CHiLL Posted August 20, 2019 Posted August 20, 2019 (edited) We have a CA setup on one of our DCs, which issues certificates to servers, workstations and users. We're using MBAM for encryption and it is failing to encrypt because of a certificate error: "A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file." The time/date are correct. Checking the server that has MBAM configured, Computer Certificates > Personal > server.local has a certificate that expired on 02/08/2019. I thought these should automatically renew from our CA? If I right click the certificate and select 'Request Certificate with New Key', a new certificate is issued and installed on the server, though MBAM still doesn't work (with the same error), even if IIS is configured to the new certificate for the MBAM site. Anyone got any ideas? Edited August 20, 2019 by CHiLL
CHiLL Posted August 20, 2019 Author Posted August 20, 2019 Update: Turns out that once I'd got the new certificate, I had to configure the SQL Reporting Services, specifically the Web Service URL and specify the new certificate. Then MBAM worked straight away. Despite that's working, shouldn't the server's automatically renew their certificates (even if I have to manually configure the SQL Reporting Services annually)?
Domino Posted August 20, 2019 Posted August 20, 2019 You'll need to configure a GPO to do so: https://docs.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-server-certificate-autoenrollment
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now