Forum Discussion
Certificate Chain Not Trusted Error Effecting PowerBI Only
Hi,
In a SQL query that I have run several times before I am not receiving the following error:
Message=A connection was successfully established with the server, but then an error occurred during the login process. (provider: SSL Provider, error: 0 - The certificate chain was issued by an authority that is not trusted.)
However, I am still able to access the databases that I receive this error for on PowerBI via SQL Server Management Studio.
Does anyone have any insight onto why I would suddenly be running into this issue after not having issues with the databases effected before and how to resolve it?
This ended up being a fairly easy solution, in order to work around this issue I ended up just having to switch the connection type from MSFT account to Windows for any who encounter this issue in the future.
29 Replies
- deanj20Advocate I
Wanted to add that there is a new issue we received a fix from MS from, looks fairly recent (starting Feb 13 2024). We were getting "certificate chain not trusted" errors on servers for Power BI Reports that previosuly worked no issue, no change anywhere.
Documented here, search "PBI_SQL_TRUSTED_SERVERS": https://learn.microsoft.com/en-us/power-query/connectors/sql-server
Can confirm after 3 days of trial and error, adding this environment variable (PBI_SQL_TRUSTED_SERVERS) to "Environment variables for your account" with the problem server name did the trick. I did have to clear out the Connection data (File > Options and Settings > Data source settings - select DB and Clear Permissions). Then add the data source back.
Adding this to all the top Google hits to hopefully save others the pain.- James_SmithRegular Visitor
deanj20 Man, I want to thank you. You probably saved me hours of work, research and frustration!
This worked for me.
- _121188nhaRegular Visitor
Thank you
- AnonymousNot applicable
This worked for me too.
For those who want more detailed instructions:
- Open your Power BI Desktop app
- Click 'File'
- Click 'Options and Settings'
- Click 'Data Source settings'
- Select the offending SQL server instance, from the list of data sources
- Click 'Edit permissions' button at base of prompt screen
- In this new prompt screen, under the 'Credentials' section, click the 'Edit' button to open a new prompt and select 'Windows'
- Select either 'Use my current credentials' or 'Use alternate crednetials' (up to you, I just used mine)
- Click' Save' button to close this prompt and return to the 'Edit Permissions' prompt screen.
- In here there is an 'Encrypt connections' option. If your server accepts encrypted connections this will need to be ticked, mine doesn't and so I left it blank.
- If you're not sure, don't worry. When you click 'Refresh All' a prompt will tell you if you need to be unencrypted and you can come back and untick this box.
Does anyone know why this works?
In my organisation, my windows account is used as my MS account, so it is the same thing, so why does the MS option not work. It used to work, and has done for over a year, and what is more the Power BI cloud service data model continued refreshing, using the MS account, fine, whilst the desktop one refused too. Spoke with head of IT and he is is equally flummoxed, saying that becuase we use our windows accounts as our orgnisational MS ones, they're the same thing and so there should be no issue...feels like a Power BI glitch to me!- cliangFrequent Visitor
This worked for me! Thank you for the detailed instructions.
- shrushtiRegular Visitor
This worked for me .
- TMoneyyyyyyFrequent Visitor
This worked! Thank you!!
- WalTigFrequent Visitor
Sometimes you have to search in another direction. I read a lot about loading service certificate and/or setting "TrustServerCertificate" to true.
However, in our case (and it sounds more cases are like this) from one day to another the user (and only "one user") was not able to connect to SQL Server from power BI anymore. Nothing had changed in our environment. Solving the issue by some certificate did not sound right.
Try this (it solved our issue): make sure the user has the latest version of Power BI Desktop installed.
In Sep 2023 the user was still working with version May 2023. Just installing the newest version of Power BI Desktop enabled him to connect to SQL data again.
- dlcollinsRegular Visitor
Thank you for sharing, this also resolved my connection error.
- nicbottie-monFrequent Visitor
So, we're getting this error (similar to above) when connecting to the Azure Analysis Services Tabular Model, from Power BI Desktop...
