PSU failing to start after a server restart

PSU failing to start after a server restart

avatar

Hey Folks,

I am getting the following error message after restarting the VM,

PowerShell Universal failed to start. Check the logs for more information.
Failed to load PowerShell Universal. The SSL connection could not be established, see inner exception. | Unable to read data from the transport connection: An existing connection was forcibly closed by the remote host.. | An existing connection was forcibly closed by the remote host.

Server Details:
Windows Server 2025
MSI Installer - version 2026.3.0

All Comments (5)

avatar

just to add to this,
this error is only happening when trying to get to the admin or portal pages.
all of my portal apps launch and I am able to access those directly through their links.

avatar

Hello @jameshennessy

Thank you for the additional detail. The fact that your Portal Apps are still launching and can be accessed directly is useful because it suggests that PSU is at least partially operational, while the Admin and Portal pages are encountering the SSL connection error.

To narrow this down, could you please provide the following:

- Was PSU 2026.3.0 a new installation or an upgrade? If it was an upgrade, which version were you running previously?
- Were the Admin and Portal pages working normally on 2026.3.0 before the VM restart?
- How is PSU hosted on this server: directly as a Windows service, through IIS, behind a reverse proxy, or another configuration?
- Please provide the relevant PSU log entries from the startup immediately after the restart, including the complete exception and inner exception surrounding the SSL failure.

For now, I would prefer to review the logs before recommending certificate, TLS, configuration, upgrade, or rollback changes, since the current error does not yet identify which connection is being closed.

Because this is a public forum, please sanitize all evidence before posting. Remove credentials, tokens, license keys, cookies, private keys, full connection strings, email addresses, usernames, customer data, tenant or account identifiers, internal domains, hostnames, IP addresses, and private URLs. Please do not upload unredacted HAR files, memory dumps, database backups, or complete configuration files to this public thread.

Best regards,
Ruben Tapia

avatar

Hi Ruben,
2026.3.0 was an upgrade, which was done as a result of the same issue as this, it was from version 2026.2.5
the admin and portal pages worked perfect since the upgrade.
PSU is hosted on a Windows 2025 VM, runs its PowershellUniversal service, IIS is installed along with a reverse proxy and URL rewrite

here is the log files in c:\program data\powershelluniversal\logs\PowershellHost

2026-10-02 15:36:33.347 +01:00 [ERR] PSUModulePath not set
2026-10-02 15:36:49.851 +01:00 [INF] Using object serializer: Quartz.Simpl.BinaryObjectSerializer, Quartz
2026-10-02 15:36:49.863 +01:00 [INF] Initialized Scheduler Signaller of type: Quartz.Core.SchedulerSignalerImpl
2026-10-02 15:36:49.864 +01:00 [INF] Quartz Scheduler created
2026-10-02 15:36:49.864 +01:00 [INF] RAMJobStore initialized.
2026-10-02 15:36:49.865 +01:00 [INF] Quartz Scheduler 3.14.0.0 - '9315779a-bc7c-49aa-8715-4e967985713f' with instanceId 'NON_CLUSTERED' initialized
2026-10-02 15:36:49.866 +01:00 [INF] Using thread pool 'Quartz.Simpl.DefaultThreadPool', size: 100
2026-10-02 15:36:49.868 +01:00 [INF] Using job store 'Quartz.Simpl.RAMJobStore', supports persistence: False, clustered: False
2026-10-02 15:36:49.879 +01:00 [INF] Scheduler 9315779a-bc7c-49aa-8715-4e967985713f_$_NON_CLUSTERED started.


