Event 20071 - checked all the usual suspects

We have two agent servers that have been monitored using a one-way trust and a certificate for well over a year successfully.  Recently, both fell into a not monitored state.  We tried reinstalling the agent, including a newly generated certificate, but event 20071 comes up immediately followed by 21016 after service restart.  Thereafter we get 20071 alone every 15 minutes.  No other warnings/errors.

(Both servers are used for ADFS.)

All usual suspects have been checked.  Root cert, cert chain, management group name, registry keys for AuthenticationName and NetworkName have FQDN, we can ping and we can telnet 5723 to management server, and I've run momcertimport.exe many times.  We have a couple thousand agents, so we've picked up on the issues to watch for over the years!  But this one has us stumped.

SCOM 2007 R2 environment.

Any takers?

Thank you!

March 24th, 2015 7:15pm

Thank you Mai.  I have already seen those links, and carefully checked that is all correct.

The certificate generation process is the same process we've used for thousands of agent servers.  Including other servers on this particular domain.  Only two servers on this domain (and subnet) have a problem, most do not.

I have not been able to find any special instructions for servers that run ADFS, but are not domain controllers.  If anyone knows of any, please let me know.  But it's not as if we just installed ADFS, they've been ADFS servers since day one.

The fact that it was working fine for over a year and just broke makes me consider that a March 2015 Windows Update could possibly have done this, but again I have not read anything to that effect.

March 25th, 2015 8:38am

Hi,

Please refer to the link below, althouh I know you have already validated most of them.

Tips and Tricks: SCOM (2012 and 2007) Gateway Server Troubleshooting Guide

http://blogs.catapultsystems.com/jcowan/archive/2012/07/03/tips-and-tricks-scom-2012-and-2007-gateway-server-troubleshooting-guide.aspx

Note: Microsoft provides third-party contact information to help you find technical support. This contact information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.

Free Windows Admin Tool Kit Click here and download it now
March 26th, 2015 3:22am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics