Symantec Management Agents fail to update configuration after changing the NS Website certificate
search cancel

Symantec Management Agents fail to update configuration after changing the NS Website certificate

book

Article ID: 218699

calendar_today

Updated On:

Products

IT Management Suite Client Management Suite

Issue/Introduction

After changing the NS WebSite certification the Sym Agent machines are unable to update their configuration and the following error is returned:

 fail to update configuration.  Error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.

Environment

ITMS 8.x

Cause

In this case, the certificate was a self-signed cert created on the Notification Server. But the issue is caused by an internal company policy (Group Policy) bring tun that prohibits using self-signed certificates.  This causes the root certificate or higher domain certificates are not installed or trusted.

 

 

Resolution

1-   Remove the GPO to allow self-signed certificates to be used.  

2- Install the root certificate on the computer and make sure all certificates including the root and other ones are installed in the trusted root.

*If the issue is just on one or a few agents, you can export the NS Certificate from another computer and import/install it on the trusted root certificate on the client. 

Additional Information