Troubleshooting tips
- Last UpdatedOct 04, 2024
- 1 minute read
- PI System
- PI Server 2024 R2
- PI Server
This topic contains troubleshooting tips to assist with custom certificate renewal using Microsoft Management Console (MMC) or Windows PowerShell.
-
Ensure that the NT SERVICE\pinetmgr (for Data Archive) and NT SERVICE\AFService (for AF) virtual service account has read access to the certificate's private key. This step is crucial for the renewal process to work correctly.
-
For the MMC method, this access is typically granted during the initial certificate setup or can be adjusted by editing the certificate’s properties in the MMC.
-
For the PowerShell method, you might need to explicitly grant this access before using the Switch-Certificate cmdlet.
-
Ensure proper permissions are granted.
-
Verify that the certificate lifecycle (system) channel is enabled and can generate and receive messages as explained in this Microsoft article: Certificate Services Lifecycle Notifications. This channel is crucial for tracking certificate renewals and swaps, enabling PI Server to monitor and respond to certificate changes effectively.