Event id: 21010 OpsMgr Connector

Windows 2003 Server in the Internet DMZ in a workgroup not reporting to SCOM2012 SP1

Error logged in the Operations Manager Log on the SCOM2012 Server:

The OpsMgr Connector negotiated the use of mutual authentication with 1P.IP.IP.IP:4092, but Active Directory is not available and no certificate is installed.

A connection cannot be established.


Error logged in operation manager log on Windows 2003 Server:

The OpsMgr Connector connected to RMS.domain.com, but the connection was closed immediately without authentication taking place.  The most likely cause of this error is a failure to authenticate either this agent or the server .

 Check the event log on the server and on the agent for events which indicate a failure to authenticate.

Done the following so far no luck .

  • 5723 opened both ways from this Windows 2003 server and our scom2012 SP1 server.
  • Created certificates for this Windows 2003 Server numerous times and imported using the momcertimport successfully
  • Certs are created using the FQDN of this Windows 2003 Server
  • On Windows 2003 Server checked the regkey to make sure the Serial Number of the cert is valid and not screwed up.
  • Host file is in place on this Windows 2003 Server pointing to my SCOm2012 SP1 server and pinging is not an issue.
  • Stopped the SCOM Agent service on Windows 2003 Server and renamed the folder here C:\Program Files\System Center Operations Manager\Agent\health service state and restarted the service.
  • Certificate on the SCOM2012 server is also valid and not screwed up in the registry.
  • review new manual agent installation in pending management view is also enabled under security on the scom 2012 server
  • I dont see any thing logged in the Agent Logs on my SCOM 2012 Server related to the above installation attempts.

I know SCOM2012SP1 supports Windows 2003 SP3.  My windows 2003 Servers are SP3.

https://techswag.nl/Monitoring/SCOM/2013/06/21/installing-scom2012-sp1-agent-on-not-supported-windows-os

Pleae let me know if I have missed anything ...merci





  • Edited by WildPacket Thursday, February 06, 2014 4:48 PM
February 6th, 2014 6:47pm

Try import with MOMCertimport.exe on the newly added MS. Once you did that all worked as expected.

Also you can check below link

http://social.technet.microsoft.com/Forums/systemcenter/en-US/4a16bb99-586b-4961-9e28-46a74516e5f6/monitoring-workgroup-computers-with-opsmgr-2007-and-certificates?forum=operationsmanagergeneral

Free Windows Admin Tool Kit Click here and download it now
February 7th, 2014 12:06pm

issue resolved

SCOM Certificate on the SCOM2012 server was screwed up in the registry ... so imported the using the momcertimport which resolved ALL my issues.  So weird 2 days ago i tested it and it was fine.

Anyways ... thanks all for participating

  • Marked as answer by WildPacket 14 hours 56 minutes ago
February 7th, 2014 3:41pm

issue resolved

SCOM Certificate on the SCOM2012 server was screwed up in the registry ... so imported the using the momcertimport which resolved ALL my issues.  So weird 2 days ago i tested it and it was fine.

Anyways ... thanks all for participating

  • Marked as answer by WildPacket Friday, February 07, 2014 8:37 PM
Free Windows Admin Tool Kit Click here and download it now
February 7th, 2014 11:37pm

Just FYI.

I also succesfully installed SCOM2012 SP1 agents on windows 2003 servers with SP2.

February 10th, 2014 11:51am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics