"Certificat a expirat" Eroare la sănătate server este afișat ca "Deconectat critice" pe un server de configurare în serviciile de recuperare Microsoft Azure

Simptome

Să luăm în considerare următorul scenariu:

  • Aveți un portal de servicii de recuperare Microsoft Azure.

  • Pe serverul de configurare server de sănătate este afișat ca Critice deconectat.

  • Când faceți clic pentru a vizualiza detaliile erorii, primiţi următorul mesaj de eroare:

    Configurare server 'nume_server' nu este conectat.

    Cauza posibilă: Serviciile necesare nu se execută pe serverul de configurare 'nume_server'

    Acțiune recomandate:
    Asigurați-vă că:
    1. Serviciul Microsoft Azure site-ul furnizor de recuperare se execută.
    2. server se poate conecta la internet.
    3. setările proxy utilizat pentru conectarea la Azure site-ul de recuperare sunt corecte.
    4. versiunea furnizor care rulează pe server este la zi. Faceți clic pe furnizorul de descărcare pentru a obține cea mai recentă versiune.

  • Pe serverul de configurare, găsiţi un mesaj de eroare care seamănă cu următorul în fișierul \home\svsytems\var\phpdebug.log installation_path:

    data ora (UTC) (UTC) CX: INFO: get_ps_settings: Curl eroare: problemă de certificat SSL: certificat a expirat


În acest scenariu, a expirat Certificatul SSL pe serverul de configurare.

Rezolvare

To resolve this issue, follow the steps in this article to renew the SSL Certificates for the Configuration server.

Note If the gencert.exe file crashes in your environment, download and replace the file with an updated gencert.exe binary.

The following gencert.exe binary files are available for download from the Microsoft Download Center:

Download Download the GenCert_OL6-64 package now.
Download Download the GenCert_SLES11-SP3-64 package now.
Download Download the GenCert_RHEL6-64 package now.
Download Download the GenCert_Windows package now.
For more information about how to download Microsoft support files, click the following article number to view the article in the Microsoft Knowledge Base:

119591 How to obtain Microsoft support files from online services Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help prevent any unauthorized changes to the file.


Step 1: Update the Configuration Server computer

  1. Log on to the CS computer.

  2. Stop the following services:

    • cxprocessserver

    • tmansvc

    • INMAGE-AppScheduler

    • DRA


  3. In the command prompt window, go to the Configuration Server's installation folder, and then go to the bin folder. This folder should resemble the following: 

    C:\home\svsystems\bin

  4. Backup your existing gencert.exe binary. Then replace it with the updated gencert.exe binary.

  5. Type the following commands, and then press Enter after each command:

    1. gencert.exe -n cs –i

      alternate text

    2. gencert.exe -n ps --dh

      alternate text

    3. genpassphrase.exe –b

      alternate text

    4. Open a command prompt window, go to the following folder and then rename the encryption.key file.

      C:\Program files\InMage systems\private

    5. genpassphrase.exe –k

      alternate text

  6. In the Run dialog box, type inetmgr in the Open box and then click OK.

    1. Under Connections, select the localhost computer, and then double-click Server Certificates.

      alternate text

    2. On the Server Certificates page, select the oldest Scout certificate.

      alternate text

    3. Right-click the Scout certificate that you chose, and then click Remove.

      alternate text

    4. Under Connections, select Default Web Site, and then click Bindings on the Actions menu.

      alternate text

    5. In the Site Bindings dialog box, click Edit.

      alternate text

    6. In the Edit Site Binding dialog box, click Select.

      alternate text

    7. On the Select Certificate page, select the Scout certificate, and then click OK.

      alternate text

    8. On the Actions menu under Manage Website, click Restart to restart the IIS service.

      alternate text

    9. Restart the following services:

      • cxprocessserver

      • tmansvc

      • INMAGE-AppScheduler

      • DRA


Step 2: Update the Process Server computer

  1. Log on to the Configuration Server.

  2. Open a command prompt window, go to the Configuration Server installation folder, and then go to bin folder. This folder should resemble the following: 

    C:\home\svsystems\bin

  3. Type the following command, and then press Enter to obtain the passphrase that's needed to update the Process Server.

    • genpassphrase.exe –n

      alternate text

  4. Log on to the Process Server.

  5. Open a command prompt window, go to the Process Server installation folder, and then go to the bin folder. This folder should resemble the following: 

    C:\home\svsystems\bin.

  6. Backup your existing gencert.exe binary. Then replace it with the updated gencert.exe binary.

  7. Type the following command, and then press Enter:

    • gencert.exe -n ps --dh

      alternate text


  8. Double-click the following command, which is located on the desktop. This command opens the Microsoft Azure Site Recovery Process Server dialog box. Provide the Configuration Server IP, the Configuration Server Port number, and the Connection Passphrase, and then click Save.

