Network Management
"CRL Connectivity Check" fails in Deployment Health on the SolarWinds Platform since Jan 15, 2025
A health check for CRL Connectivity fails in the SolarWinds Web Console due to Microsoft retiring Azure CDN services from the azureedge.net domain.
First published date
Last published date
Overview
On January 15, 2025, Microsoft retired Azure CDN services on the azureedge.net domain, which was used to check CRL connectivity. This causes the Health check item on the page at Settings > My Deployment > Deployment Health in the SolarWinds Web Console to fail and display as a potential issue. The error message states:
"The certificate is not valid for the required usage."
This issue does not affect installing or upgrading the SolarWinds Platform.
Product section
Cause
This issue occurs due to Microsoft retired the Azure CDN services on the Azureedge.net domain on January 15, 2025. The SolarWinds Platform was still referencing this domain in versions prior to 2025.1.1, causing the check to fail.
Resolution
To resolve this issue, please upgrade to SolarWinds Platform 2025.1.1 and above. If an upgrade is not possible, we recommend silencing this check.
- Log in to the SolarWinds Web Console and navigate to Settings > My Deployment > Deployment Health
- Click the Check box next to Check CRL Connectivity, and select Silence Check.
After upgrading, run the "Check CRL Connectivity" test to confirm resolution:
-
- Using Active Diagnostics (on the SolarWinds Server):
- Launch Active Diagnostics from the SolarWinds server.
- Click Run individual tests
- Locate Check CRL Connectivity under the Poller Health section.
- Click Run Test.
- Using the My Deployment Page (via Web Console):
- Go to Settings > My Deployment > Deployment Health.
- Find Check CRL Connectivity.
- Click Refresh Check.
- Using Active Diagnostics (on the SolarWinds Server):
Expected outcome after upgrade:
-
- If successful, you will see:
"No issues with CRL found." - If the issue persists, verify that:
- Your server has outbound internet access to Microsoft CRL endpoints.
- No firewall or proxy is blocking the updated URLs.
- If successful, you will see: