Loading...
Loading...
When attempting to perform actions in Veeam Backup & Replication that initiate secure connections, those tasks may fail in environments where the Veeam Backup Server or other Windows-based component servers are either isolated from the internet or subject to significant firewall restrictions to outside servers. Operations that may be affected include, but are not limited to: Windows Guest File Level Restore (FLR)Example: Task fails with "The request has been canceled" Malware Scan Backup Session (which relies on Windows FLR) Veeam Data Cloud Vault connectionsExample: Interaction fails with "Rename folder failed" Adding Hyper-V hosts Connecting the Veeam Backup & Replication Console
When a connection is initiated, Veeam Backup & Replication components use certificates to establish gRPC connections over HTTPS. The Windows feature "Automatically update certificates in the Microsoft Root Certificate Program" checks for revoked certificates via an HTTP request to "ctldl.windowsupdate.com" with a 15-second timeout. Since Veeam's gRPC connection timeout is also 15 seconds, if certificate verification takes too long then the connection fails.
At this time, three workarounds exist to resolve this issue: Option 1: Update Firewalls or Network Access Policies Ensure that both the Veeam Backup Server and other Windows-based component servers have access to "ctldl.windowsupdate.com" over port 80. This allows Windows to successfully complete certificate revocation checks.
More information about the Windows feature "Automatically update certificates in the Microsoft Root Certificate Program" can be found here: Microsoft Documentation: Certificates and trust in Windows
Click on a version to see all relevant bugs
Veeam Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.