<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Qlik Sense Hub and Management Console down - Bootstrap fails Newly created client certificate not valid; root certificate can't sign new certificates in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Hub-and-Management-Console-down-Bootstrap-fails-Newly/ta-p/1715452</link>
    <description>&lt;P&gt;The Qlik Sense Enterprise hub and Management Console are down.&amp;nbsp;The Qlik Sense Repository Service (QRS) startup procedure does not complete.&lt;BR /&gt;&lt;BR /&gt;If recreating the certificates based on &lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-to-recreate-or-just-delete-certificates-in-Qlik-Sense-No/ta-p/1712692" target="_blank" rel="noopener"&gt;How to recreate or just delete certificates in Qlik Sense&lt;/A&gt;&amp;nbsp;does not resolve the issue.&lt;BR /&gt;&lt;BR /&gt;Manually running the bootstrap fails with error:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;[ERROR] Fatal exception during bootstrap: Newly created client certificate not valid; root certificate can't sign new certificates; see logs &amp;nbsp; &amp;nbsp;at Qlik.Sense.Communication.Security.CertSetup.ThrowAndLogFatalRootError(String msg)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;at Qlik.Sense.Common.Security.SecuritySetup.SetupCA(String externalRootCertThumbprint, ICipherAlgorithm secretsAlgorithm, Boolean forceNewSetup)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;at Repository.Core.Bootstrap.BootstrapHandler.Install(BootstrapState bootstrapState)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;at Repository.Core.Bootstrap.BootstrapHandler.Bootstrap(BootstrapState bootstrapState)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;at Repository.QRSMain.Bootstrap()&lt;BR /&gt;&amp;nbsp; &amp;nbsp;at Repository.QRSMain.Main()&lt;BR /&gt;Bootstrap mode has terminated. Press ENTER to exit..&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Joining a Rim node fails with incorrect password, even if the password was copied or typed correctly:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sebastian_Linser_0-1650525551323.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/77568i798B0049C292E347/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Sebastian_Linser_0-1650525551323.png" alt="Sebastian_Linser_0-1650525551323.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Other errors in the Qlik Sense Logs include:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Certificates are not correctly installed&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;20201022T144326.598+0200&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;STRONG&gt;ERROR&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;APP03&amp;nbsp;&amp;nbsp; &amp;nbsp;Security.Repository.Qlik.Sens&lt;WBR /&gt;e.Communication.Security.Certi&lt;WBR /&gt;ficates.CertUtil&amp;nbsp;&amp;nbsp; &amp;nbsp;44&amp;nbsp;&amp;nbsp; &amp;nbsp;c0cde05d-6354-46fb-a249-d7de9&lt;WBR /&gt;3aad09c&amp;nbsp;&amp;nbsp; &amp;nbsp;HELD-W2K\QlikService&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;STRONG&gt;When accessing certificate store&lt;/STRONG&gt;&amp;nbsp;(loc:LocalMachine, name:Root):&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Duplicate&amp;nbsp;&lt;/STRONG&gt;or invalid root certificates&amp;nbsp;&lt;STRONG&gt;are not allowed&lt;/STRONG&gt;;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Waiting for certificates&lt;/STRONG&gt;&amp;nbsp;and hostname&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;WARN&amp;nbsp;&amp;nbsp; &amp;nbsp;APP03&amp;nbsp;&amp;nbsp; &amp;nbsp;Security.Printing.Qlik.Sense.&lt;WBR /&gt;Communication.Security.Certifi&lt;WBR /&gt;cates.CertValidator&amp;nbsp;&amp;nbsp; &amp;nbsp;4&amp;nbsp;&amp;nbsp; &amp;nbsp;886518e5-f503-418c-b441-094d4&lt;WBR /&gt;ed4fc2f&amp;nbsp;&amp;nbsp; &amp;nbsp;HELD-W2K\QlikService&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;STRONG&gt;Certificate 'CN=QlikClient'&lt;/STRONG&gt;&amp;nbsp;(D24E4965A56C5D0764E9B5255670F&lt;WBR /&gt;38B01F8D9EF)&amp;nbsp;&lt;STRONG&gt;is invalid because it was not signed correctly&amp;nbsp;&lt;/STRONG&gt;by&amp;nbsp;886518e5-f503-418c-b441-094&lt;WBR /&gt;d4ed4fc2f&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Environment:&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Qlik Sense Enterprise, all versions&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 class="qlik-migrated-tkb-headings"&gt;&lt;STRONG&gt;Resolution:&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This issue is caused by access issues when attempting to access/recreate the certificates and/or other GPOs that affect certificates.