SMS_REST_PROVIDER : Connection to administration service is unsuccessful PKI

Vid3al 96 Reputation points
2024-10-11T15:15:24.3166667+00:00

Hello everyone,

Current our version and configuration : MECM 2303 No Hotfix. (Site Configuration : Enhanced HTTP)

We have noticed daily errors, but we do not understand the cause, and why they are present :

Component : SMS_REST_PROVIDER
Source : SMS Server
Message ID : 11610
Severity : Error
Description : Connection to administration service is unsuccessful. Error info: "Error status: TrustFailure, Error message: The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel." 
Component : SMS_REST_PROVIDER
Source : SMS Server
Message ID : 11615
Severity : Error
Description : Connection to administration service is unsuccessful because of PKI certificate issue. 

In our MECM configuration, we are not aware that we are using PKI certificates.

User's image

Why do we have these errors?

How can we solve them?

We would like to fix them before upgrading to version 2403.

Thank you for your patience and support.

Microsoft System Center
Microsoft System Center
A suite of Microsoft systems management products that offer solutions for managing datacenter resources, private clouds, and client devices.
1,017 questions
Microsoft Configuration Manager
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Simon Ren-MSFT 35,546 Reputation points Microsoft Vendor
    2024-10-14T08:14:56.2466667+00:00

    Hi,

    Thank you for posting in Microsoft Q&A forum.

    1,Where do you see these errors? Is the SMS_REST_PROVIDER shown green under Monitoring\System Status\Component Status?

    2,Please reboot of the server to have a try. If possible, we can also try a site reset and see if it repairs the provider.

    3,Message ID 11610 usually occurs when there is a trust failure: "The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel." This error is due to the fact that the connection to the administration service is being made over an SSL/TLS secure channel, but the certificate presented by the server while establishing the connection is not trusted by the client. The SSL/TLS certificate presented by the server could be invalid, self-signed or the certificate chain is incomplete.

    On the other hand, Message ID 11615 occurs due to a PKI certificate issue while connecting to the administration service. It could mean that there is a problem with the PKI certificate being used.

    Based on the information you have provided, I would suggest the following troubleshooting steps:

    Check the validity of your SSL/TLS certificate and ensure that it is trusted by the client.

    Check for the completeness of the certificate chain.

    Check the validity of the PKI certificate being used.

    Check the time and date on your server and ensure that they are correct.

    4,For more information, please refer to:

    How to set up the administration service in Configuration Manager

    Thanks for your time. Have a nice day!

    Best regards,

    Simon


    If the response is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Vid3al 96 Reputation points
    2024-10-25T14:35:00.54+00:00

    We solved this by requiring a new https 443 Binding certificate for the Default Site in IIS.

    So the events mentioned above have disappeared.

    (Site Configuration : Enhanced HTTP)

    Thank you for your support.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.