here is log file in c:\program data\powershelluniversal\logs\system

2026-10-02 15:36:12.738 +01:00 [INF] Found development certificate. Thumbprint: {Thumbprint}
2026-10-02 15:36:12.786 +01:00 [INF] appsettings file exists: C:\ProgramData\PowerShellUniversal\appsettings.json
2026-10-02 15:36:12.858 +01:00 [INF] Using database connection string: Data Source=C:\ProgramData\UniversalAutomation\database.db
2026-10-02 15:36:14.182 +01:00 [INF] PowerShell Universal Version: 2026.3.0
2026-10-02 15:36:14.186 +01:00 [INF] OS Version: Microsoft Windows NT 10.0.26100.0
2026-10-02 15:36:14.186 +01:00 [INF] OS Architecture: x64
2026-10-02 15:36:14.186 +01:00 [INF] Process Architecture: x64
2026-10-02 15:36:14.187 +01:00 [INF] Node Name: {server name}
2026-10-02 15:36:14.270 +01:00 [INF] Starting PowerShell Universal...
2026-10-02 15:36:14.417 +01:00 [WRN] The entity type 'WorkflowDefinition' is configured to use schema 'Elsa', but SQLite does not support schemas. This configuration will be ignored by the SQLite provider.
2026-10-02 15:36:14.417 +01:00 [WRN] The entity type 'WorkflowInstance' is configured to use schema 'Elsa', but SQLite does not support schemas. This configuration will be ignored by the SQLite provider.
2026-10-02 15:36:14.462 +01:00 [INF] Acquiring an exclusive lock for migration application. See https://aka.ms/efcore-docs-migrations-lock for more information if this takes too long.
2026-10-02 15:36:14.515 +01:00 [INF] No migrations were applied. The database is already up to date.
2026-10-02 15:36:14.528 +01:00 [INF] Acquiring an exclusive lock for migration application. See https://aka.ms/efcore-docs-migrations-lock for more information if this takes too long.
2026-10-02 15:36:14.533 +01:00 [INF] No migrations were applied. The database is already up to date.
2026-10-02 15:36:14.643 +01:00 [INF] Acquiring an exclusive lock for migration application. See https://aka.ms/efcore-docs-migrations-lock for more information if this takes too long.
2026-10-02 15:36:14.659 +01:00 [INF] No migrations were applied. The database is already up to date.
2026-10-02 15:36:14.714 +01:00 [WRN] The entity type 'SerializedKeyValuePair' is configured to use schema 'Elsa', but SQLite does not support schemas. This configuration will be ignored by the SQLite provider.
2026-10-02 15:36:14.714 +01:00 [WRN] The entity type 'ActivityExecutionRecord' is configured to use schema 'Elsa', but SQLite does not support schemas. This configuration will be ignored by the SQLite provider.
2026-10-02 15:36:14.714 +01:00 [WRN] The entity type 'BookmarkQueueItem' is configured to use schema 'Elsa', but SQLite does not support schemas. This configuration will be ignored by the SQLite provider.
2026-10-02 15:36:14.714 +01:00 [WRN] The entity type 'StoredBookmark' is configured to use schema 'Elsa', but SQLite does not support schemas. This configuration will be ignored by the SQLite provider.
2026-10-02 15:36:14.714 +01:00 [WRN] The entity type 'StoredTrigger' is configured to use schema 'Elsa', but SQLite does not support schemas. This configuration will be ignored by the SQLite provider.
2026-10-02 15:36:14.714 +01:00 [WRN] The entity type 'WorkflowExecutionLogRecord' is configured to use schema 'Elsa', but SQLite does not support schemas. This configuration will be ignored by the SQLite provider.
2026-10-02 15:36:14.714 +01:00 [WRN] The entity type 'WorkflowInboxMessage' is configured to use schema 'Elsa', but SQLite does not support schemas. This configuration will be ignored by the SQLite provider.
2026-10-02 15:36:14.719 +01:00 [INF] Acquiring an exclusive lock for migration application. See https://aka.ms/efcore-docs-migrations-lock for more information if this takes too long.
2026-10-02 15:36:14.725 +01:00 [INF] No migrations were applied. The database is already up to date.
2026-10-02 15:36:14.868 +01:00 [INF] Running startup complete.
2026-10-02 15:36:14.895 +01:00 [INF] Checking for pending database migrations
2026-10-02 15:36:14.906 +01:00 [WRN] Activity descriptor Elsa.Parallel v1 was already registered for tenant null. Replacing with new descriptor
2026-10-02 15:36:14.910 +01:00 [INF] Current migration version: 3
2026-10-02 15:36:14.911 +01:00 [INF] Database migration check completed in 15ms
2026-10-02 15:36:15.504 +01:00 [INF] RPC services being provided by PowerShellUniversal.Automation.JobInvokerGrpcService: 4
2026-10-02 15:36:15.513 +01:00 [INF] RPC services being provided by PowerShellUniversal.Automation.TerminalService: 3
2026-10-02 15:36:15.523 +01:00 [INF] RPC services being provided by PowerShellUniversal.Authentication.AppTokenClient: 8
2026-10-02 15:36:15.530 +01:00 [INF] RPC services being provided by PowerShellUniversal.Authentication.IdentityClient: 6
