Jeff K Posted January 14, 2015 Report post Posted January 14, 2015 anything in particular i am looking for??? i am new to this Internet MP stuff and not too good at the certificates stuff. Quote Share this post Link to post Share on other sites More sharing options...
Peter van der Woude Posted January 14, 2015 Report post Posted January 14, 2015 Check if the request arrives and what the message is displayed. When it's a 403 message, look at the number behind that as it will provide more details about the exact error. Quote Share this post Link to post Share on other sites More sharing options...
Jeff K Posted January 16, 2015 Report post Posted January 16, 2015 now I copied all of the items in the client folder to the machine and it is starting to install, whether or not the client will connect is a different story but I stopped IIS and WWW service on the MP cleared the WWW logs before I started then rebooted the MP and checked and the MP is good. so I started on the client and it didn't work but again if I copy the client files to the machine then it starts the install. I don't want to do this on 40 machines or 400. here is the log from IIS, nothing connects. #Software: Microsoft Internet Information Services 8.5#Version: 1.0#Date: 2015-01-16 13:14:51#Fields: date s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status sc-bytes time-taken2015-01-16 ::1 GET /SMS_MP/.sms_aut MPLIST 443 - ::1 SMS_MP_CONTROL_MANAGER - 200 0 0 602 24542015-01-16 ::1 GET /SMS_MP/.sms_aut MPLIST 443 - ::1 SMS_MP_CONTROL_MANAGER - 200 0 0 602 382015-01-16 ::1 GET /SMS_MP/.sms_aut MPLIST 443 - ::1 SMS_MP_CONTROL_MANAGER - 200 0 0 602 372015-01-16 ::1 GET /SMS_MP/.sms_aut MPLIST 443 - ::1 SMS_MP_CONTROL_MANAGER - 200 0 0 602 522015-01-16 ::1 GET /SMS_MP/.sms_aut MPLIST 443 - ::1 SMS_MP_CONTROL_MANAGER - 200 0 0 602 292015-01-16 ::1 GET /SMS_MP/.sms_aut MPLIST 443 - ::1 SMS_MP_CONTROL_MANAGER - 200 0 0 602 412015-01-16 ::1 GET /SMS_MP/.sms_aut MPLIST 443 - ::1 SMS_MP_CONTROL_MANAGER - 200 0 0 602 352015-01-16 ::1 GET /SMS_MP/.sms_aut MPLIST 443 - ::1 SMS_MP_CONTROL_MANAGER - 200 0 0 602 1072015-01-16 ::1 GET /SMS_MP/.sms_aut MPLIST 443 - ::1 SMS_MP_CONTROL_MANAGER - 200 0 0 602 362015-01-16 ::1 GET /SMS_MP/.sms_aut MPLIST 443 - ::1 SMS_MP_CONTROL_MANAGER - 200 0 0 602 1032015-01-16 ::1 GET /SMS_MP/.sms_aut MPLIST 443 - ::1 SMS_MP_CONTROL_MANAGER - 200 0 0 602 93 Quote Share this post Link to post Share on other sites More sharing options...
