Common Windows Issues: Key Management Server Activation

  • Last updated on: 2015-12-31
  • Authored by: Rackspace Support

Problem: Periodic activation requests to the KMS are rejected and the operating system is seen as unlicensed.

Cause: Windows cannot locate the Key Management Server (KMS) after changing the time zone of the Cloud Server. Now your Cloud Server’s system clock does not sync with the KMS.

Resolution: You will need to resynch your Cloud Server with the KMS server:

  1. Log in to your Cloud Server as Administrator (Start, All Programs, Accessories, right-click Command Prompt and select Run as Administrator).

  2. Choose the data center in the following table that corresponds to the location of your server and run the applicable command from the command prompt.

    Data Center Command
    ORD (Chicago) ping
    DFW (Dallas) ping
    IAD (Ashburn) ping
    LON (London) ping
    HKG (Hong Kong) ping
    SYD (Sydney) ping

    Note: If there is a reply, move on to step 3. No reply means that there is an interface, hardware, or routing issue.

  3. Set the KMS manually within the registry.

    Data Center Command
    ORD (Chicago) slmgr.vbs /skms
    DFW (Dallas) slmgr.vbs /skms
    IAD (Ashburn) slmgr.vbs /skms
    LON (London) slmgr.vbs /skms
    HKG (Hong Kong) slmgr.vbs /skms
    SYD (Sydney) slmgr.vbs /skms
  4. Request activation from the KMS:

    slmgr.vbs /ato

  5. If step 4 returns an error reading EXACTLY “0xC004F074 The Key Management Server (KMS) is unavailable”, run the following:

    w32tm /resync

  6. If the time on the Cloud Server is drastically different than what is on the KMS the resync will fail. At this point you will need to either set the time manually or configure the server to use an NTP instance over the internet.

    Data Center Command
    ORD (Chicago) net stop w32time
    w32tm /config / /syncfromflags:MANUAL
    net start w32time
    DFW (Dallas) net stop w32time
    w32tm /config / /syncfromflags:MANUAL
    net start w32time
    IAD (Ashburn) net stop w32time
    w32tm /config / /syncfromflags:MANUAL
    net start w32time
    LON (London) net stop w32time
    w32tm /config / /syncfromflags:MANUAL
    net start w32time
    HKG (Hong Kong) net stop w32time
    w32tm /config / /syncfromflags:MANUAL
    net start w32time
    SYD (Sydney) net stop w32time
    w32tm /config / /syncfromflags:MANUAL
    net start w32time
  7. Once the time is synced up, attempt the following:

    w32tm /resync slmgr.vbs /ato

  8. You will also need to open UDP port 123 to allow the sync.

  9. Make sure your firewall allows outbound connections to TCP port 1688.

Continue the conversation in the Rackspace Community.