2026-10-02 15:36:15.532 +01:00 [INF] Loading app tokens...
2026-10-02 15:36:15.532 +01:00 [WRN] Type cannot be serialized; ignoring: System.IDisposable
2026-10-02 15:36:15.532 +01:00 [WRN] Signature not recognized for PowerShellUniversal.IConfigurationSystemWatcher.Pause; method will not be bound
2026-10-02 15:36:15.532 +01:00 [WRN] Signature not recognized for PowerShellUniversal.IConfigurationSystemWatcher.CheckSum; method will not be bound
2026-10-02 15:36:15.536 +01:00 [INF] RPC services being provided by Universal.Server.Services.Configuration.ConfigurationSystemWatcher: 5
2026-10-02 15:36:15.555 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.AiAgentService: 5
2026-10-02 15:36:15.560 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.AiToolService: 5
2026-10-02 15:36:15.566 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.ComputerGroupService: 5
2026-10-02 15:36:15.573 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.DeploymentClient: 6
2026-10-02 15:36:15.578 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.EndpointDocumentationService: 5
2026-10-02 15:36:15.583 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.EndpointService: 5
2026-10-02 15:36:15.589 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.EnvironmentConfigService: 5
2026-10-02 15:36:15.594 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.EventHubService: 5
2026-10-02 15:36:15.601 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.FolderService: 5
2026-10-02 15:36:15.607 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.HealthCheckConfigService: 5
2026-10-02 15:36:15.618 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.ModuleConfigService: 5
2026-10-02 15:36:15.627 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.PortalComponentService: 5
2026-10-02 15:36:15.633 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.PortalPageService: 5
2026-10-02 15:36:15.639 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.PublishedFolderCommand: 5
2026-10-02 15:36:15.645 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.RoleService: 5
2026-10-02 15:36:15.653 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.ScheduleService: 7
2026-10-02 15:36:15.661 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.ScriptService: 7
2026-10-02 15:36:15.668 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.SettingsService: 5
2026-10-02 15:36:15.674 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.TagService: 5
2026-10-02 15:36:15.679 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.TerminalService: 5
2026-10-02 15:36:15.685 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.TriggerService: 5
2026-10-02 15:36:15.692 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.UserSessionService: 5
2026-10-02 15:36:15.695 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.UserSessionGrpcService: 1
2026-10-02 15:36:15.700 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.VariableService: 5
2026-10-02 15:36:15.720 +01:00 [INF] RPC services being provided by PowerShellUniversal.Configuration.VaultService: 5
2026-10-02 15:36:15.723 +01:00 [INF] RPC services being provided by PowerShellUniversal.Secrets.SecretManagerService: 1
2026-10-02 15:36:15.729 +01:00 [INF] RPC services being provided by PowerShellUniversal.Workflows.WorkflowActivityService: 3
2026-10-02 15:36:15.735 +01:00 [INF] RPC services being provided by PowerShellUniversal.Workflows.WorkflowModelService: 5
2026-10-02 15:36:15.751 +01:00 [INF] RPC services being provided by PowerShellUniversal.JobDataService: 14
2026-10-02 15:36:15.754 +01:00 [INF] RPC services being provided by PowerShellUniversal.BrandingService: 1
2026-10-02 15:36:15.756 +01:00 [WRN] Signature not recognized for PowerShellUniversal.Platform.ICacheService.GetCacheDataAsync; method will not be bound
2026-10-02 15:36:15.759 +01:00 [INF] RPC services being provided by PowerShellUniversal.CacheService: 5
2026-10-02 15:36:15.787 +01:00 [INF] RPC services being provided by PowerShellUniversal.PublicClient: 27
2026-10-02 15:36:15.788 +01:00 [INF] Loading app assets...
2026-10-02 15:36:15.796 +01:00 [INF] RPC services being provided by PowerShellUniversal.ComputerClient: 7
2026-10-02 15:36:15.798 +01:00 [WRN] Type cannot be serialized; ignoring: PowerShellUniversal.EndpointProfile
2026-10-02 15:36:15.798 +01:00 [WRN] Signature not recognized for PowerShellUniversal.IStatsService.TrackEndpoint; method will not be bound
2026-10-02 15:36:15.798 +01:00 [WRN] Type cannot be serialized; ignoring: PowerShellUniversal.EndpointProfile
2026-10-02 15:36:15.798 +01:00 [WRN] Signature not recognized for PowerShellUniversal.IStatsService.EndTrackEndpoint; method will not be bound