Jeff K Posted January 16, 2015 Report post Posted January 16, 2015 I looked in the logs and some stuff isn't making sense. I am trying to figure out why it can send back FSP messages. Sending Fallback Status Point message, STATEID='500'.Failed to send status 500 to the FSP (87D0027E)Processing pending site assignment.Assigning to site 'IMP'LSIsSiteCompatible : Verifying Site Compatibility for <IMP>Using INF MP sccmlab.domain.com as lookup MP.Attempting to retrieve site information from lookup MP(s) via HTTPSRefreshing the Management Point List for site IMPRaising event: instance of CCM_CcmHttp_Status{ DateTime = "20150116141245.516000+000"; HostName = "sccmlab.domain.com"; HRESULT = "0x00000000"; ProcessID = 3900; StatusCode = 0; ThreadID = 4984;}; Refreshing trusted key informationRaising event: instance of CCM_CcmHttp_Status{ DateTime = "20150116141245.828000+000"; HostName = "sccmlab.domain.com"; HRESULT = "0x00000000"; ProcessID = 3900; StatusCode = 0; ThreadID = 4984;}; LSRefreshTrustedKeyInfo: Client is always on Internet. Skipping refresh from AD.Persisting the management point authentication information in WMIPersisted Management Point Authentication Information locallyRefreshing Certifcate Information over HTTPRaising event: instance of CCM_CcmHttp_Status{ DateTime = "20150116141246.249000+000"; HostName = "SCCMLAB.domain.com"; HRESULT = "0x00000000"; ProcessID = 3900; StatusCode = 0; ThreadID = 4984;}; Refreshed Certificate Information over HTTPLSGetSiteInformationFromManagementPoint('IMP'): Assignment Site Code [iMP], Version [5.00.7958.1000], Capabilities [<Capabilities SchemaVersion="1.0"/>], Client Operational Settings [<ClientOperationalSettings><Version>5.00.7958.1000</Version><SecurityConfiguration><SecurityModeMask>0</SecurityModeMask><SecurityModeMaskEx>480</SecurityModeMaskEx><HTTPPort>80</HTTPPort><HTTPSPort>443</HTTPSPort><CertificateStoreName></CertificateStoreName><CertificateIssuers>CN=nwtraders-NWDC02-CA-1; DC=nwtraders; DC=msft</CertificateIssuers><CertificateSelectionCriteria></CertificateSelectionCriteria><CertificateSelectFirstFlag>1</CertificateSelectFirstFlag><SiteSigningCert>308202F4308201DCA0030201020210166DDD5E5297ECAA45969EC299A3FC31300D06092A864886F70D01010B05003016311430120603550403130B53697465205365727665723020170D3134313232333230313732355A180F32313134313133303230313732355A3016311430120603550403130B536974652053657276657230820122300D06092A864886F70D01010105000382010F003082010A0282010100A764D4DF2C469C65AB28B4B0CFD9F8AB3692BAD9DBB2074F5144694AD82EE99958C2D1D1B2B815C7FD464FED386DE37FECEE5384EDA42B9B4651266F4C3F8297CF535AE8F3E67FB179D671847458A4C9BBFB10FF3843DD19BAE635B02115A3AE691FB1426AB472A99D54A92A747B42F3D40C16278959FE96AFF53B4EE5E43B1754231EAA7601A36CA8E518F65835EB0C9E0DE7D6091943592890DD84C99581C74E3F865C499B644E2FD725FBD2BE461C43E943E00D510558F4392D1CE75582A46132A09EC50BEDAEB6A5B053A4E352977FB913C332E4CC422DF402C2263FB1B51202AAA38BBDF9B5EEBB0363E98B978AA2562FD42B8B608AAFAB59E711DB369B0203010001A33C303A30220603551D11041B301982174E574943434D30312E6E77747261646572732E6D73667430140603551D25040D300B06092B060104018237650B300D06092A864886F70D01010B050003820101002C7291839729410C8713B1C342CA89434D64F76EDA860411FE9F6A34B9F