Monitoring of other domain member server

Hello,

we have some servers in our LAN with another domain then our scom server. We create a scom certificate from our scom cert template with the servername.other.domain and import it with the Momcertimport.exe on the server. The entry on the Key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Operations Manager\3.0\Machine Settings" is correct like the serial number in the imported certificate. The telent connection runs successfulll over port 5723.

But the server is not visible at scom and throws some errors in OM event log:

  1. ID20057: Failed to initialize security context for target MSOMHSvc/SCOMSERVER.domain The error returned is 0x80090303(The specified target is unknown or unreachable).  This error can apply to either the Kerberos or the SChannel package.
  2. ID21001: The OpsMgr Connector could not connect to MSOMHSvc/SCOMSERVER.domain because mutual authentication failed.  Verify the SPN is properly registered on the server and that, if the server is in a separate domain, there is a full-trust relationship between the two domains.
  3. ID20071: The OpsMgr Connector connected to SCOMSERVER.domain, but the connection was closed immediately without authentication taking place.  The most likely cause of this error is a failure to authenticate either this agent or the server. Check the event log on the server and on the agent for events which indicate a failure to authenticate.
  4. ID21016: OpsMgr was unable to set up a communications channel to SCOMSERVER.domain and there are no failover hosts.  Communication will resume when SCOMSERVER.domain is available and communication from this computer is allowed.

What can we check?

Thanks & regards

Doreen

February 16th, 2015 11:01am

Hi,

Common issues when working with certificates in OpsMgr

http://blog.coretech.dk/msk/common-issues-when-working-with-certificates-in-opsmgr/

Free Windows Admin Tool Kit Click here and download it now
February 16th, 2015 11:27am

Hi,

Please make sure you have full-trust relationship between the two domains, if they are not in the same foreast, you may try create forest trust between them.

Note, with External trust, there is only NTLM authentication is supported. So check whether you are using this kind of trust.

In addition, please also refer to the link to check SCOM SPN:

OpsMgr 2012: What should the SPNs look like?

http://blogs.technet.com/b/kevinholman/archive/2011/08/08/opsmgr-2012-what-should-the-spn-s-look-like.aspx

Here is an article which should be helpful

Solving the Gateway 20071 event

Regards,

Yan Li

February 17th, 2015 12:14am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics