question

Guyute-0518 avatar image
0 Votes"
Guyute-0518 asked StoyanChalakov answered

PKI mgmt Pack

I found that deleting some self-signed certificates and then restarting the monitoring agent has changed the Expired Certificate from Expired to Healthy in the Expired Certificates view. However the info stays in the Expired Certificates Dashboard and does not clear. I have tried repairing the agent, restarting services, stopping service & deleting the Health folder and restarting services, I have tried a reboot of the server. I stopped the services on the management servers, deleted the Health folders, and restarted services and nothing.

I'm about to remove the agent and then reinstall the agent to get the message to clear from the Expired Certificates view.. Any other thoughts on this issue or how to avoid/clear the Healthy State certs from the Expired Certificate dashboard?

thanks

msc-operations-manager
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

StoyanChalakov avatar image
1 Vote"
StoyanChalakov answered

Hi,
can you please post a couple of screenshots, so that we can get an idea on how to approach this?
I assume that the "old" certificates are just orphaned objects, corresponding to the previous seIf-sigtned certificates you haad. So, since those do not exist anymore I would do a couple of things here:

  • Run Remove-SCOMDisabledClassInstance

Demystifying Remove-SCOMDisabledClassInstance
https://kevinholman.com/2021/05/13/demystifying-remove-scomdisabledclassinstance/

Remove-SCOMDisabledClassInstance
https://docs.microsoft.com/en-us/powershell/module/operationsmanager/remove-scomdisabledclassinstance?view=systemcenter-ps-2022

  • Clear the console cache:

How and When to Clear the Cache
https://docs.microsoft.com/en-us/system-center/scom/manage-clear-healthservice-cache?view=sc-om-2022

It just might be that this is some console cache issue, this is how you can rule this out.

Please post an update, I am curious what was the solution here.


(If the reply was helpful please don't forget to upvote or accept as answer, thank you)
Regards,
Stoyan





5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Guyute-0518 avatar image
0 Votes"
Guyute-0518 answered

We have tried clearing the cache and i think your assumptions about the orphaned objects. Here is what we are seeing. Appreciate the assistance.



[1]: /answers/storage/attachments/203217-orphanedcert1.jpg

[2]: /answers/storage/attachments/203179-certstore.jpg


orphanedcert1.jpg (42.9 KiB)
certstore.jpg (27.7 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.