4E457F0DF1A00CABB51E8DA466EB8214E9A805B5222AB7C777D1C14B4317F83A1A2FE909F520F2010C70B4C219F00207367825D20E43EDE04F131B5D9E9441C5AD0B267DFF6093290E50FBEBB6AB79EA3E5E2B670013F5FBAE5F8988F311F38598B46603B4B32AC27BFD85427E76B1973ACC760CE7CAA962BB93A169647BF846B740645E5BCD9A857C15D3182A65231F5E612A7D6647072754F2301987673C5C3C93EFE35F369E645E0429059F9098DD43344EDE15FE2CFB5F7B0CD95B306AAF69DE261002E88B950B7431FEF7E2DA6C46468F2DAF5A3E68F1F8A82D49F4ED53C5B95</SiteSigningCert></SecurityConfiguration></ClientOperationalSettings>].LSIsSiteVersionCompatible : Site Version '5.00.7958.1000' is compatible.LSIsSiteCompatible : Site <IMP> Version '5.00.7958.1000' is compatible.LSVerifySiteAssignment : Client can be assigned to site <IMP>.Client is on the internet. Verifying the existence of an internet facing MP prior to reassigning to the new siteCurrent AD site of machine is Default-First-Site-NameRaising event: instance of CCM_CcmHttp_Status{ DateTime = "20150116141246.966000+000"; HostName = "SCCMLAB.domain.com"; HRESULT = "0x00000000"; ProcessID = 3900; StatusCode = 0; ThreadID = 4984;}; Successfully reached INF MP at 'SCCMLAB.domain.com'. Client is able to reassign to new siteClient is not assigned to a site. Cannot get portal info.LSRefreshSecuritySettings: Client is always on Internet - skipping security settings refresh.Using INF MP sccmlab.domain.com as lookup MP.Attempting to retrieve site information from lookup MP(s) via HTTPSRefreshing the Management Point List for site IMPRaising event: instance of CCM_CcmHttp_Status{ DateTime = "20150116141247.653000+000"; HostName = "sccmlab.domain.com"; HRESULT = "0x00000000"; ProcessID = 3900; StatusCode = 0; ThreadID = 4984;}; Refreshing trusted key informationRaising event: instance of CCM_CcmHttp_Status{ DateTime = "20150116141248.012000+000"; HostName = "sccmlab.domain.com"; HRESULT = "0x00000000"; ProcessID = 3900; StatusCode = 0; ThreadID = 4984;}; Persisting the management point authentication information in WMIPersisted Management Point Authentication Information locallyRefreshing Certifcate Information over HTTPRaising event: instance of CCM_CcmHttp_Status{ DateTime = "20150116141248.339000+000"; HostName = "SCCMLAB.domain.com"; HRESULT = "0x00000000"; ProcessID = 3900; StatusCode = 0; ThreadID = 4984;}; Refreshed Certificate Information over HTTPLSGetSiteInformationFromManagementPoint('IMP'): Assignment Site Code [iMP], Version [5.00.7958.1000], Capabilities [<Capabilities SchemaVersion="1.0"/>], Client Operational Settings [<ClientOperationalSettings><Version>5.00.7958.1000</Version><SecurityConfiguration><SecurityModeMask>0</SecurityModeMask><SecurityModeMaskEx>480</SecurityModeMaskEx><HTTPPort>80</HTTPPort><HTTPSPort>443</HTTPSPort><CertificateStoreName></CertificateStoreName><CertificateIssuers>CN=nwtraders-NWDC02-CA-1; DC=nwtraders; DC=msft</CertificateIssuers><CertificateSelectionCriteria></CertificateSelectionCriteria><CertificateSelectFirstFlag>1</CertificateSelectFirstFlag><SiteSigningCert>308202F4308201DCA0030201020210166DDD5E5297ECAA45969EC299A3FC31300D06092A864886F70D01010B05003016311430120603550403130B53697465205365727665723020170D3134313232333230313732355A180F32313134313133303230313732355A3016311