Jump to content

Problem with backup certificate


Recommended Posts

Gabriel Boettcher
Posted

I performed a backup of the Kaspersky Security Center (KSC) server from AD-TF-01 to AD-TF-02. The process completed successfully, including the certificate backup (as far as I can tell), but the network agents on the endpoints are not recognizing the new server's certificate. As a result, all devices are now appearing as unmanaged. What could be causing this issue, and how can I resolve it?

Screenshot_2.png

Posted (edited)

Name of server.

 

Edited by Renan Corassa
Gabriel Boettcher
Posted
12 minutes ago, Renan Corassa disse:

Name of server.

 

SERV-AD-TF-02 ( 10.10.240.251 ) is the one i'm using now

Posted

@Gabriel Boettcher hello

If possible, restore your server to its previous state and follow the article: https://support.kaspersky.com/13920

If this is not possible, please follow the next recommendation from the article:

  • Use the klmover utility to restore connection from uncontrolled devices to Administration Server, for example, after an Administration Server failure, if it is not possible to restore from a backup.

 

 

Gabriel Boettcher
Posted
20 minutes ago, Demiad disse:

@Gabriel Boettcher hello

If possible, restore your server to its previous state and follow the article: https://support.kaspersky.com/13920

If this is not possible, please follow the next recommendation from the article:

  • Use the klmover utility to restore connection from uncontrolled devices to Administration Server, for example, after an Administration Server failure, if it is not possible to restore from a backup.

 

 

But klmover utility has to be used on each computer? we have over 150 computers that lost connection to the server

Posted

@Gabriel Boettcher
1. Uninstall KSC completely.
2. Change the server name to the old one.
3. Reinstall KSC.
4. Restore the backup using KLBACKUP.

Everything will almost certainly return to normal.
The certificate has the old server name.

To avoid having to use KLMOVER and/or DNS records for pointing.

2 minutes ago, Gabriel Boettcher disse:

Mas o utilitário klmover tem que ser usado em cada computador? Temos mais de 150 computadores que perderam a conexão com o servidor

The computers will be discovered again and you can apply an installation task after importing the .bat file with the server data by calling klmover and pointing to the Unassigned Devices group.

Gabriel Boettcher
Posted
22 horas atrás, Renan Corassa disse:

@Gabriel Boettcher
1. Uninstall KSC completely.
2. Change the server name to the old one.
3. Reinstall KSC.
4. Restore the backup using KLBACKUP.

Everything will almost certainly return to normal.
The certificate has the old server name.

To avoid having to use KLMOVER and/or DNS records for pointing.

The computers will be discovered again and you can apply an installation task after importing the .bat file with the server data by calling klmover and pointing to the Unassigned Devices group.

i tried to backup in the same server TF-01 . but it says "certificate incorrect" after i try log on on mmc. I don't understand where does this certificate go after the backup is completed.

Renan Corassa
Posted
2 horas atrás, Gabriel Boettcher disse:

Tentei fazer backup no mesmo servidor TF-01, mas aparece a mensagem "certificado incorreto" depois que tento fazer login no MMC. Não entendi para onde vai esse certificado depois que o backup é concluído.

Gabriel,
Restart the kladminserver service and try accessing it again.

Gabriel Boettcher
Posted
5 minutes ago, Renan Corassa disse:

Gabriel,
Restart the kladminserver service and try accessing it again.

On mmc this worked but in web console it didn't. Still in MMC the devices can't recognize the certificate

 image.thumb.png.c6fd7dbe855b43f964fb6b5d7e17a8ff.png

image.png.f757e3e088a8f2720c3dcba54ad6c1ed.png

Renan Corassa
Posted

@Gabriel Boettcher
To repair access to the KSC Web Console,
Before beginning the entire process of restoring access to the Web Console, close all open browsers or those that are accessing the Web Console link.

Open Control Panel (from the Run menu, use the appwiz.cpl command) → Programs and Features.
Select the Kaspersky Security Center Web Console product and click Uninstall/Change.
Choose your preferred language > OK.
Select Reissue Certificate and click Next.
Wait until the process is complete and then try accessing the Web Console again.

42 minutes ago, Gabriel Boettcher disse:

No MMC isso funcionou, mas no console web não. Ainda no MMC, os dispositivos não conseguem reconhecer o certificado.

 imagem.thumb.png.c6fd7dbe855b43f964fb6b5d7e17a8ff.png

imagem.png.f757e3e088a8f2720c3dcba54ad6c1ed.png

Did you do the above procedure?

Gabriel Boettcher
Posted
2 minutes ago, Renan Corassa disse:

@Gabriel Boettcher
To repair access to the KSC Web Console,
Before beginning the entire process of restoring access to the Web Console, close all open browsers or those that are accessing the Web Console link.

Open Control Panel (from the Run menu, use the appwiz.cpl command) → Programs and Features.
Select the Kaspersky Security Center Web Console product and click Uninstall/Change.
Choose your preferred language > OK.
Select Reissue Certificate and click Next.
Wait until the process is complete and then try accessing the Web Console again.

Did you do the above procedure?

Yes, the web console is working now, but the devices still aren’t connecting to the server

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...