    • cspsconfigtool.exe

      alternate text

Step 3: Update the Master Target (MT) computer (Windows)

  1. Log on to the Configuration Server computer.

  2. Open a command prompt window, go to the Configuration Server installation folder, and then go to the bin folder. This folder should resemble the following:

    C:\home\svsystems\bin

  3. Type the following command to obtain the passphrase that's needed to update the Master Target Windows computer:

    • genpassphrase.exe –n

      alternate text

  4. Log on to the Master Target computer.

  5. Open a command prompt window, and then go to the installation folder. This folder should resemble the following:

    C:\Program Files (x86)\Microsoft Azure Site Recovery

  6. Backup your existing gencert.exe binary. Then replace it with the updated gencert.exe binary.

  7. Type the following command, and then press Enter:

    • gencert.exe -n ps --dh

      alternate text

  8. Double-click the hostconfigwxcommon.exe file. This file opens the Host Agent Config dialog box. On the Global tab, provide the CS IP, CS HTTPS port number, the connection passphrase, and then click OK.

    alternate text

Step 4: Update the Master Target (MT) computer (Linux)


  1. Log on to the Configuration Server computer.

  2. Open a command prompt window, go to the Configuration Server installation folder, and then go to the bin folder. This folder should resemble the following:

    C:\home\svsystems\bin.

  3. Type the following command to obtain the passphrase that's needed to update the Master Target Linux computer:

    • genpassphrase –n

      alternate text

  4. Log on to the Master Target computer.

  5. Go to the installation folder, and then go to the /Vx/bin folder. This folder should resemble the following:

    /usr/local/ASR/Vx/bin

  6. Backup your existing gencert.exe binary. Then replace it with the updated gencert.exe binary.

  7. Type the following command, and then press Enter:

    chmod 770 /usr/local/ASR/Vx/bin/gencert

  8. Type the following command, and then press Enter:

    ./gencert -n ps --dh

  9. Type the following command and then press Enter. This command opens the Host Config Interface dialog box.

    ./hostconfigcli

  10. Press Enter to open the Global tab options. Provide the Configuration Server IP, Configuration Server HTTPS port number, and the connection passphrase.

  11. Press Tab to update the changes, and then click Quit to close the dialog box.


Step 5: Update the Source computers (Windows)

This step must be performed on each protected Windows computer.

  1. Log on to the Configuration Server computer.

  2. Open a Command Prompt window, go to the Configuration Server installation folder, and then go to the bin folder. This folder should resemble the following:

    C:\home\svsystems\bin

  3. Type the following command to obtain the passphrase that's needed to update the Source Windows computer:

    genpassphrase.exe –n

    alternate text

  4. Log on to the Source computer.

  5. Open a Command Prompt window, and then go to the Mobility Service installation folder. This folder should resemble the following:

    C:\Program Files (x86)\Microsoft Azure Site Recovery

  6. Backup your existing gencert.exe binary. Then replace it with the updated gencert.exe binary.

  7. Type the following command, and then press Enter:

    gencert.exe -n ps --dh

    alternate text

  8. Double-click the hostconfigwxcommon.exe file. This file opens the Host Agent Config dialog box. On the Global tab, provide the Configuration Server IP, Configuration Server HTTPS port number, the connection passphrase, and then click OK.

    alternate text


Step 6: Update the Source computers (Linux)

This step must be performed on all protected Linux computers.

  1. Log on to the Configuration Server computer.

  2. Open a Command Prompt window, go to the Configuration Server installation folder, and then go to the bin folder. This folder should resemble the following:

    C:\home\svsystems\bin

  3. Type the following command to obtain the passphrase that's needed to update the Source Linux computer:

    genpassphrase –n

    alternate text

  4. Log on to the Source computer.

  5. Go to the Mobility Service installation folder, and then go to the /Vx/bin folder. This folder should resemble the following:

    /usr/local/ASR/Vx/bin

  6. Backup your existing gencert.exe binary. Then replace it with the updated gencert.exe binary.

  7. Type the following command, and then press Enter:

    chmod 770 /usr/local/ASR/Vx/bin/gencert

  8. Type the following command, and then press Enter:

    ./gencert -n ps --dh

  9. Type the following command and then press Enter. This command opens the Host Config Interface dialog box.

    ./hostconfigcli

  10. Press Enter to open the Global tab options. Provide the Configuration Server IP, Configuration Server HTTPS port number, and the connection passphrase.

  11. Press Tab to update the changes, and then click Quit to close the dialog box.


Aveți nevoie de ajutor suplimentar?

Extindeți-vă competențele
Explorați instruirea
Fiți primul care obține noile caracteristici
Alăturați-vă la Microsoft Insider

V-a fost de ajutor această informație?

Vă mulțumim pentru feedback!

Vă mulțumim pentru feedback! Se pare că ar fi util să luați legătura cu unul dintre agenții noștri de asistență Office.

×