-
cubicle9726
- Lurker
- Posts: 2
- Liked: never
- Joined: Mar 17, 2026 6:17 pm
- Full Name: Mike H
- Contact:
Hyper-V cluster gets untrusted when "Cluster Group" changes owner
When I move the "Cluster Group" containing "Cluster IP Address" and "Cluster Name" resources to a different node in our cluster it changes the certificate that is used by WinRM to that of the new node rather than having one dedicated to the cluster and that causes Veeam to no longer trust the cluster. I think this needs to be fixed on the cluster side but I can't find any documentation about it.
-
cubicle9726
- Lurker
- Posts: 2
- Liked: never
- Joined: Mar 17, 2026 6:17 pm
- Full Name: Mike H
- Contact:
Re: Hyper-V cluster gets untrusted when "Cluster Group" changes owner
Could someone verify that if they go to veeam backup and replication menu > options > security and export an xml file of their trusted hosts that their cluster has a different certificate fingerprint than any of the hosts in the cluster? Then I at least know that this is possible to setup.
-
jbarrow
- Lurker
- Posts: 1
- Liked: never
- Joined: May 02, 2018 2:13 pm
- Full Name: Jeffrey Barrow
- Contact:
Re: Hyper-V cluster gets untrusted when "Cluster Group" changes owner
It looks like the "Certificate" of the cluster name is the same as the cert for ONE of the members of that cluster.
I took before/after snapshots of the trusted certificate list and verified that the new cert it saw for the cluster was the existing cert for the other node (and this is just a 2 node cluster).
I'm thinking that the only way around this will be to set up a certificate authority in the hyper-v AD network, and set up each machine to automatically generate certs from that, and have the Veeam server trust the new CA. Will that work?
I took before/after snapshots of the trusted certificate list and verified that the new cert it saw for the cluster was the existing cert for the other node (and this is just a 2 node cluster).
I'm thinking that the only way around this will be to set up a certificate authority in the hyper-v AD network, and set up each machine to automatically generate certs from that, and have the Veeam server trust the new CA. Will that work?
Who is online
Users browsing this forum: No registered users and 2 guests