Jump to content


SCCMentor

Established Members
  • Posts

    47
  • Joined

  • Last visited

Everything posted by SCCMentor

  1. I tested this. I unchecked the box to remove eHTTP. I deleted the SMS Role SSL Certificate certificate from local machine. I wasn't able to select Not Selected - greyed out like you said. I then re-enabled eHTTP, it recreated the SMS Role SSL Certificate and I then set this in IIS.
  2. Yes that's the cert. Was it generated by Configmgr or did you copy it from the other box?
  3. From the list of certs in the IIS binding
  4. OK this will be potentially the problem then. So remove eHTTP by unchecking the box. Set the IIS SSL cert to 'Not selected' Keep an eye on the sitecomp and mpcontrol logs and ensure they complete removing eHTTP - just watch them until they stop churning over. Reenable the check box. Watch the sitecomp log again, keep an eye out for 'Detected change in SSLState for client settings' Then check back in certlm.msc for the SMS Role SSL Certificate cert in the personal store and then see if it's bound to IIS. At that point, restart the ccmexec services on the endpoint and see what clientidmanagerstartup log does. Does it get an 'Retrieved Certificate options successfully' entry and then check for cert?
  5. Do you have a cert called SMS Role SSL Certificate? This is generated by when enabling eHTTP and is automatically bound to IIS. If you were running full PKI previously it's possible that hasn't been set (I've seen this happen before where the SMS Role SSL Cert doesn't get generated due to an old PKI cert) Check for the cert in your certlm.msc console on the server running the MP Note also that the errors you have in the clientidmanagerstartup and cert maintenance logs - I get these also in my eHTTP site. I've noticed that the ConfigMgr applet doesn't have all the tabs and that the clientidmanager log still reports are registration pending. Does the client complete registration? Hard to know when we are working off screenshots. Cheers
  6. What cert is bound to IIS?
  7. The eHTTP MP should be sufficient for this to work. Has the SMS Role SSL Cert automatically bound to the IIS or been changed at all? Are you able to share the BitLockerManagementHandler log at all? Cheers Paul
  8. No. Since the process will need to talk to the MBAM endpoints
  9. This shows you how to add a .exe to ConfigMgr https://sccmentor.com/2013/06/12/deploying-exe-files-via-sccm-2012/
  10. Run a WMIC query on the machine to get the details CSProduct Get Name https://sccmentor.com/2013/05/20/find-out-the-computers-model-type-from-a-wmi-query/
  11. you can mount the wim and inject the cab files. https://sccmentor.com/2013/06/11/add-language-packs-to-an-offline-wim-file/
  12. BTW MS released a support matrix for Windows 10 ADK. It is not supported on 2012 https://blogs.technet.microsoft.com/enterprisemobility/2016/09/09/configuration-manager-and-the-windows-adk-for-windows-10-version-1607/
  13. Feel free to post any comments on my blog as well. I'd like to collate any notes from the field to assist people when running this in PROD environments. Cheers Paul
  14. Details from TechNet Package https://technet.microsoft.com/en-gb/library/gg682112.aspx?f=255&MSPPError=-2147217396 Applications https://technet.microsoft.com/en-gb/library/gg682159.aspx
  15. Give my script a go. As stated, use with caution on encrypted hard drives and ensure that encryption is disabled prior to running the script. https://gallery.technet.microsoft.com/Remove-partition-as-part-e4c6ec39
  16. Jeroen, Take a look at Jörgen's blog piece http://ccmexec.com/2015/12/customizing-the-taskbar-in-windows-10-during-osd/ which can be implemented via a Task Sequence. Windows 10 1607 allows for a managed XML file to achieve this rather than hacking away. The solution requires a reg export to re-populate the Taskbar icons. Maybe this is what you are missing from your UE-V set up.
  17. When sequencing perform a custom installation rather than select installer. When you get to the 'Install your applications now' screen, copy putty into the folder you want it to be in and create shortcuts in public desktop and start menus. You could modify the shortcuts to point to %USERPROFILE% instead. When all your config is done press I am finished installing. The custom install then picks up the changes you have made to the system.
  18. No issue downloading here. Direct link - http://hotfixv4.microsoft.com/ConfigMgrV5/sp1/ConfigMgr_2012_SP2_R2SP1_CU2_KB3100144_E/05.00.8239.1301/free/488307_ENU_x64_zip.exe
  19. Use the Content Library Transfer tool. Simple as.
  20. Have you tested this outside of a Tak Sequence on Windows 10 to ensure the end to end process works and therefore eliminating ConfigMgr as the cause or not?
  21. Try some of these https://sccmentor.wordpress.com/2014/03/18/a-little-bit-of-site-server-c-drive-housekeeping/
  22. It's a known issue and will more than likely be fixed in the next CU
  23. AbuNael - the preference is to install packages during the TS. Do this after the ConfigMgr client install
  24. Do you get enough information from Hardware Inventory? This will give you all apps installed in Add/Remove Programs? If not try out http://www.snowsoftware.com/int
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.