2026-10-02 15:36:15.801 +01:00 [INF] RPC services being provided by PowerShellUniversal.StatsService: 4
2026-10-02 15:36:15.802 +01:00 [INF] Initializing database...
2026-10-02 15:36:15.809 +01:00 [INF] RPC services being provided by Universal.Server.Services.DashboardGrpcClient: 7
2026-10-02 15:36:15.812 +01:00 [INF] RPC services being provided by host.TestExecutionService: 1
2026-10-02 15:36:15.819 +01:00 [INF] RPC services being provided by PowerShellUniversal.Testing.TestService: 6
2026-10-02 15:36:15.834 +01:00 [INF] RPC services being provided by PowerShellUniversal.IGitSettingsService: 12
2026-10-02 15:36:15.841 +01:00 [INF] RPC services being provided by UniversalAutomation.IPublicGitService: 3
2026-10-02 15:36:15.844 +01:00 [INF] RPC services being provided by UniversalAutomation.IPublicApiService: 1
2026-10-02 15:36:15.851 +01:00 [INF] RPC services being provided by UniversalAutomation.IPublicGitSyncService: 5
2026-10-02 15:36:15.985 +01:00 [WRN] HTTP/2 is not enabled for [::]:5000. The endpoint is configured to use HTTP/1.1 and HTTP/2, but TLS is not enabled. HTTP/2 requires TLS application protocol negotiation. Connections to this endpoint will use HTTP/1.1.
2026-10-02 15:36:16.003 +01:00 [INF] Now listening on: http://[::]:60370
2026-10-02 15:36:16.003 +01:00 [INF] Now listening on: http://[::]:5006
2026-10-02 15:36:16.003 +01:00 [INF] Now listening on: http://[::]:5000
2026-10-02 15:36:16.003 +01:00 [INF] Now listening on: https://[::]:5001
2026-10-02 15:36:16.004 +01:00 [INF] Application started. Press Ctrl+C to shut down.
2026-10-02 15:36:16.005 +01:00 [INF] Loading configuration files...
2026-10-02 15:36:16.005 +01:00 [INF] Hosting environment: Production
2026-10-02 15:36:16.005 +01:00 [INF] Content root path: C:\Program Files (x86)\Universal
2026-10-02 15:36:16.026 +01:00 [INF] Reading configuration for Vault
2026-10-02 15:36:16.068 +01:00 [INF] Reading configuration for LoggingTarget
2026-10-02 15:36:16.465 +01:00 [INF] Request starting HTTP/1.1 GET http://localhost:5000/api/v1/alive - null null
2026-10-02 15:36:16.749 +01:00 [INF] Executing endpoint 'UniversalAutomation.AliveController.Get (Universal.Server)'
2026-10-02 15:36:16.757 +01:00 [INF] Route matched with {action = "Get", controller = "Alive", page = ""}. Executing controller action with signature Microsoft.AspNetCore.Mvc.IActionResult Get() on controller UniversalAutomation.AliveController (Universal.Server).
2026-10-02 15:36:16.767 +01:00 [INF] Executing action method UniversalAutomation.AliveController.Get (Universal.Server) - Validation state: "Valid"
2026-10-02 15:36:16.929 +01:00 [INF] Executed action method UniversalAutomation.AliveController.Get (Universal.Server), returned result Microsoft.AspNetCore.Mvc.OkObjectResult in 157.1642ms.
2026-10-02 15:36:16.935 +01:00 [INF] Executing OkObjectResult, writing value of type '<>f__AnonymousType2`8[[System.Boolean, System.Private.CoreLib, Version=10.0.0.0, Culture=neutral, PublicKeyToken={public key token}],[System.Boolean, System.Private.CoreLib, Version=10.0.0.0, Culture=neutral, PublicKeyToken={public key token}],[System.String, System.Private.CoreLib, Version=10.0.0.0, Culture=neutral, PublicKeyToken={public key token}],[System.String, System.Private.CoreLib, Version=10.0.0.0, Culture=neutral, PublicKeyToken={public key token}],[System.Boolean, System.Private.CoreLib, Version=10.0.0.0, Culture=neutral, PublicKeyToken={public key token}],[System.Boolean, System.Private.CoreLib, Version=10.0.0.0, Culture=neutral, PublicKeyToken={public key token}],[System.String, System.Private.CoreLib, Version=10.0.0.0, Culture=neutral, PublicKeyToken={public key token}],[System.Boolean, System.Private.CoreLib, Version=10.0.0.0, Culture=neutral, PublicKeyToken={public key token}]]'.
2026-10-02 15:36:17.002 +01:00 [INF] Executed action UniversalAutomation.AliveController.Get (Universal.Server) in 240.6468ms
2026-10-02 15:36:17.002 +01:00 [INF] Executed endpoint 'UniversalAutomation.AliveController.Get (Universal.Server)'
2026-10-02 15:36:17.006 +01:00 [INF] Request finished HTTP/1.1 GET http://localhost:5000/api/v1/alive - 200 null application/json; charset=utf-8 543.9705ms
2026-10-02 15:36:18.748 +01:00 [INF][UniversalAutomation.Services.UniversalConfigurationService] Reading configuration for Tag
2026-10-02 15:36:18.791 +01:00 [INF][UniversalAutomation.Services.UniversalConfigurationService] Reading configuration for Variable
2026-10-02 15:36:19.283 +01:00 [INF][UniversalAutomation.Services.UniversalConfigurationService] Reading configuration for Translation
2026-10-02 15:36:19.297 +01:00 [INF][UniversalAutomation.Services.UniversalConfigurationService] Reading configuration for Settings
