Forum Discussion

mr-roboto's avatar
mr-roboto
Tin Contributor
Jul 07, 2026

Import SSL failed 'Distribution Ubuntu-24.04-Mcc is not accessible from gMSA context'

I’m looking for assistance with troubleshooting issues importing a new SSL certificate purchased from Digicert. We are running MCC v2.0.0.2124_e with deployment application v1.0.24.0. Successfully generated the CSR, sent to Digicert and downloaded the signed certificate. Upon importing the certificate with gMSA on Windows Server 2022 we receive an error message "IMPORT_RESULT: FAILED, Certificate import failed”. 

 

I believe this is due to a known issue with the older deployment scripts v1.0.24.0. The following post acknowledges the issue and shows resolved in v1.0.26.0. 

 

Instructions mention “Then you may proceed to re-deploy your Connected Cache node…”.  Is re-deploying the MCC node is required to fix the issue?

 

I just updated the deployment scripts to v1.0.26.0 and attempted the certificate import again. Received error message "IMPORT_RESULT: FAILED, ERROR: Distribution Ubuntu-24.04-Mcc is not accessible from gMSA context”. 

 

Please let me know how to proceed. I can provide the logs for troubleshooting. If we need to start from scratch, do I need to generate another CSR request? Finally, are we able to use the Digicert certificate that we just purchased? 

1 Reply

  • Hi, the new error sounds like the updated script is now getting farther, but the gMSA cannot access the MCC WSL distribution/context it needs for the import.

     

    I would first confirm that the `Ubuntu-24.04-Mcc` distribution exists and is accessible under the same service/gMSA context used by the MCC deployment tools. Also check that the gMSA has the required local rights and that the scheduled task/service is actually running under the expected identity.

     

    If Microsoft's guidance says to re-deploy the Connected Cache node after moving to the fixed deployment scripts, I would take that seriously. Updating the script files may not fully repair an already-created WSL distribution or its permissions. You should not need to buy a new DigiCert certificate unless the private key/CSR material is lost or invalidated, but I would back up the cert files and logs before redeploying and confirm with the MCC support channel if this is production.