted store, and all future console connections will be automatically established using that certificate.

 

If you select "No", the certificates will still be used (no way around this), but they just won't be installed into the system's local store, and you'll get this prompt every time you establish a console connection from this system.

 

If you select "Cancel", of course, the console connection attempt will be aborted.


Viewing all articles
Browse latest Browse all 22513

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>