When attempting to perform actions in Veeam Backup & Replication that initiate secure connections, those tasks may fail in environments where the Veeam Backup Server or other Windows-based component servers are either isolated from the internet or subject to significant firewall restrictions to outside servers.
Operations that may be affected include, but are not limited to:
When a connection is initiated, Veeam Backup & Replication components use certificates to establish gRPC connections over HTTPS. The Windows feature "Automatically update certificates in the Microsoft Root Certificate Program" checks for revoked certificates via an HTTP request to "ctldl.windowsupdate.com" with a 15-second timeout.
Since Veeam's gRPC connection timeout is also 15 seconds, if certificate verification takes too long then the connection fails.
At this time, two workarounds exist to resolve this issue:
Ensure that both the Veeam Backup Server and other Windows-based component servers have access to "ctldl.windowsupdate.com" over port 80. This allows Windows to successfully complete certificate revocation checks
If access to ctldl.windowsupdate.com cannot be granted, the "Automatically update certificates in the Microsoft Root Certificate Program" setting must be disabled in the Group Policy Editor on each affected component server.
More information about the Windows feature "Automatically update certificates in the Microsoft Root Certificate Program" can be found here:
If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case.
To submit feedback regarding this article, please click this link: Send Article Feedback
To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.
This form is only for KB Feedback/Suggestions, if you need help with the software open a support case