<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Deploying SCOM Gateway server</title>
	<atom:link href="http://bradstechblog.com/scom/deploying-scom-gateway-server/feed" rel="self" type="application/rss+xml" />
	<link>http://bradstechblog.com/scom/deploying-scom-gateway-server</link>
	<description>Microsoft technologies like: System Center Operations Manager, and whatever else comes up at the office.</description>
	<lastBuildDate>Tue, 22 Nov 2011 15:12:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: SCOM 2007 R2 Gateway Server &#8211; A few notes&#8230; &#171; Churchfield17&#39;s IT-Blog</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-505</link>
		<dc:creator>SCOM 2007 R2 Gateway Server &#8211; A few notes&#8230; &#171; Churchfield17&#39;s IT-Blog</dc:creator>
		<pubDate>Wed, 26 Jan 2011 15:40:55 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-505</guid>
		<description>[...] Eine sehr gute Anleitung findet man hier . Vielen Dank dem [...]</description>
		<content:encoded><![CDATA[<p>[...] Eine sehr gute Anleitung findet man hier . Vielen Dank dem [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad Hearn</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-504</link>
		<dc:creator>Brad Hearn</dc:creator>
		<pubDate>Wed, 29 Sep 2010 21:16:25 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-504</guid>
		<description>JK, 

I am sure you checked these, but I&#039;ll list these off as items that I have seen missed in the past.

1. Make sure the cert chain is installed on the GW under local computer\&gt;Certificates&gt;Trusted Root Certification&gt;Certificates and not under Current User. This can cause the problem right away.
2. Is the GW in a domain or workgroup? 
3. Make sure the FQDN of the GW is the servername.gwdomain.com. If this is a workgroup, then a GW really wont help you here. However the FQDN would only be the server name with no FQDN
4. What OS is the Gateway? And what CSP are you using in your Cert template? 
If this is 2003 and up you should be using MS RSA SChannel Cryptographic Provider.
5. make sure the cert is in the reg on the gw at HKLM\Software\Microsoft\Microsoft Operations Manager\3.0\Machine Settings\ChannelCertificateSerialNumber 

Let me know if this helps or not
Brad</description>
		<content:encoded><![CDATA[<p>JK, </p>
<p>I am sure you checked these, but I&#8217;ll list these off as items that I have seen missed in the past.</p>
<p>1. Make sure the cert chain is installed on the GW under local computer\>Certificates>Trusted Root Certification>Certificates and not under Current User. This can cause the problem right away.<br />
2. Is the GW in a domain or workgroup?<br />
3. Make sure the FQDN of the GW is the servername.gwdomain.com. If this is a workgroup, then a GW really wont help you here. However the FQDN would only be the server name with no FQDN<br />
4. What OS is the Gateway? And what CSP are you using in your Cert template?<br />
If this is 2003 and up you should be using MS RSA SChannel Cryptographic Provider.<br />
5. make sure the cert is in the reg on the gw at HKLM\Software\Microsoft\Microsoft Operations Manager\3.0\Machine Settings\ChannelCertificateSerialNumber </p>
<p>Let me know if this helps or not<br />
Brad</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JK</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-503</link>
		<dc:creator>JK</dc:creator>
		<pubDate>Wed, 29 Sep 2010 15:29:15 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-503</guid>
		<description>Hello.

Thanks for the detailed info. It has been really useful. However I couldn&#039;t get it to work and would appreciate your help.

I created two certificates with FQDN for gateway and RMS. I imported both of them to both gateway and RMS by cert import GUI and MomCertImport. I ran the gw approval tool as well and can now see the gw in SCOM console under management servers.

However, the gw still cannot connect to the RMS and there are 20057, 21001 and  21016 errors in the event log. I requested and checked the ports and they are open. Any suggestions?

PS: One thing I am not sure about is that do I need to import both RMS and gw certs to the gw? Or only the gw certificate?

Thanks for your help..</description>
		<content:encoded><![CDATA[<p>Hello.</p>
<p>Thanks for the detailed info. It has been really useful. However I couldn&#8217;t get it to work and would appreciate your help.</p>
<p>I created two certificates with FQDN for gateway and RMS. I imported both of them to both gateway and RMS by cert import GUI and MomCertImport. I ran the gw approval tool as well and can now see the gw in SCOM console under management servers.</p>
<p>However, the gw still cannot connect to the RMS and there are 20057, 21001 and  21016 errors in the event log. I requested and checked the ports and they are open. Any suggestions?</p>
<p>PS: One thing I am not sure about is that do I need to import both RMS and gw certs to the gw? Or only the gw certificate?</p>
<p>Thanks for your help..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad Hearn</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-497</link>
		<dc:creator>Brad Hearn</dc:creator>
		<pubDate>Tue, 19 Jan 2010 17:58:09 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-497</guid>
		<description>Hi Krishna,

If I understand your question to be &quot;Can you use the IPSEc offline cert instead of a custom OpsMgr cert?&quot; 

I would say no. There are OID&#039;s that need to be part of the certificate. So in this case you will need to create it.  

I have not used 2008 R2 CA yet for Opsmgr. But yes, you can use this. I have seen many blogs as well that discuss this.