2026-10-02 15:36:19.849 +01:00 [INF][Microsoft.AspNetCore.Hosting.Diagnostics] Request starting HTTP/1.1 GET http://localhost:5000/api/v1/alive - null null
2026-10-02 15:36:21.014 +01:00 [ERR][Microsoft.AspNetCore.Diagnostics.ExceptionHandlerMiddleware] An unhandled exception has occurred while executing the request.
System.Net.Http.HttpRequestException: The SSL connection could not be established, see inner exception.
---> System.IO.IOException: Unable to read data from the transport connection: An existing connection was forcibly closed by the remote host..
---> System.Net.Sockets.SocketException (10054): An existing connection was forcibly closed by the remote host.
--- End of inner exception stack trace ---
at System.Net.Sockets.Socket.AwaitableSocketAsyncEventArgs.ThrowException(SocketError error, CancellationToken cancellationToken)
at System.Net.Sockets.Socket.AwaitableSocketAsyncEventArgs.System.Threading.Tasks.Sources.IValueTaskSource<System.Int32>.GetResult(Int16 token)
at System.Net.Security.SslStream.EnsureFullTlsFrameAsync[TIOAdapter](CancellationToken cancellationToken, Int32 estimatedSize)
at System.Runtime.CompilerServices.PoolingAsyncValueTaskMethodBuilder`1.StateMachineBox`1.System.Threading.Tasks.Sources.IValueTaskSource<TResult>.GetResult(Int16 token)
at System.Net.Security.SslStream.ReceiveHandshakeFrameAsync[TIOAdapter](CancellationToken cancellationToken)
at System.Net.Security.SslStream.ForceAuthenticationAsync[TIOAdapter](Boolean receiveFirst, Byte[] reAuthenticationData, CancellationToken cancellationToken)
at System.Net.Http.ConnectHelper.EstablishSslConnectionAsync(SslClientAuthenticationOptions sslOptions, HttpRequestMessage request, Boolean async, Stream stream, CancellationToken cancellationToken)
--- End of inner exception stack trace ---
at System.Net.Http.ConnectHelper.EstablishSslConnectionAsync(SslClientAuthenticationOptions sslOptions, HttpRequestMessage request, Boolean async, Stream stream, CancellationToken cancellationToken)
at System.Net.Http.HttpConnectionPool.ConnectAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken)
at System.Net.Http.HttpConnectionPool.CreateHttp11ConnectionAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken)
at System.Net.Http.HttpConnectionPool.InjectNewHttp11ConnectionAsync(QueueItem queueItem)
at System.Threading.Tasks.TaskCompletionSourceWithCancellation`1.WaitWithCancellationAsync(CancellationToken cancellationToken)
at System.Net.Http.HttpConnectionPool.SendWithVersionDetectionAndRetryAsync(HttpRequestMessage request, Boolean async, Boolean doRequestAuth, CancellationToken cancellationToken)
at System.Net.Http.DiagnosticsHandler.SendAsyncCore(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken)
at System.Net.Http.RedirectHandler.SendAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken)
at System.Net.Http.DecompressionHandler.SendAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken)
at System.Net.Http.HttpClient.<SendAsync>g__Core|83_0(HttpRequestMessage request, HttpCompletionOption completionOption, CancellationTokenSource cts, Boolean disposeCts, CancellationTokenSource pendingRequestsCts, CancellationToken originalCancellationToken)
at Devolutions.Licensing.DevolutionsLicenseManager.GetLicenseAsync(String serial, LicensingOptions options)
at Devolutions.Licensing.DevolutionsLicenseManager.RefreshAsync(String serial, LicensingOptions options)
at UniversalLicensing.LicenseManager.DecodeLicenseAsync(String licenseText) in D:\a\powershell-universal\powershell-universal\src\Licensing\LicenseManager.cs:line 84
at Universal.Server.Services.LicenseService.CacheLicenses(Boolean force) in D:\a\powershell-universal\powershell-universal\src\Universal.Server\Services\LicenseService.cs:line 365
at Universal.Server.Services.LicenseService.IsLicensed() in D:\a\powershell-universal\powershell-universal\src\Universal.Server\Services\LicenseService.cs:line 542
at PowerShellUniversal.Login.OnGet(String returnUrl) in D:\a\powershell-universal\powershell-universal\src\Universal.Server\Pages\Login.cshtml.cs:line 83
at Microsoft.AspNetCore.Mvc.RazorPages.Infrastructure.ExecutorFactory.ActionResultHandlerMethod.Execute(Object receiver, Object[] arguments)
at Microsoft.AspNetCore.Mvc.RazorPages.Infrastructure.PageActionInvoker.InvokeHandlerMethodAsync()
at Microsoft.AspNetCore.Mvc.RazorPages.Infrastructure.PageActionInvoker.InvokeNextPageFilterAsync()
at Microsoft.AspNetCore.Mvc.RazorPages.Infrastructure.PageActionInvoker.Rethrow(PageHandlerExecutedContext context)
at Microsoft.AspNetCore.Mvc.RazorPages.Infrastructure.PageActionInvoker.Next(State& next, Scope& scope, Object& state, Boolean& isCompleted)
at Microsoft.AspNetCore.Mvc.RazorPages.Infrastructure.PageActionInvoker.InvokeInnerFilterAsync()
