MicrosoftDocs / Windows-Admin-Center-Ideas-and-Feedback

Windows Admin Center's hub for ideas and feedback.
Creative Commons Attribution 4.0 International
20 stars 9 forks source link

Cannot connect to managed server using WinRM SSL, The SSL Certificate could not be checked for revocation #223

Open ElSrJuez opened 2 years ago

ElSrJuez commented 2 years ago

Gateway Version: 1.3.2111.01001

To Reproduce Steps to reproduce the behavior:

  1. Go to the WAC Home Page
  2. Click on Any server that you have added
  3. Connect to the server
  4. See error
    400 - PSRemotingTransportException: Connecting to remote server xxxx.yyyy.zzz failed with the following error message : The server certificate on the destination computer (xxxx.yyyy.zzz:5986) has the following errors: 
    The SSL certificate could not be checked for revocation. The server used to check for revocation might be unreachable. 

I have checked and the CRL endpoint is perfectly reachable from the WAC server, from the WinRM destination endpoint and the WAC client.

If RDPing to the WAC server and manually initiating a SSL PSRemote session to the destination server, it works on the first try AND after that it also works from WAC itself!

Expected behavior That the WAC server is able to check the CRL without requiring a user to manually create a PS Session.

Screenshots & Additional context The same issue is reported by other people here: https://techcommunity.microsoft.com/t5/windows-admin-center/certificate-revocation-issues/m-p/2260351