CMG - WINHTTP_CALLBACK_STATUS_FLAG_CERT_CN_INVALID on client

cwilliams255 96 Reputation points
2020-09-14T15:09:29.377+00:00

Brand new CMG, running Config Manager 2006, getting WINHTTP_CALLBACK_STATUS_FLAG_CERT_CN_INVALID in locationservices log on client

Basically this,

https://learn.microsoft.com/en-ca/troubleshoot/mem/configmgr/cannot-download-content-from-cmg

However that was fixed in old version. In addition, there is talk about simply disabling CMG DP as a workaround, this made no difference. Set up is public CA cert, CNAME from our domain to ms. Certificate passes browser validation, however whilst I started writing this I wonder if the user of a wildcard cert could be the issue? The cmg hostname is in SAN's (so browsers are happy) but common-name is *.

Before I buy a dedicated cert, can anyone confirm if this should work with wildcard

Thanks

Microsoft Configuration Manager
0 comments No comments
{count} votes

Accepted answer
  1. cwilliams255 96 Reputation points
    2020-09-15T09:21:41.93+00:00

    Fixed, I incorrectly assumed that using a public cert meant no requirements client side but actually I needed to upload the root CA to the CMG in addition to wildcard. Now just to figure out why updates are stuck at 0%, closing this

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Eswar Koneti 2,201 Reputation points
    2020-09-14T16:58:04.497+00:00

    Hi,
    The wildcard certs are supported, just make sure you to create the CNAME record in the public DNS.
    You can refer to the blog post to request a public cert http://eskonr.com/2020/07/how-to-request-a-cert-from-public-provider-for-cloud-management-gateway/

    0 comments No comments