Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Intune Extension v5 Error getting device list. self signed certificate in certificate chain

This thread has been viewed 11 times
  • 1.  Intune Extension v5 Error getting device list. self signed certificate in certificate chain

    Posted Sep 30, 2021 02:48 PM
    I'm trying to set up the v5 intune extension and I get this error when trying to sync:

    [2021-09-30T11:27:09.898] [ERROR] Intune - Error getting device list. self signed certificate in certificate chain

    I suspect this is because we're doing SSL decryption on our firewall since we've seen similar issues before. The problem is I don't know what URL the extension is trying to reach to whitelist it from decryption. The extension IP address doesn't show up in the firewall logs, and I tried whitelisting graph.windows.net but that didn't help.

    Another thread suggested using curl against the extension address but curl doesn't exist as a command on the cppm. Any ideas what to try?

    ------------------------------
    Chalupa Supreme
    ------------------------------


  • 2.  RE: Intune Extension v5 Error getting device list. self signed certificate in certificate chain
    Best Answer

    Posted Sep 30, 2021 08:51 PM
    Try whitelisting graph.microsoft.com as that's the API endpoint.

    ------------------------------
    James Andrewartha
    ------------------------------



  • 3.  RE: Intune Extension v5 Error getting device list. self signed certificate in certificate chain

    Posted Oct 01, 2021 05:53 PM
    That did the trick. I had to reinstall the extension after whitelisting it but it started pulling devices down after that, thanks for the help!

    ------------------------------
    Chalupa Supreme
    ------------------------------