Observability
Website configuration failed due to SSL certificate mismatch on HTTPS binding
First published date
Last published date
Overview
When running the SolarWinds Configuration Wizard on the main polling engine, the Website step fails with “Website configuration failed” and the web console cannot be opened over HTTPS. The Check site certificates diagnostic reports that the SSL certificate bound to the SolarWinds website in IIS does not match what SolarWinds expects on the configured HTTPS binding (for example, https://<server>:8787).
Product section
Cause
The SSL certificate bound to the SolarWinds website’s HTTPS binding in IIS (for example, IP 192.168.1.56 on port 8787) does not match the certificate that SolarWinds expects, as detected by the Check site certificates diagnostic. As a result, the Website configuration step in the Configuration Wizard fails and the web console cannot be reached over HTTPS.
Resolution
-
Confirm the current HTTPS binding in IIS
-
Open IIS Manager on the SolarWinds main polling engine.
-
In the left pane, expand Sites and select the SolarWinds Platform (or SolarWinds Orion) website.
-
In the Actions pane, select Bindings….
-
Locate the https binding used by SolarWinds (for example, IP
192.168.30.56, port8787). -
Select the binding and click Edit….
-
Note the IP address, Port, and especially the SSL certificate currently selected. This is the binding that the diagnostic reports as having the wrong certificate.
-
-
Verify that the correct certificate exists and is valid
-
On the SolarWinds server, run
mmc.exe. -
Add the Certificates snap-in for the Computer account.
-
In Certificates (Local Computer), expand Personal → Certificates.
-
Locate the intended SolarWinds Platform certificate (for example, with a friendly name matching your SolarWinds site FQDN or
SolarWinds-Orion). -
Confirm that:
-
The certificate is not expired.
-
It has a private key.
-
The certificate chain is trusted (no errors when you open it).
-
-
If the correct certificate is missing or invalid, either:
-
Import the correct certificate (with private key) into Local Computer → Personal, or
-
Plan to let the Configuration Wizard create a new self-signed certificate and use that certificate for the SolarWinds website binding.
-
-
-
Re-bind the correct certificate to the HTTPS binding in IIS
-
Return to IIS Manager → Sites → SolarWinds Platform website → Bindings… → Edit for the HTTPS binding.
-
In SSL certificate, choose the correct, valid certificate from Local Computer → Personal.
-
Click OK to save the binding.
-
Ensure there is only one active HTTPS binding for the SolarWinds website on the expected IP and port combination (for example, IP
192.168.30.56, port8787). This aligns the IIS binding with what the diagnostic expects and removes the certificate mismatch condition.
-
-
Re-run the Configuration Wizard and complete the Website step
-
On the main polling engine, run the SolarWinds Configuration Wizard as an elevated administrator.
-
Proceed through the Database and Services steps as normal.
-
On the Website step:
-
Confirm that the site is configured to use HTTPS on the expected port (for example,
8787). -
If prompted for a certificate, select the same certificate you just bound in IIS.
-
-
Let the Configuration Wizard complete the Website configuration.
-
After the wizard finishes successfully, browse to the SolarWinds web console URL (for example,
https://<server>:8787/Orion/Login.aspx) and confirm that it loads without a Website configuration failed error.
-
Additional Notes:
-
If your environment uses a certificate issued by an internal or public CA, ensure the full chain (root and any intermediate CAs) is trusted on the SolarWinds server before binding the certificate in IIS.
-
If you allow the Configuration Wizard to generate a self-signed certificate, plan to replace it later with a production certificate that meets your organization’s security requirements.