IQService Issue After Changing Service Log On As Account

Hi All,

I have an Active Directory connection that has been connected successfully, including using TLS for IQService. However, I have since changed the service “Log On As” account and am now seeing the following error:
Failed to connect to IQService. Please check TLS configuration for IQService: Remote host terminated the handshake

The new Log On As is a domain user, not the original local system account. Do we need to reimport the certificate as the new user?

Thanks

have you also ran the command IQService.exe -a <User/s> to add the new user?

Hi Sunny,

Yes, the domain user is registered and matches the running as user in the IQTrace.log

Thanks

Okay, can you try adding full control permission for this new users on the certificate you have imported,
open the mmc console, add snap in for certificates and then right click on cert , all tasks → manage private key and then add permission. After adding, restart IQService and then try.

1 Like

There it is!

We had added the full control in the registry, as the documentation describes, but not this step.

Thank you, Sunny!