Share via

What issue is really being encountered by the Azure Key Vault VM extension on my Azure Arc Server?

Thomas Zook 25 Reputation points
2026-03-23T16:30:05.4533333+00:00

When installing the Azure Key Vault VM extension on my Azure Arc Server, it keeps failing with the error message:

Message: Extension Message: Failed to download one or more certificates and retries exhausted. The last error was: Refreshing 'REDACTED' failed with exception: Chain validation failed with critical error: CERT_TRUST_IS_NOT_TIME_VALID

I've independently verified that the Certificate and its chain certificates are valid(both as the certificate is being used elsewhere without issue, such as in a Azure Application Gateway, and I've used "Test-Certificate" on the certificate the extension downloaded and it passed without issue).

I've made sure that the Azure Connected Machine Agent is all the way up to date, the server has external internet access to verify the chain certificates, and I've tried uninstalling and reinstalling the extension without success.

Azure Arc
Azure Arc

A Microsoft cloud service that enables deployment of Azure services across hybrid and multicloud environments.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.