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Example scenarios: &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;A GPO is in place which enforces duplication of the hostname-CA certificate. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;or&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;A GPO is in place which prevents the creation of a new certificate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It may also be possible that access to the certificate is not granted. In which case the following may help:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Stop the services&lt;/LI&gt;
&lt;LI&gt;Launch Regedit&lt;/LI&gt;
&lt;LI&gt;Locate &lt;SPAN&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb&lt;/SPAN&gt;.&lt;/LI&gt;
&lt;LI&gt;Add &lt;SPAN&gt;ProtectionPolicy&lt;/SPAN&gt; DWORD 32-bit with the value of 1.&lt;/LI&gt;
&lt;LI&gt;Run the bootstrap process again by running&amp;nbsp;&lt;STRONG&gt;"&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;I&gt;C:\Program Files\Qlik\Sense\Repository\Repository.exe" -bootstrap -standalone&amp;nbsp;&lt;/I&gt;&lt;/STRONG&gt;&lt;STRONG&gt;-restorehostname&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;from an&amp;nbsp;&lt;STRONG&gt;elevated&lt;/STRONG&gt; (Run as Administrator) command prompt&lt;/LI&gt;
&lt;LI&gt;Start the services&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;In addition to get rid of the error with the RIM Nodes please add the same key on all the RIM Nodes then restart the machines and redistribute the certificates.&lt;/P&gt;
&lt;H3&gt;Related Content:&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-to-recreate-or-just-delete-certificates-in-Qlik-Sense-No/ta-p/1712692" target="_blank" rel="noopener"&gt;How to recreate or just delete certificates in Qlik Sense - No access to QMC or Hub&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Fri, 19 Aug 2022 06:23:20 GMT</pubDate>
    <dc:creator>Daniele_Purrone</dc:creator>
    <dc:date>2022-08-19T06:23:20Z</dc:date>
    <item>
      <title>Qlik Sense Hub and Management Console down - Bootstrap fails Newly created client certificate not valid; root certificate can't sign new certificates</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Hub-and-Management-Console-down-Bootstrap-fails-Newly/ta-p/1715452</link>
      <description>&lt;P&gt;The Qlik Sense Enterprise hub and Management Console are down.&amp;nbsp;The Qlik Sense Repository Service (QRS) startup procedure does not complete.&lt;BR /&gt;&lt;BR /&gt;If recreating the certificates based on &lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-to-recreate-or-just-delete-certificates-in-Qlik-Sense-No/ta-p/1712692" target="_blank" rel="noopener"&gt;How to recreate or just delete certificates in Qlik Sense&lt;/A&gt;&amp;nbsp;does not resolve the issue.&lt;BR /&gt;&lt;BR /&gt;Manually running the bootstrap fails with error:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;[ERROR] Fatal exception during bootstrap: Newly created client certificate not valid; root certificate can't sign new certificates; see logs &amp;nbsp; &amp;nbsp;at Qlik.Sense.Communication.Security.CertSetup.ThrowAndLogFatalRootError(String msg)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;at Qlik.Sense.Common.Security.SecuritySetup.SetupCA(String externalRootCertThumbprint, ICipherAlgorithm secretsAlgorithm, Boolean forceNewSetup)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;at Repository.Core.Bootstrap.BootstrapHandler.Install(BootstrapState bootstrapState)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;at Repository.Core.Bootstrap.BootstrapHandler.Bootstrap(BootstrapState bootstrapState)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;at Repository.QRSMain.Bootstrap()&lt;BR /&gt;&amp;nbsp; &amp;nbsp;at Repository.QRSMain.Main()&lt;BR /&gt;Bootstrap mode has terminated. Press ENTER to exit..&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Joining a Rim node fails with incorrect password, even if the password was copied or typed correctly:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sebastian_Linser_0-1650525551323.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/77568i798B0049C292E347/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Sebastian_Linser_0-1650525551323.png" alt="Sebastian_Linser_0-1650525551323.