Endpoint Agents Certificate Renewal Pending error in RSA Data Loss Prevention 9.6 and later
Originally Published: 2016-05-02
Article Number
Applies To
RSA Product/Service Type: Endpoint
RSA Version/Condition: 9.6/9.6/SP2
Platform: Windows Server 2008R2 / Windows 7
Issue
If the certificates are not renewed even after the existing certificates are expired, the respective DLP Endpoint component stops communicating with the other DLP Endpoint components. The DLP Endpoint components with the expired certificates will appear nonoperational on the Enterprise Manager console.
In which the Endpoint Agents are showing red/down on Enterprise Manager UI with the status "Certificate renewal pending" error as depicted below:
Cause
- The below logs captured from "Enterprise-Manager/em.log file" under path: [C:\program Files(x86)\RSA\Enterprise Manager\logs] shows that TLS certificates exchange between Enterprise-Manager & Root-End-point-coordinator servers failed due to a Microsoft Windows Server error with "Schannel".
18 Feb 2016 05:10:38,652 | DEBUG - RootEpcCertificateRenewer.renewCertificate(87) | No certificate exist for Root epc [Root Endpoint Coordinator] signed by CA, alias [em-ca-key-1441260004260] 18 Feb 2016 05:10:38,652 | INFO - RootEpcCertificateRenewer.renewCertificate(94) | Initiating renewal flow for Root Endpoint Coordinator 18 Feb 2016 05:10:39,432 | ERROR - RootEpcCertificateRenewer.renewCertificate(119) | Failed to renew sub-ca certificate of Root Endpoint coordintator at com.rsa.dlp.em.security.certificate.scheduledjobs.RootEpcCertificateRenewer.renewRootEndpointCoordinatorCertificate(RootEpcCertificateRenewer.java:125) at com.rsa.dlp.em.security.certificate.scheduledjobs.RootEpcCertificateRenewer.renewCertificate(RootEpcCertificateRenewer.java:95) at com.rsa.dlp.em.security.certificate.scheduledjobs.CertificateRenewalJob.secureExecuteInternal(CertificateRenewalJob.java:60) 18 Feb 2016 05:15:38,604 | ERROR - RootEpcCertificateRenewer.renewCertificate(119) | Failed to renew sub-ca certificate of Root Endpoint coordintator
Resolution
- The DLP administrator should review the certification authorities trusted for client authentication and remove those that do not really need to be trusted.
- For details steps, please follow the KB# https://support.microsoft.com/en-us/kb/2464556.
- Upon applying that MS fix and restarting the "RSA DLP Endpoint coordinator" service the certificates will be sent to Enterprise Manager followed by new certificates exchange where a new REPC certificate will be generated and placed on rEPC inside the certificate store "RSA DLP EPi Trust" which will be utilized in renewing the Endpoint agent(s) certificates.
Related Articles
How to configure the Certificate Renewal Policy 25Number of Views Error: 'Unable to install the certificate. Error code: 80004005' ; certificate renewal fails for encryption certificate to… 17Number of Views Certificate renewal to hardware storage device such as a USB token 27Number of Views RSA SilverTail Profile Analyzer license installation and renewal 15Number of Views Error: 'VBScript: certificate renewal' appears when installing a certificate using Microsoft Internet Explorer 6.0. An err… 7Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA announces the availability of the RSA SecurID Hardware Appliance 230 based on the Dell PowerEdge R240 Server How to troubleshoot Oracle database ORA-04030 errors in RSA Identity Governance & Lifecycle RSA Authentication Manager Upgrade Process Microsoft SQL Server Collectors can no longer connect to the SQL Server database after upgrade to Microsoft SQL Server 201…
Don't see what you're looking for?