SCOM Certificates and KSP

Andrew Perry 1 Reputation point
2024-06-14T15:58:29.8033333+00:00

Our AD Team has recently updated Certificate Templates to make use of KSP as per recommendations from Microsoft.

However all our SCOM Gateway Cert renewals are failing as it seems SCOM does not support KSP.

Does anyone know if Microsoft plan to fix this and if so, when?

Thanks

Andrew

Operations Manager
Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,440 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. XinGuo-MSFT 15,781 Reputation points
    2024-06-17T09:43:37.45+00:00

    Hi,

    It appears that there is a known issue with SCOM (System Center Operations Manager) not supporting KSP (Key Storage Providers), which are recommended for use with newer ciphers like ECDSA P384. This is due to SCOM's reliance on the older CSP (Cryptographic Service Provider) that supports older ciphers (SHA-1, SHA-256, SHA-512) and the requirement for KeySpec to be set to 1, which is not compatible with KSP where KeySpec must be 0.

    As for the plans to address this issue, I found a Microsoft Learn article that clearly states that Cryptography API Key Storage Provider (KSP) is not supported for Operations Manager certificates. This suggests that there has been no update or change in the support for KSP in SCOM as of the latest information available in the article dated April 10, 2024.

    https://video2.skills-academy.com/en-us/system-center/scom/obtain-certificate-windows-server-and-operations-manager?view=sc-om-2022&tabs=Enterp%2CEnter

    0 comments No comments