A connection was successfully established with the server, but then an error occurred during the login process. (provider: SSL Provider, error: 0 - The certificate chain was issued by an authority that is not trusted.)\r\nStackTrace:\n at Microsoft.Data.ProviderBase.DbConnectionPool.TryGetConnection(DbConnection owningObject, UInt32 waitForMultipleObjectsTimeout, Boolean allowCreate, Boolean onlyOneCheckConnection, DbConnectionOptions userOptions, DbConnectionInternal& connection)\r\n at Microsoft.Data.ProviderBase.DbConnectionPool.TryGetConnection(DbConnection owningObject, TaskCompletionSource`1 retry, DbConnectionOptions userOptions, DbConnectionInternal& connection)\r\n at Microsoft.Data.ProviderBase.DbConnectionFactory
Where can one specify "Connection Properties" and choose "Trust server certificate" in Power BI Desktop?
Microsoft Support ticket guides us to that setting, like you can set in SSMS when Connecting to a SQL Server...In SSMS...
- AnonymousNot applicable
heoliv,
Make sure that the certificate used by the SQL Server is within the Trusted Root Certification Authorities store of the machine running the Power BI Desktop.
There are a similar thread and a blog for your reference.
http://community.powerbi.com/t5/Desktop/provider-SSL-provider-error-0-The-certificate-chain-was-issued/td-p/354074
https://powerbi.microsoft.com/en-us/blog/ssl-security-error-with-data-source/
Regards,
Lydia- heolivAdvocate I
Thanks Lydia, I saw these threads but since the connection works in SQL Server Management Studio I thought it may be something else? If not how do I locate the Certificate Authority the database I am connecting to uses? Thanks for the insight.
- AnonymousNot applicable
heoliv,
You would need to contact SQL Server database administrator about that where he stores the SSL certificate. Then import the certificate to the client computer that installs Power BI Desktop following the guide in the KB below.
https://support.microsoft.com/en-sg/help/316898/how-to-enable-ssl-encryption-for-an-instance-of-sql-server-by-using-mi
Regards,
Lydia
- RamyaKanakaMicrosoft Employee
I am getting this certificate error while i am trying to connect to SQL OnPrem source. I tried to connect to the same soure through excel and it works but it getting error in PowerBBi.
Any help please!
- Syndicate_AdminAdministrator
This worked for me- thank you!! Any idea as to why what caused it
- Syndicate_AdminAdministrator
One of my team member is facing similar issue. However the problem here is, he cannot switch to Windows Authentication mode due to same not being provided to every one for data security. We had given him datareader credentials and it was working fine for him till last few days since he start recieving this error. So any help on this.
- Syndicate_AdminAdministrator
Sometimes you have to search in another direction. I read a lot about loading service certificate and/or setting "TrustServerCertificate" to true.
However, in our case (and it sounds more cases are like this) from one day to another the user (and only "one user") was not able to connect to SQL Server from power BI anymore. Nothing had changed in our environment. Solving the issue by some certificate did not sound right.
Try this (it solved our issue): make sure the user has the latest version of Power BI Desktop installed.
In Sep 2023 the user was still working with version May 2023. Just installing the newest version of Power BI Desktop enabled him to connect to SQL data again.
- RAJARAMSRegular Visitor
Issue:
This issue occurs due to mismatches between the versions of Power BI and SQL Server. To resolve it, please follow the steps below, how to install SSL Certificate from your local machine which is available from sql server installed machine.Steps to Resolve:
Export the Certificate:
- On the server where SQL Server is installed, open MMC (Microsoft Management Console).
- Load the Certificates snap-in for the Computer account.
- Navigate to the certificate being used for SQL Server (typically found under Personal > Certificates).
- Right-click the certificate and select All Tasks > Export.
- Export the certificate without the private key in .cer format.
Install the Certificate on the Client:
- Copy the exported .cer file to the client machine.
- On the client machine, open MMC and add the Certificates snap-in for the Computer account.
- Import the .cer file into the Trusted Root Certification Authorities store.
Restart SQL Server Service:
- After the certificate is trusted, restart your SQL Server service and retry the connection.