Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

SCOM07 agent push from RMS server in one domain, to servers in another domain (with a two way non-transitive trust between them) fails

Posted on 2009-05-18
2
Medium Priority
?
806 Views
Last Modified: 2013-11-21
Discovery, authentication and agent installation seems to work fine, the agent installs fine on the servers in the 2nd domain when pushed from the RMS server in the 1st domain.  The active tasks window in the opsmgr console even reports that the agents were successfully installed, so no failed install log is generated on the RMS.  Our two domains are trusted, so a certificate based agent install shouldn't be necessary...On the servers, these three errors are listed in their opsmgr event logs:

Event ID:20057: Failed to initialize security context for target MSOMHSvc/rmsserver.domain1.com The error returned is 0x80090303(The specified target is unknown or unreachable).  This error can apply to either the Kerberos or the SChannel package.

Event ID:21001: The OpsMgr Connector could not connect to MSOMHSvc/rmsserver.domain1.com because mutual authentication failed.  Verify the SPN is properly registered on the server and that, if the server is in a separate domain, there is a full-trust relationship between the two domains.

Event ID: 21016: OpsMgr was unable to set up a communications channel to rmsserver.domain1.com and there are no failover hosts.  Communication will resume when rmsserver.domain1.com is both available and allows communication from this computer.

I've run the remote agent prerequisite tool with no errors between the RMS and a host server in the 2nd domain.
I've also tested (via telnet) ports 5723 & 5724 between the RMS and remote host, and they are both open.  Any options for me before I may have to resort to a certificate based install?
Thank you.
0
Comment
Question by:guitar_dave
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 15

Accepted Solution

by:
wwwally earned 2000 total points
ID: 24414492
In an untrusted domain scenario you should us a gateway server.
This gateway will be a domain member of the untrusted domain and will service, by a certificate pair on RMS and gateway, the agents in the other domain.
Discovery, authentication and agent installation work fine because you use the domain credentials of the untrusted domain but in normal operation thats not enough.
Follow this guide to get it the gateway installed en configured.
http://weblogwally.spaces.live.com/blog/cns!A913F865098E0556!488.entry
You will need a CA for this!!!
Regards,
Walter
http://weblogwally.spaces.live.com
0
 

Author Comment

by:guitar_dave
ID: 24414944
So just to clarify...An external non-transitive trust is not enough then?
0

Featured Post

Fill in the form and get your FREE NFR key NOW!

Veeam® is happy to provide a FREE NFR server license to certified engineers, trainers, and bloggers.  It allows for the non‑production use of Veeam Agent for Microsoft Windows. This license is valid for five workstations and two servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This is my 3rd article on SCCM in recent weeks, the 1st (http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_Server_2008/A_4466-A-beginners-guide-to-installing-SCCM2007-on-Windows-2008-R2-Server.html) dealing with installat…
Remote Apps is a feature in server 2008 which allows users to run applications off Remote Desktop Servers without having to log into them to run the applications.  The user can either have a desktop shortcut installed or go through the web portal to…
Visualize your data even better in Access queries. Given a date and a value, this lesson shows how to compare that value with the previous value, calculate the difference, and display a circle if the value is the same, an up triangle if it increased…
Have you created a query with information for a calendar? ... and then, abra-cadabra, the calendar is done?! I am going to show you how to make that happen. Visualize your data!  ... really see it To use the code to create a calendar from a q…
Suggested Courses

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question