@Coolguy3289 Thanks for the log line. It points at a bug, not at your approach.
The installer creates a “FOG Agent CA” under the server root CA. It only creates it when the file is missing. If the root CA changes later (for example, you copy the old server’s /opt/fog/snapins/ssl onto the new box so existing clients keep trusting it), the agent CA stays signed by the first root. Every enrollment then fails with the error you see, and the agent gets a 503.
The fix is in PR #1810: the installer now re-creates the agent CA when the current root did not sign it.
To fix your server now, without waiting for the PR:
sudo grep PKI_AGENT_CA_CERT /opt/fog/.fog-pkiMove the .fogAgentCA.pem and .fogAgentCA.key files in that directory to a backup location. Then re-run the installer. It creates a new agent CA under your current root, and enrollment works.
You do not need your internal PKI for this. The FOG-generated root is fine for production.