at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeNextResourceFilter>g__Awaited|25_0(ResourceInvoker invoker, Task lastTask, State next, Scope scope, Object state, Boolean isCompleted)
at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Rethrow(ResourceExecutedContextSealed context)
at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Next(State& next, Scope& scope, Object& state, Boolean& isCompleted)
at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.InvokeFilterPipelineAsync()
--- End of stack trace from previous location ---
at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeAsync>g__Logged|17_1(ResourceInvoker invoker)
at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeAsync>g__Logged|17_1(ResourceInvoker invoker)
at Microsoft.AspNetCore.Routing.EndpointMiddleware.<Invoke>g__AwaitRequestTask|7_0(Endpoint endpoint, Task requestTask, ILogger logger)
at Microsoft.AspNetCore.Authorization.AuthorizationMiddleware.Invoke(HttpContext context)
at PowerShellUniversal.FeatureMiddleware.InvokeAsync(HttpContext context, RequestDelegate next) in D:\a\powershell-universal\powershell-universal\src\Universal.Server\Middleware\FeatureMiddleware.cs:line 42
at Microsoft.AspNetCore.Builder.UseMiddlewareExtensions.InterfaceMiddlewareBinder.<>c__DisplayClass2_0.<<CreateMiddleware>b__0>d.MoveNext()
--- End of stack trace from previous location ---
at PowerShellUniversal.DisallowedModeMiddleware.InvokeAsync(HttpContext context, RequestDelegate next) in D:\a\powershell-universal\powershell-universal\src\Universal.Server\Middleware\ModeMiddleware.cs:line 25
at Microsoft.AspNetCore.Builder.UseMiddlewareExtensions.InterfaceMiddlewareBinder.<>c__DisplayClass2_0.<<CreateMiddleware>b__0>d.MoveNext()
--- End of stack trace from previous location ---
at PowerShellUniversal.CspMiddleware.InvokeAsync(HttpContext context, RequestDelegate next) in D:\a\powershell-universal\powershell-universal\src\Universal.Server\Middleware\CspMiddleware.cs:line 28
at Microsoft.AspNetCore.Builder.UseMiddlewareExtensions.InterfaceMiddlewareBinder.<>c__DisplayClass2_0.<<CreateMiddleware>b__0>d.MoveNext()
--- End of stack trace from previous location ---
at Universal.Server.Middleware.RoutingMiddleware.Invoke(HttpContext httpContext, IPolicyEvaluator policyEvaluator) in D:\a\powershell-universal\powershell-universal\src\Universal.Server\Middleware\RoutingMiddleware.cs:line 176
at PowerShellUniversal.PSUMiddleware.InvokeAsync(HttpContext context, RequestDelegate next) in D:\a\powershell-universal\powershell-universal\src\Universal.Server\Middleware\PowerShellMiddleware.cs:line 15
at Microsoft.AspNetCore.Builder.UseMiddlewareExtensions.InterfaceMiddlewareBinder.<>c__DisplayClass2_0.<<CreateMiddleware>b__0>d.MoveNext()
--- End of stack trace from previous location ---
at Universal.Server.Middleware.RegexApiMiddleware.Invoke(HttpContext httpContext, IApiService apiService) in D:\a\powershell-universal\powershell-universal\src\Universal.Server\Middleware\RegexApiMiddleware.cs:line 19
at Swashbuckle.AspNetCore.SwaggerUI.SwaggerUIMiddleware.Invoke(HttpContext httpContext)
at Swashbuckle.AspNetCore.Swagger.SwaggerMiddleware.Invoke(HttpContext httpContext, ISwaggerProvider swaggerProvider)
at Universal.Server.Middleware.WindowsAuthMiddleware.InvokeAsync(HttpContext context, RequestDelegate next) in D:\a\powershell-universal\powershell-universal\src\Universal.Server\Middleware\WindowsAuthMiddleware.cs:line 58
at Microsoft.AspNetCore.Builder.UseMiddlewareExtensions.InterfaceMiddlewareBinder.<>c__DisplayClass2_0.<<CreateMiddleware>b__0>d.MoveNext()
--- End of stack trace from previous location ---
at Universal.Server.Middleware.SwaggerAuthenticationMiddleware.InvokeAsync(HttpContext context, RequestDelegate next) in D:\a\powershell-universal\powershell-universal\src\Universal.Server\Middleware\SwaggerAuthMiddleware.cs:line 51
at Microsoft.AspNetCore.Builder.UseMiddlewareExtensions.InterfaceMiddlewareBinder.<>c__DisplayClass2_0.<<CreateMiddleware>b__0>d.MoveNext()
--- End of stack trace from previous location ---
at Universal.Server.Middleware.McpAuthenticationMiddleware.InvokeAsync(HttpContext context, RequestDelegate next) in D:\a\powershell-universal\powershell-universal\src\Universal.Server\Middleware\McpAuthenticationMiddleware.cs:line 42
at Microsoft.AspNetCore.Builder.UseMiddlewareExtensions.InterfaceMiddlewareBinder.<>c__DisplayClass2_0.<<CreateMiddleware>b__0>d.MoveNext()
--- End of stack trace from previous location ---
at StackExchange.Profiling.MiniProfilerMiddleware.Invoke(HttpContext context) in C:\projects\dotnet\src\MiniProfiler.AspNetCore\MiniProfilerMiddleware.cs:line 112