Hope this helps,
Brad</description>
		<content:encoded><![CDATA[<p>Hi Krishna,</p>
<p>If I understand your question to be &#8220;Can you use the IPSEc offline cert instead of a custom OpsMgr cert?&#8221; </p>
<p>I would say no. There are OID&#8217;s that need to be part of the certificate. So in this case you will need to create it.  </p>
<p>I have not used 2008 R2 CA yet for Opsmgr. But yes, you can use this. I have seen many blogs as well that discuss this.</p>
<p>Hope this helps,<br />
Brad</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Krishna</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-495</link>
		<dc:creator>Krishna</dc:creator>
		<pubDate>Mon, 18 Jan 2010 10:25:21 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-495</guid>
		<description>Hello Brad,

Thank you for this Artilce

We are planning to Monitor our servers in DMZ throught Scom, will IPSec (Offline Request) custom certicate can be used for this as well ?

Currently I have CA installed on  Windows 2003 Standard edition which is also a DC and we are planning to migrate to Windows 2008 enterprise or Windows 2008 R2 Standard as this supports V1, V2, V3 certificate templates.

Currently we are running on SCOM 2007 SP1 and all servers are windows 2003.

Kindly Advice if i need to make sure for any other prerequistes.  Will windows 2008 R2 CA will suites our requirement

Regards,
Krishna
http://smtpport25.wordpress.com</description>
		<content:encoded><![CDATA[<p>Hello Brad,</p>
<p>Thank you for this Artilce</p>
<p>We are planning to Monitor our servers in DMZ throught Scom, will IPSec (Offline Request) custom certicate can be used for this as well ?</p>
<p>Currently I have CA installed on  Windows 2003 Standard edition which is also a DC and we are planning to migrate to Windows 2008 enterprise or Windows 2008 R2 Standard as this supports V1, V2, V3 certificate templates.</p>
<p>Currently we are running on SCOM 2007 SP1 and all servers are windows 2003.</p>
<p>Kindly Advice if i need to make sure for any other prerequistes.  Will windows 2008 R2 CA will suites our requirement</p>
<p>Regards,<br />
Krishna<br />
<a href="http://smtpport25.wordpress.com" rel="nofollow">http://smtpport25.wordpress.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad Hearn</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-492</link>
		<dc:creator>Brad Hearn</dc:creator>
		<pubDate>Fri, 18 Dec 2009 13:48:42 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-492</guid>
		<description>Jacob,

You will need both the custom certificate and root certificate for all your management servers. This includes your RMS, all MS servers and any gateways that you have. And remember that after you have imported these certs on each server using the MMC certificate tool, you will then need to use the SCOM certimport utility on each server to update the registry with the certificate serial number.

Brad</description>
		<content:encoded><![CDATA[<p>Jacob,</p>
<p>You will need both the custom certificate and root certificate for all your management servers. This includes your RMS, all MS servers and any gateways that you have. And remember that after you have imported these certs on each server using the MMC certificate tool, you will then need to use the SCOM certimport utility on each server to update the registry with the certificate serial number.</p>
<p>Brad</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jacob</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-491</link>
		<dc:creator>Jacob</dc:creator>
		<pubDate>Wed, 16 Dec 2009 23:51:42 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-491</guid>
		<description>Thanks for the reply and do we need custom certificate for RMS and MS?</description>
		<content:encoded><![CDATA[<p>Thanks for the reply and do we need custom certificate for RMS and MS?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad Hearn</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-489</link>
		<dc:creator>Brad Hearn</dc:creator>
		<pubDate>Tue, 15 Dec 2009 13:45:47 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-489</guid>
		<description>Hi Jacob,

You will need a personalized cert for each server that you will monitor without a gateway. Or a cert for each Gateway. This is partly because each cert needs to be named accordingly to the server name. Also, you will need to run the certimport utility on each server. This tool is used to copy the certificate serial number from the cert into the following registry location HKLM\Software\Microsoft\Microsoft Operations Manager\3.0\Machine Settings\ChannelCertificateSerialNumber 

A bit of a pain i know. But also a motivator to use a gateway server to minimize the work where possible.</description>
		<content:encoded><![CDATA[<p>Hi Jacob,</p>
<p>You will need a personalized cert for each server that you will monitor without a gateway. Or a cert for each Gateway. This is partly because each cert needs to be named accordingly to the server name. Also, you will need to run the certimport utility on each server. This tool is used to copy the certificate serial number from the cert into the following registry location HKLM\Software\Microsoft\Microsoft Operations Manager\3.0\Machine Settings\ChannelCertificateSerialNumber </p>
<p>A bit of a pain i know. But also a motivator to use a gateway server to minimize the work where possible.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jacob</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-488</link>
		<dc:creator>Jacob</dc:creator>
		<pubDate>Mon, 14 Dec 2009 23:39:00 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-488</guid>
		<description>Am confused on one thing, do we need to create custom certificate for each servers and have to register same on respective servers using momcertimport?</description>
		<content:encoded><![CDATA[<p>Am confused on one thing, do we need to create custom certificate for each servers and have to register same on respective servers using momcertimport?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steeve Theriault</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-487</link>
		<dc:creator>Steeve Theriault</dc:creator>
		<pubDate>Tue, 08 Dec 2009 00:10:58 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-487</guid>
		<description>Thai, to be able to see the certificate templates thecertificate authority has to be a windows enteprise version as it support v2 certificate.</description>
		<content:encoded><![CDATA[<p>Thai, to be able to see the certificate templates thecertificate authority has to be a windows enteprise version as it support v2 certificate.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

