Kelvin Ma (gmail) 0 Posted February 15, 2020 Posted February 15, 2020 (edited) Dear Sir, I am performing same IP ESMC Server migration from Server 2008R2 to Server 2019. I successfully backup the database from old server and restored the database to new server using command line. Then, I followed the below steps suggested by vendor support. Import Certificate Authority exported from old server Repair ESMC server at Programs and Features Login WebConsole Change server certificate at Server Settings using exported old cert. Restart ESMC services Although the overview shows that the Server Certificate is valid and has two agent certs. It looks healthy. However, the client computers are still disconnected from the newly migrated server. Please advise how to solve this problem, Kelvin Ma https://help.eset.com/esmc_install/70/en-US/migrated_database_same_ip.htmlInsert existing attachment Edited February 15, 2020 by Kelvin Ma (gmail)
Administrators Marcos 5,453 Posted February 15, 2020 Administrators Posted February 15, 2020 Couldn't it be that the name of the ESMC server has changed and clients are attempting to connect to the old one? Does creating agent live installer and installing it on clients (or on 1 for a start) make the machine to connect to the new server? If not, what error is reported in C:\ProgramData\ESET\RemoteAdministrator\Agent\EraAgentApplicationData\Logs\status.html and trace.log?
ESET Staff MartinK 384 Posted February 15, 2020 ESET Staff Posted February 15, 2020 4 hours ago, Kelvin Ma (gmail) said: Could you please double-check that step "4" was performed correctly? Screenshot from ESMC Server configuration (^) shows that ESMC is using certificate created on 15th February 2020, which probably means that this is not original certificate, i.e. it is probably newly generated certificate signed by new CA which is not known to clients. Also it would help to provide us status.html from client that is not able to connect, especially in case setting old certificate in ESMC settings won't resolve connectivity issue.
Kelvin Ma (gmail) 0 Posted February 15, 2020 Author Posted February 15, 2020 3 hours ago, Marcos said: status_clientPC.pdfCouldn't it be that the name of the ESMC server has changed and clients are attempting to connect to the old one? Does creating agent live installer and installing it on clients (or on 1 for a start) make the machine to connect to the new server? If not, what error is reported in C:\ProgramData\ESET\RemoteAdministrator\Agent\EraAgentApplicationData\Logs\status.html and trace.log? the new ESMC server is previously installed with the name Antivirus5. Afterwards, I turn off the old ESMC Server (name: Antivirus4) and change the name of new ESMC server to Antitivirus4. I wonder if Certificate Authority is generated during the installation of ESET ESMC Server. If I change the name server to another one later, would it still follow the old name, Antivirus5? I hereby attach the agent log of one affected client PC for your reference.
Kelvin Ma (gmail) 0 Posted February 15, 2020 Author Posted February 15, 2020 3 hours ago, MartinK said: Could you please double-check that step "4" was performed correctly? Screenshot from ESMC Server configuration (^) shows that ESMC is using certificate created on 15th February 2020, which probably means that this is not original certificate, i.e. it is probably newly generated certificate signed by new CA which is not known to clients. Also it would help to provide us status.html from client that is not able to connect, especially in case setting old certificate in ESMC settings won't resolve connectivity issue. I attach the screenshot of changing the server certificate with the exported old certificate from the old ESMC server. It is strange that the information does not update (still is valid from 15/2/2020) even it shows that the import is successful. I restart the ESMC server service. This information still does not update. Please advise if the procedure I performed to import the server certificate is correct or not. Thank you very much,
Kelvin Ma (gmail) 0 Posted February 15, 2020 Author Posted February 15, 2020 (edited) On my newly migrated ESMC server (Server2019), I had already successfully changed the server certificate to an old one. I succeed to do so by both selecting the certificate from folder and importing the certificate. You can see that it is valid from 9/9/2018. However, another problem arises. At Status Overview, it shows that the server certificate is invalid. What causes this problem? It even tried a much older server certificate which I backup at earlier time. The same problem occurs. It shows the server certificate is invalid. Please kindly advise, Thank you very much. Kelvin Ma Edited February 15, 2020 by Kelvin Ma (gmail)
Kelvin Ma (gmail) 0 Posted February 15, 2020 Author Posted February 15, 2020 The screenshots are the Server Certificate of the old ESMC Server (Server 2008R2) for your reference.
Recommended Posts