Tech Community Live: Endpoint Manager edition
Jul 21 2022, 08:00 AM - 12:00 PM (PDT)

CMG "failed to decrypt app secret key" message

%3CLINGO-SUB%20id%3D%22lingo-sub-2171480%22%20slang%3D%22en-US%22%3ERE%3A%20CMG%20%22failed%20to%20decrypt%20app%20secret%20key%22%20message%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2171480%22%20slang%3D%22en-US%22%3EWe%20had%20the%20same%20thing.%20We%20had%20to%20delete%20the%20application%20and%20then%20redo%20it.%20Make%20sure%20the%20person%20signing%20in%20for%20the%20application%20has%20Global%20Admin%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2161058%22%20slang%3D%22en-US%22%3ECMG%20%22failed%20to%20decrypt%20app%20secret%20key%22%20message%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2161058%22%20slang%3D%22en-US%22%3E%3CP%3EUPDATE%2004%2F01%2F21%3A%26nbsp%3B%20After%20working%20with%20MS%20Support%20on%20these%20errors%20they%20said%3A%20%22%3C%2FP%3E%3CP%3EThis%20error%20may%20affect%20the%20sync%20with%20Intune%20via%20the%20tenant%20attach%20feature%2C%20apart%20from%20that%20everything%20would%20work%20as%20it%20is%20supposed%20to%20be.%20With%20tenant%20attach%20you%20can%20manage%20the%20SCCM%20client%20machines%20from%20the%20Endpoint%20manager%20console%20if%20this%20is%20something%20we%20don%E2%80%99t%20use%20then%20I%20think%20it%E2%80%99s%20safe%20to%20ignore%20this%20for%20now.%22%26nbsp%3B%20We%20are%20trying%20to%20leverage%20Intune%20for%20the%20onboarding%20of%20devices%20for%20simpler%20deployment%20of%20Defender%20ATP%20so%20for%20us%20this%20will%20need%20to%20be%20fixed.%26nbsp%3B%20If%20we%20do%20manage%20to%20fix%20it%20I'll%20edit%20this%20post%20again%20with%20the%20resolution.%26nbsp%3B%20Thanks!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20don't%20necessarily%20see%20anything%20broken%20here...%20looking%20more%20for%20somebody%20to%20confirm%20my%20thought%20that%20this%20particular%20log%20error%20can%20be%20safely%20ignored.%26nbsp%3B%20I%20see%20this%20in%20both%20the%26nbsp%3BCMGatewayNotificationWorker.log%20and%20the%20Status%20messages%20for%20SMS_SERVICE_CONNECTOR...%26nbsp%3B%20%26nbsp%3B%3C%2FP%3E%3CP%3EFailed%20to%20execute%20worker%20%22CMGatewayNotificationWorker%22%20with%20error%20%22Failed%20to%20decrypt%20app%20secret%20key%3A%20Decryption%20failed%20with%200%22.%20See%20CMGatewayNotificationWorker.log%20for%20further%20details.%26nbsp%3B%3C%2FP%3E%3CP%3ELogs%20it%20about%20every%2060%20mins.%26nbsp%3B%20%26nbsp%3BHowever%2C%20clients%20are%20getting%20content%2C%20the%20Connection%20Analyzer%20shows%20all%20green%20marks.%26nbsp%3B%20%26nbsp%3BAnd%20the%20CMG%20connection%20point%20server%20shows%20%22connected%22.%26nbsp%3B%20%26nbsp%3BLooking%20at%20other%20non-critical%20entries%20in%20the%26nbsp%3BSMS_SERVICE_CONNECTOR%20status%20messenges%20it%20appears%20that%20other%20%22workers%22%20are%20decrypting%20the%20secret%20key%20just%20fine%20as%20they%20start%20and%20finish%20their%20cycles%20without%20incident.%26nbsp%3B%20%26nbsp%3BI'm%20thinking%20for%20certain%20things%20this%20is%20expected%20or%20normal%20depending%20on%20how%20things%20are%20configured.%26nbsp%3B%3C%2FP%3E%3CP%3EAnybody%20know%20what%20this%20means%2C%20especially%20whether%20it's%20safe%20to%20ignore%20or%20should%20i%20keep%20digging%3F%3C%2FP%3E%3CP%3EThanks%20in%20advance!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2161058%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECloud-attached%20management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ECM%20current%20branch%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESite%20Setup%20and%20client%20deployment%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Regular Visitor

UPDATE 04/01/21:  After working with MS Support on these errors they said: "

This error may affect the sync with Intune via the tenant attach feature, apart from that everything would work as it is supposed to be. With tenant attach you can manage the SCCM client machines from the Endpoint manager console if this is something we don’t use then I think it’s safe to ignore this for now."  We are trying to leverage Intune for the onboarding of devices for simpler deployment of Defender ATP so for us this will need to be fixed.  If we do manage to fix it I'll edit this post again with the resolution.  Thanks!

 

I don't necessarily see anything broken here... looking more for somebody to confirm my thought that this particular log error can be safely ignored.  I see this in both the CMGatewayNotificationWorker.log and the Status messages for SMS_SERVICE_CONNECTOR...   

Failed to execute worker "CMGatewayNotificationWorker" with error "Failed to decrypt app secret key: Decryption failed with 0". See CMGatewayNotificationWorker.log for further details. 

Logs it about every 60 mins.   However, clients are getting content, the Connection Analyzer shows all green marks.   And the CMG connection point server shows "connected".   Looking at other non-critical entries in the SMS_SERVICE_CONNECTOR status messenges it appears that other "workers" are decrypting the secret key just fine as they start and finish their cycles without incident.   I'm thinking for certain things this is expected or normal depending on how things are configured. 

Anybody know what this means, especially whether it's safe to ignore or should i keep digging?

Thanks in advance!

1 Reply
We had the same thing. We had to delete the application and then redo it. Make sure the person signing in for the application has Global Admin