430120603550403130B536974652053657276657230820122300D06092A864886F70D01010105000382010F003082010A0282010100A764D4DF2C469C65AB28B4B0CFD9F8AB3692BAD9DBB2074F5144694AD82EE99958C2D1D1B2B815C7FD464FED386DE37FECEE5384EDA42B9B4651266F4C3F8297CF535AE8F3E67FB179D671847458A4C9BBFB10FF3843DD19BAE635B02115A3AE691FB1426AB472A99D54A92A747B42F3D40C16278959FE96AFF53B4EE5E43B1754231EAA7601A36CA8E518F65835EB0C9E0DE7D6091943592890DD84C99581C74E3F865C499B644E2FD725FBD2BE461C43E943E00D510558F4392D1CE75582A46132A09EC50BEDAEB6A5B053A4E352977FB913C332E4CC422DF402C2263FB1B51202AAA38BBDF9B5EEBB0363E98B978AA2562FD42B8B608AAFAB59E711DB369B0203010001A33C303A30220603551D11041B301982174E574943434D30312E6E77747261646572732E6D73667430140603551D25040D300B06092B060104018237650B300D06092A864886F70D01010B050003820101002C7291839729410C8713B1C342CA89434D64F76EDA860411FE9F6A34B9F4E457F0DF1A00CABB51E8DA466EB8214E9A805B5222AB7C777D1C14B4317F83A1A2FE909F520F2010C70B4C219F00207367825D20E43EDE04F131B5D9E9441C5AD0B267DFF6093290E50FBEBB6AB79EA3E5E2B670013F5FBAE5F8988F311F38598B46603B4B32AC27BFD85427E76B1973ACC760CE7CAA962BB93A169647BF846B740645E5BCD9A857C15D3182A65231F5E612A7D6647072754F2301987673C5C3C93EFE35F369E645E0429059F9098DD43344EDE15FE2CFB5F7B0CD95B306AAF69DE261002E88B950B7431FEF7E2DA6C46468F2DAF5A3E68F1F8A82D49F4ED53C5B95</SiteSigningCert></SecurityConfiguration></ClientOperationalSettings>].Refreshed security settings over MP here is the FSPstatemessage.log Failed to send location services HTTP failure message.[CCMHTTP] ERROR: URL=HTTP://SCCMLAB.domain.com/SMS_FSP/.sms_fsp, Port=80, Options=448, Code=0, Text=CCM_E_BAD_HTTP_STATUS_CODE Failed to send location services HTTP failure message.[CCMHTTP] ERROR: URL=HTTP://SCCMLAB.domain.com/SMS_FSP/.sms_fsp, Port=80, Options=480, Code=0, Text=CCM_E_BAD_HTTP_STATUS_CODE Successfully sent location services HTTP failure message.[CCMHTTP] ERROR: URL=HTTP://SCCMLAB.domain.com/SMS_FSP/.sms_fsp, Port=80, Options=480, Code=0, Text=CCM_E_BAD_HTTP_STATUS_CODE Successfully sent location services HTTP failure message.[CCMHTTP] ERROR: URL=HTTP://SCCMLAB.domain.com/SMS_FSP/.sms_fsp, Port=80, Options=480, Code=0, Text=CCM_E_BAD_HTTP_STATUS_CODE Successfully sent location services HTTP failure message.[CCMHTTP] ERROR: URL=HTTP://SCCMLAB.domain.com/SMS_FSP/.sms_fsp, Port=80, Options=480, Code=0, Text=CCM_E_BAD_HTTP_STATUS_CODE Successfully sent location services HTTP failure message.[CCMHTTP] ERROR: URL=HTTP://SCCMLAB.domain.com/SMS_FSP/.sms_fsp, Port=80, Options=480, Code=0, Text=CCM_E_BAD_HTTP_STATUS_CODE Successfully sent location services HTTP failure message.[CCMHTTP] ERROR: URL=HTTP://SCCMLAB.domain.com/SMS_FSP/.sms_fsp, Port=80, Options=480, Code=0, Text=CCM_E_BAD_HTTP_STATUS_CODE Successfully sent location services HTTP failure message.[CCMHTTP] ERROR: URL=HTTP://SCCMLAB.domain.com/SMS_FSP/.sms_fsp, Port=80, Options=480, Code=0, Text=CCM_E_BAD_HTTP_STATUS_CODE Successfully sent location services HTTP failure message.[CCMHTTP] ERROR: URL=HTTP://SCCMLAB.domain.com/SMS_FSP/.sms_fsp, Port=80, Options=480, Code=0, Text=CCM_E_BAD_HTTP_STATUS_CODE Successfully sent location services HTTP failure message.