After upgrading ITMS and Internet Gateways to ITMS 8.8.1, new agents installed with the CEM enabled package are unable to register to the Notification Server.
The following errors may be seen in the agent logs (C:\ProgramData\Symantec\Symantec Agent\Logs):Operation 'CEM: Connect' failed. Connection path: 1 - Via gateway 1 SNI EPH:Connecton stage: Gateway tunnel connect Error type: SSPI error Error code: The certificate chain was issued by an authority that is not trusted (0x80090325)
Error code: An existing connection was forcibly closed by the remote host (10054) Error note: Failed to receive 16413 bytes from sync socket 0000000000001234
Failed to send basic inventory, COM error: The certificate chain was issued by an authority that is not trusted (0x80090325)
Failed to find any certificate accepted by CEM Site, error: Element not found (0x00000490)
The correct certificates are bound on the Notification Server and Internet Gateway/s and were not changed prior to, or after upgrading to 8.8.1
Ephemeral Certificates Authentication Connectivity was enabled after upgrading. This policy is located in Settings > Notification Server > Notification Server Settings
ITMS 8.8.1
Cloud Enabled Management
CEM Internet Gateway/s are not registered to the Notification Server.
The 'Servers' tab of the Symantec Management Platform Internet Gateway Manager shows connected Site Servers and Notification Servers. The 'Registration status:' under the NS shows: 'Not registered'
The 'Settings' tab of the Internet Gateway Manager shows a new 'Ephemeral Certificate Authentication' section and 'Allow ephemeral certificates authentication' is enabled.
ITMS 8.8.1 introduces support for a new type of certificates known as Ephemeral Certificates. This new type of certificate can streamline the process of generating and managing CEM client certificates. Consistent with the industry trend, ephemeral certificates make it easier for ITMS administrators to use CEM client certificates with a short duration.
If the Internet Gateway is not registered with the Notification Server, it rejects all ephemeral certificates from connecting agents. Agents can still connect using permanent certificates in this state. When ephemeral certificate connectivity is enabled, the CEM agent installation package will be built with ephemeral certificate authentication.
See KB Cloud-enabled Agents Access Troubleshooting page: usage and CEM connection reporting (ITMS 8.8.1)
Register the Notification Server on all configured Internet Gateways.