at AspNetCoreRateLimit.RateLimitMiddleware`1.Invoke(HttpContext context) in D:\a\powershell-universal\powershell-universal\src\AspNetCoreRateLimit\Middleware\RateLimitMiddleware.cs:line 109
at Microsoft.AspNetCore.Session.SessionMiddleware.Invoke(HttpContext context)
at Microsoft.AspNetCore.Session.SessionMiddleware.Invoke(HttpContext context)
at Microsoft.AspNetCore.Diagnostics.ExceptionHandlerMiddlewareImpl.<Invoke>g__Awaited|10_0(ExceptionHandlerMiddlewareImpl middleware, HttpContext context, Task task)
2026-10-02 15:36:32.334 +01:00 [FTL][UniversalAutomation.StartupService] Failed to start PowerShell Universal.
System.Net.Http.HttpRequestException: The SSL connection could not be established, see inner exception.
---> System.IO.IOException: Unable to read data from the transport connection: An existing connection was forcibly closed by the remote host..
---> System.Net.Sockets.SocketException (10054): An existing connection was forcibly closed by the remote host.
--- End of inner exception stack trace ---
at System.Net.Sockets.Socket.AwaitableSocketAsyncEventArgs.ThrowException(SocketError error, CancellationToken cancellationToken)
at System.Net.Sockets.Socket.AwaitableSocketAsyncEventArgs.System.Threading.Tasks.Sources.IValueTaskSource<System.Int32>.GetResult(Int16 token)
at System.Net.Security.SslStream.EnsureFullTlsFrameAsync[TIOAdapter](CancellationToken cancellationToken, Int32 estimatedSize)
at System.Runtime.CompilerServices.PoolingAsyncValueTaskMethodBuilder`1.StateMachineBox`1.System.Threading.Tasks.Sources.IValueTaskSource<TResult>.GetResult(Int16 token)
at System.Net.Security.SslStream.ReceiveHandshakeFrameAsync[TIOAdapter](CancellationToken cancellationToken)
at System.Net.Security.SslStream.ForceAuthenticationAsync[TIOAdapter](Boolean receiveFirst, Byte[] reAuthenticationData, CancellationToken cancellationToken)
at System.Net.Http.ConnectHelper.EstablishSslConnectionAsync(SslClientAuthenticationOptions sslOptions, HttpRequestMessage request, Boolean async, Stream stream, CancellationToken cancellationToken)
--- End of inner exception stack trace ---
at System.Net.Http.ConnectHelper.EstablishSslConnectionAsync(SslClientAuthenticationOptions sslOptions, HttpRequestMessage request, Boolean async, Stream stream, CancellationToken cancellationToken)
at System.Net.Http.HttpConnectionPool.ConnectAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken)
at System.Net.Http.HttpConnectionPool.CreateHttp11ConnectionAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken)
at System.Net.Http.HttpConnectionPool.InjectNewHttp11ConnectionAsync(QueueItem queueItem)
at System.Threading.Tasks.TaskCompletionSourceWithCancellation`1.WaitWithCancellationAsync(CancellationToken cancellationToken)
at System.Net.Http.HttpConnectionPool.SendWithVersionDetectionAndRetryAsync(HttpRequestMessage request, Boolean async, Boolean doRequestAuth, CancellationToken cancellationToken)
at System.Net.Http.RedirectHandler.SendAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken)
at System.Net.Http.DecompressionHandler.SendAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken)
at System.Net.Http.HttpClient.<SendAsync>g__Core|83_0(HttpRequestMessage request, HttpCompletionOption completionOption, CancellationTokenSource cts, Boolean disposeCts, CancellationTokenSource pendingRequestsCts, CancellationToken originalCancellationToken)
at Devolutions.Licensing.DevolutionsLicenseManager.GetLicenseAsync(String serial, LicensingOptions options)
at Devolutions.Licensing.DevolutionsLicenseManager.RefreshAsync(String serial, LicensingOptions options)
at UniversalLicensing.LicenseManager.DecodeLicenseAsync(String licenseText) in D:\a\powershell-universal\powershell-universal\src\Licensing\LicenseManager.cs:line 84
at Universal.Server.Services.LicenseService.CacheLicenses(Boolean force) in D:\a\powershell-universal\powershell-universal\src\Universal.Server\Services\LicenseService.cs:line 365
at Universal.Server.Services.LicenseService.IsLicensed() in D:\a\powershell-universal\powershell-universal\src\Universal.Server\Services\LicenseService.cs:line 542
at PowerShellUniversal.Automation.JobService.TriggerEvent(EventType eventType, Object metadata, String metadataName, Boolean skipLicenseCheck) in D:\a\powershell-universal\powershell-universal\src\PowerShellUniversal.Automation\JobService.cs:line 530
at UniversalAutomation.StartupService.RunStartup(CancellationToken cancellationToken) in D:\a\powershell-universal\powershell-universal\src\Universal.Server\Services\StartupService.cs:line 570
at UniversalAutomation.StartupService.TryRunStartup(CancellationToken cancellationToken) in D:\a\powershell-universal\powershell-universal\src\Universal.Server\Services\StartupService.cs:line 278

