Newly installed CEM agents are unable to register to the NS after upgrade to ITMS 8.8.1
search cancel

Newly installed CEM agents are unable to register to the NS after upgrade to ITMS 8.8.1

book

Article ID: 447936

calendar_today

Updated On:

Products

IT Management Suite

Issue/Introduction

After upgrading ITMS and Internet Gateways to ITMS 8.8.1, new agents installed with the CEM enabled package are unable to register to the Notification Server.

The following errors may be seen in the agent logs (C:\ProgramData\Symantec\Symantec Agent\Logs):

Operation 'CEM: Connect' failed. 
Connection path: 1 - Via gateway 1 SNI EPH:
Connecton stage: Gateway tunnel connect 
Error type: SSPI error 
Error code: The certificate chain was issued by an authority that is not trusted (0x80090325) 

Error code: An existing connection was forcibly closed by the remote host (10054) 
Error note: Failed to receive 16413 bytes from sync socket 0000000000001234

Failed to send basic inventory, COM error: The certificate chain was issued by an authority that is not trusted (0x80090325)

Failed to find any certificate accepted by CEM Site, error: Element not found (0x00000490)

The correct certificates are bound on the Notification Server and Internet Gateway/s and were not changed prior to, or after upgrading to 8.8.1

Ephemeral Certificates Authentication Connectivity was enabled after upgrading. This policy is located in Settings > Notification Server > Notification Server Settings

Environment

ITMS 8.8.1

Cloud Enabled Management

Cause

CEM Internet Gateway/s are not registered to the Notification Server.

The 'Servers' tab of the Symantec Management Platform Internet Gateway Manager shows connected Site Servers and Notification Servers. The 'Registration status:' under the NS shows: 'Not registered'

The 'Settings' tab of the Internet Gateway Manager shows a new 'Ephemeral Certificate Authentication' section and 'Allow ephemeral certificates authentication' is enabled.

ITMS 8.8.1 introduces support for a new type of certificates known as Ephemeral Certificates. This new type of certificate can streamline the process of generating and managing CEM client certificates. Consistent with the industry trend, ephemeral certificates make it easier for ITMS administrators to use CEM client certificates with a short duration.

If the Internet Gateway is not registered with the Notification Server, it rejects all ephemeral certificates from connecting agents. Agents can still connect using permanent certificates in this state. When ephemeral certificate connectivity is enabled, the CEM agent installation package will be built with ephemeral certificate authentication.

See KB Cloud-enabled Agents Access Troubleshooting page: usage and CEM connection reporting (ITMS 8.8.1)

Resolution

Register the Notification Server on all configured Internet Gateways.

  1. Open the Symantec Management Platform Internet Gateway Manager
  2. Ensure the Internet Gateway is updated to the current version
  3. Click on the 'Servers' tab
  4. Click 'Not registered' on the NS server's 'Registration Status'
  5. Enter either Windows credentials or NS Access Token (if token authentication is enabled)
  6. Click OK and refresh the connection to the NS
  7. Verify if newly installed CEM agents and existing CEM agents register to the Notification Server when CEM mode is enabled