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Other errors in the Qlik Sense Logs include:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Certificates are not correctly installed&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;20201022T144326.598+0200&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;STRONG&gt;ERROR&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;APP03&amp;nbsp;&amp;nbsp; &amp;nbsp;Security.Repository.Qlik.Sens&lt;WBR /&gt;e.Communication.Security.Certi&lt;WBR /&gt;ficates.CertUtil&amp;nbsp;&amp;nbsp; &amp;nbsp;44&amp;nbsp;&amp;nbsp; &amp;nbsp;c0cde05d-6354-46fb-a249-d7de9&lt;WBR /&gt;3aad09c&amp;nbsp;&amp;nbsp; &amp;nbsp;HELD-W2K\QlikService&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;STRONG&gt;When accessing certificate store&lt;/STRONG&gt;&amp;nbsp;(loc:LocalMachine, name:Root):&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Duplicate&amp;nbsp;&lt;/STRONG&gt;or invalid root certificates&amp;nbsp;&lt;STRONG&gt;are not allowed&lt;/STRONG&gt;;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Waiting for certificates&lt;/STRONG&gt;&amp;nbsp;and hostname&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;WARN&amp;nbsp;&amp;nbsp; &amp;nbsp;APP03&amp;nbsp;&amp;nbsp; &amp;nbsp;Security.Printing.Qlik.Sense.&lt;WBR /&gt;Communication.Security.Certifi&lt;WBR /&gt;cates.CertValidator&amp;nbsp;&amp;nbsp; &amp;nbsp;4&amp;nbsp;&amp;nbsp; &amp;nbsp;886518e5-f503-418c-b441-094d4&lt;WBR /&gt;ed4fc2f&amp;nbsp;&amp;nbsp; &amp;nbsp;HELD-W2K\QlikService&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;STRONG&gt;Certificate 'CN=QlikClient'&lt;/STRONG&gt;&amp;nbsp;(D24E4965A56C5D0764E9B5255670F&lt;WBR /&gt;38B01F8D9EF)&amp;nbsp;&lt;STRONG&gt;is invalid because it was not signed correctly&amp;nbsp;&lt;/STRONG&gt;by&amp;nbsp;886518e5-f503-418c-b441-094&lt;WBR /&gt;d4ed4fc2f&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Environment:&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Qlik Sense Enterprise, all versions&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 class="qlik-migrated-tkb-headings"&gt;&lt;STRONG&gt;Resolution:&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This issue is caused by access issues when attempting to access/recreate the certificates and/or other GPOs that affect certificates.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Example scenarios: &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;A GPO is in place which enforces duplication of the hostname-CA certificate. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;or&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;A GPO is in place which prevents the creation of a new certificate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It may also be possible that access to the certificate is not granted. In which case the following may help:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Stop the services&lt;/LI&gt;
&lt;LI&gt;Launch Regedit&lt;/LI&gt;
&lt;LI&gt;Locate &lt;SPAN&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb&lt;/SPAN&gt;.&lt;/LI&gt;
&lt;LI&gt;Add &lt;SPAN&gt;ProtectionPolicy&lt;/SPAN&gt; DWORD 32-bit with the value of 1.&lt;/LI&gt;
&lt;LI&gt;Run the bootstrap process again by running&amp;nbsp;&lt;STRONG&gt;"&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;I&gt;C:\Program Files\Qlik\Sense\Repository\Repository.exe" -bootstrap -standalone&amp;nbsp;&lt;/I&gt;&lt;/STRONG&gt;&lt;STRONG&gt;-restorehostname&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;from an&amp;nbsp;&lt;STRONG&gt;elevated&lt;/STRONG&gt; (Run as Administrator) command prompt&lt;/LI&gt;
&lt;LI&gt;Start the services&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;In addition to get rid of the error with the RIM Nodes please add the same key on all the RIM Nodes then restart the machines and redistribute the certificates.&lt;/P&gt;
&lt;H3&gt;Related Content:&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Support-Knowledge-Base/How-to-recreate-or-just-delete-certificates-in-Qlik-Sense-No/ta-p/1712692" target="_blank" rel="noopener"&gt;How to recreate or just delete certificates in Qlik Sense - No access to QMC or Hub&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 19 Aug 2022 06:23:20 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Hub-and-Management-Console-down-Bootstrap-fails-Newly/ta-p/1715452</guid>
      <dc:creator>Daniele_Purrone</dc:creator>
      <dc:date>2022-08-19T06:23:20Z</dc:date>
    </item>
  </channel>
</rss>