avatar

just to add a little more to this,
while the portal apps are accessible and look to be working as normal.

my daily scripts attached to schedules have not run.

avatar

Hello @jameshennessy

Thank you for the additional information and logs. The stack trace is especially useful because the SSL failure occurs while PSU is attempting a licensing operation during startup.

I also noted your latest update that the Portal Apps remain accessible, but the scripts attached to your daily schedules have not run.

Could you please confirm the following?

- Did the scheduled scripts stop running immediately after the same VM restart that caused the Admin and Portal issue?
- Does this server require a proxy to access the Internet, or does it have direct outbound HTTPS access?
- Is any TLS or SSL inspection performed by a firewall, proxy, or other security appliance for outbound traffic from this server?
- Were there any recent changes to the proxy, firewall, TLS inspection, certificates, GPOs, or other network policies before the issue appeared?
- Which account type is the PowerShellUniversal Windows service running under: Local System, Network Service, or a dedicated service account?
- Are any HTTP_PROXY, HTTPS_PROXY, ALL_PROXY, or NO_PROXY environment variables configured on the server or for the PowerShellUniversal service account? You do not need to post their values, only whether they are configured.
- When the issue occurred previously on PSU 2026.2.5, did restarting, upgrading, or making any network-related change restore functionality?

For now, please do not make changes to the license file, certificates, IIS bindings, reverse proxy, firewall, or PSU configuration. I would like to establish whether the failed outbound SSL connection is related to the service context or network path first.

Best regards,
Ruben Tapia