Effects in Ivanti:
When selecting a device, ivanti tries to gather feedback e.g. if the device is online or remote control service is available. If this agent feedback is not showing up for an online device or if it takes up to 20 seconds to occur, you should follow the instructions described in this document.
Effects in the five(9)s Console:
When a device is selected, you might see "client validation failed" beside the online indicator.
This validation ensures that the correct agent responds and if it is not successful, some console actions like Custom Buttons are not allowed to be used.
What causes this issue?
Ivanti is increasing the security level for Endpoint Manager. To ensure only code from Ivanti can be executed through the agent on managed devices, all DLLs and executables inside the EPM Agent are digitally signed with a code signing certificate of DigiCert.
In EPM 2020.1, the digital signature in the file, which is signed with a 3rd party code signing certificate became the “primary” validation, with .sig file as the backup. In 2021.1, the .sig files are gone, and the digital signature is the only option to validate the files.
When Ivanti EPM and five(9)s console access the client to validate the correct agent, the new certificate check will take place:
On a regular basis Windows (responsible for the OCSP flow) validates, if the EPM certificate was revoked for some reason. To do this, a DigiCert Certification Service (WEB PKI) will be contacted, which is hosted by the Akamai Content Delivery Network.
In some scenarios (VPN, special Networks, Proxy Settings, ...) this PKI infrastructure is not reachable.
This might cause delays up to 20 sec in the certificate validation process.
How to solve the issue:
Option A
If your corporate firewall and/or access control devices are configured to allow only a certain set of IP addresses to be accessed from your network, you need to include the DigiCert IP addresses to be able to access DigiCert via https
DigiCert services have new dedicated IP addresses since 10.01.2025
Check DigiCert Documentation now
Option B
Since Ivanti EPM 2024, you are able to disable the check per device.
Helpfull links:
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article