Error: "Authentication over SSL encrypted channel with the Configuration Storage Server could not be verified"

ISSUE:

When installing the ISA Server in workgroup with CSS you may encounterĀ the above mentionedĀ error if you try to change the Authentication method between CSS and other ISA Servers in the same Array.

Configuration:

Node1: ISA01
Roles: CSS + ISA Services

RESOLUTION:

  1. Remove any Certificates which you tried to associate with ADAM_ISASTGCTRL service or under any of the local stores.
  2. Close all ISA Server consoles and run the setup from the ISA Installation CD
  3. Select Repair and proceed
  4. Select "I am deploying in a workgroup or domains without trust relationship" and provide the .PFX file path by browsing. Also, provide the password for the .PFX file.
  5. Proceed by clicking Next and verify the name of the CSS and provide the username / password
  6. Under Authentication options, select "Authentication over SSL encrypted channel" and select the "Use an Existing trusted Root CA certificate". If you have a root certificate file then select the second option.
  7. Click Next and Now, you can install the CSS without any problem

CONSIDERATIONS:

  1. Back up your configuration before repairing the ISA Server. It will not delete any rules but to be on safer side, backup is helpful
  2. Get a .PFX file for your certificate. The certificate name should be of you ISA machine which has CSS on it.