Download Management Pack - Security Certificate Problem

Saravanan Balasubramanian 266 Reputation points
2020-09-07T03:52:44.05+00:00

hi guys, i have just installed SCOM 2019 fresh. while trying to download management pack
i am getting security certificate issue. the server behind a proxy but it doesn't need a proxy configuration detail as all the traffic are captured irrespective of proxy setting mentioned. i can still click continue and proceed. but would like to resolve this pop error message. the root certificate is already imported by default. but still the error is not resolved. your help is appreciated.

22906-image.png

Operations Manager
Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,417 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Leon Laude 85,666 Reputation points
    2020-09-07T06:13:34.33+00:00

    Hi,

    Like the error message states, I would verify that:

    • The certificate is issued by a trusted Certificate Authority (CA)
    • The certificate is not expired
    • The certificate is issued for the appropriate web site

    What actually happens is when downloading the management packs from the Operations Console, is SCOM is performing a web service call to the following URL:
    https://www.microsoft.com/mpdownload/ManagementPackCatalogWebService.asmx

    The web site can be behind many IP addresses, more information mentioned here:
    https://www.catapultsystems.com/blogs/tips-and-tricks-opsmgr-2012-sp1-what-web-service-url-ip-and-ports-does-the-management-pack-catalog-web-service-call/

    If the certificate is fine and trusted, you could try setting the web service URL as a trusted site in Internet Explorer.


    (If the reply was helpful please don't forget to upvote or accept as answer, thank you)

    Best regards,
    Leon

    0 comments No comments

  2. Crystal-MSFT 43,381 Reputation points Microsoft Vendor
    2020-09-07T06:25:58.04+00:00

    @Saravanan Balasubramanian For our issue, please check the port 443 is open. Secondly, please make sure the following URL must be allowed by your firewall - https://www.microsoft.com/mpdownload/ManagementPackCatalogWebService.asmx

    We can see more details in the following link:
    https://learn.microsoft.com/en-us/system-center/scom/plan-security-config-firewall?view=sc-om-2019

    After researching, I find a similar issue with us. we can try the suggestions in the following link to see if our issue can be fixed:
    https://social.technet.microsoft.com/Forums/systemcenter/en-US/79b0640c-1b1a-4252-9b68-c5ff08fa2a01/security-certificate-problem?forum=operationsmanagergeneral

    Hope it can help.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  3. CyrAz 5,181 Reputation points
    2020-09-09T13:49:34.497+00:00

    I would say your company's proxy is doing Deep Packet Inspection, which requires it to replace the original MS certificate by one created for the Proxy.
    This is likely what you are witnessing here.
    So maybe you didn't properly import the root cert, or maybe MS implemented some kind of additional security such as Certificate Pining which will prevent SCOM from trusting the certificate even if you imported the proxy's root cert.

    What I would do here is ask the proxy admin to allow outbound queries to that URL without inspecting them...

    0 comments No comments