Untrusted server certificate exported to SCOM 2019 but manual agent installation not reflecting

Vibin Raj Nadakkal 61 Reputation points
2020-11-06T10:37:07.867+00:00

Hi,

I have imported untrusted server certificate to SCOM 2019 management server and completed the pending steps as per the below guide, But client agent not reflecting in the operation console - pending management for manual agent installation. Please let me know how to to fix the issue.

https://www.cloudsma.com/2015/06/monitoring-add-untrusted-servers-to_23/

https://www.cloudsma.com/2015/06/monitoring-add-untrusted-servers-to/

Regards,
Vibin Raj N

Operations Manager
Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,413 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Leon Laude 85,651 Reputation points
    2020-11-06T10:40:58.86+00:00

    Hi @VibinRajNadakkal-7146,

    First of all make sure the certificates are indeed correct and OK, over 90% of these cases are issues with the certificates itself.

    Also SCOM rejects manually installed agents by default, check that your manual agent installation settings under Administration > Settings > Security and make sure the setting is not set to "Reject new manual agent installations".

    38051-manual-agent-install-settings.png

    Also check the Operations Manager event log on both the SCOM management server and the agent computer for any errors, if any errors appear do some research about these errors.

    ----------

    (If the reply was helpful please don't forget to upvote or accept as answer, thank you)

    Best regards,
    Leon

    0 comments No comments

  2. George Moise 2,346 Reputation points Microsoft Employee
    2020-11-06T10:46:07.247+00:00

    Hi @VibinRajNadakkal-7146,

    If the newly configured agents are not appearing at all in the SCOM Console, can you double check that the agents are not getting automatically rejected? (SCOM Console --> Administration --> Settings --> Security)

    Another reason for the agent not to appear in the Console could be that the agent is not able to connect to the primary management server --> check name resolution, TCP 5723 access from agent to management server.

    Exact details on each of the above should be visible, as @Leon Laude said in the OperationsManager Event Logs on the Agent and Primary Management Server

    BR,
    George

    0 comments No comments

  3. AlexZhu-MSFT 5,551 Reputation points Microsoft Vendor
    2020-11-09T02:58:22.52+00:00

    Hi,

    During the step-by-step guide mentioned above, there is some verification process, for example, to verify the certificate via registry. Have we performed the verification steps? Also, MMA (Microsoft Monitoring Agent) restarting is required.

    If all the above steps are confirmed, we may also check the firewall settings, for example, TCP port 5723 or other ports required, the untrusted server need to talk to get the management packs.

    Hope the above information helps.

    Alex Zhu


    If the response is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments