Windows-Admin-Center-Ideas-and-Feedback
Windows-Admin-Center-Ideas-and-Feedback copied to clipboard
Cannot connect to managed server using WinRM SSL, The SSL Certificate could not be checked for revocation
trafficstars
Gateway Version: 1.3.2111.01001
To Reproduce Steps to reproduce the behavior:
- Go to the WAC Home Page
- Click on Any server that you have added
- Connect to the server
- See error
400 - PSRemotingTransportException: Connecting to remote server xxxx.yyyy.zzz failed with the following error message : The server certificate on the destination computer (xxxx.yyyy.zzz:5986) has the following errors:
The SSL certificate could not be checked for revocation. The server used to check for revocation might be unreachable.
I have checked and the CRL endpoint is perfectly reachable from the WAC server, from the WinRM destination endpoint and the WAC client.
If RDPing to the WAC server and manually initiating a SSL PSRemote session to the destination server, it works on the first try AND after that it also works from WAC itself!
Expected behavior That the WAC server is able to check the CRL without requiring a user to manually create a PS Session.
Screenshots & Additional context The same issue is reported by other people here: https://techcommunity.microsoft.com/t5/windows-admin-center/certificate-revocation-issues/m-p/2260351