[CCMHTTP] ERROR: URL=HTTP://SCCMLAB.domain.com/SMS_FSP/.sms_fsp, Port=80, Options=480, Code=0, Text=CCM_E_BAD_HTTP_STATUS_CODE Successfully sent location services HTTP failure message. here is out of the clientidstartup [----- STARTUP -----]Machine: L00729OS Version: 6.1 Service Pack 1SCCM Client Version: 5.00.7958.1000'RDV' Identity store does not support backup.CCM Identity is in sync with Identity storesClient is set to use HTTPS when available. The current state is 480.Begin searching client certificates based on Certificate IssuersCertificate Issuer 1 [CN=nwtraders-NWDC02-CA-1; DC=nwtraders; DC=msft]Based on Certificate Issuer 'nwtraders-NWDC02-CA-1' found Certificate [Thumbprint 4D8D7531458995076E3C7D2F35D846FDBD175C3F] issued to 'L00729.company.local'Begin validation of Certificate [Thumbprint 4D8D7531458995076E3C7D2F35D846FDBD175C3F] issued to 'L00729.company.local'Completed validation of Certificate [Thumbprint 4D8D7531458995076E3C7D2F35D846FDBD175C3F] issued to 'L00729.company.local'Completed searching client certificates based on Certificate IssuersBegin to select client certificateBegin validation of Certificate [Thumbprint 4D8D7531458995076E3C7D2F35D846FDBD175C3F] issued to 'L00729.company.local'Completed validation of Certificate [Thumbprint 4D8D7531458995076E3C7D2F35D846FDBD175C3F] issued to 'L00729.company.local'>>> Client selected the PKI Certificate [Thumbprint 4D8D7531458995076E3C7D2F35D846FDBD175C3F] issued to 'L00729.company.local'Raising event: instance of CCM_ServiceHost_CertRetrieval_Status{ DateTime = "20150116141301.802000+000"; HRESULT = "0x00000000"; ProcessID = 1420; ThreadID = 3040;}; Failed to submit event to the Status Agent. Attempting to create pending event.Raising pending event: instance of CCM_ServiceHost_CertRetrieval_Status{ DateTime = "20150116141301.802000+000"; HRESULT = "0x00000000"; ProcessID = 1420; ThreadID = 3040;}; Client PKI cert is available.Initializing registration renewal for potential PKI issued certificate changes.Succesfully intialized registration renewal.[RegTask] - Executing registration task synchronously.Read SMBIOS (encoded): 5200390045003200580039004B00Evaluated SMBIOS (encoded): 5200390045003200580039004B00No SMBIOS ChangedSMBIOS unchangedSID unchangedHWID unchangedWindows To Go requires a minimum operating system of Windows 8GetSystemEnclosureChassisInfo: IsFixed=TRUE, IsLaptop=TRUEWindows To Go requires a minimum operating system of Windows 8Computed HardwareID=2:22BA17F582848D457E3D2F5435AE75E8C8C9AD0E Win32_SystemEnclosure.SerialNumber=R9E2X9K Win32_SystemEnclosure.SMBIOSAssetTag=No Asset Information Win32_BaseBoard.SerialNumber=1ZK3R16213L Win32_BIOS.SerialNumber=R9E2X9K Win32_NetworkAdapterConfiguration.MACAddress=<Not used on laptop>[RegTask] - Client is not registered. Sending registration request for GUID:660a9ab9-9a2d-46b7-8142-68e5cdd5d6ef ...RegTask: Failed to send registration request message. Error: 0x87d00231RegTask: Failed to send registration request. Error: 0x87d00231[RegTask] - Sleeping for 60 seconds ...[RegTask] - Client is not registered. Sending registration request for GUID:660a9ab9-9a2d-46b7-8142-68e5cdd5d6ef ... Quote Share this post Link to post Share on other sites More sharing options...
Peter van der Woude Posted January 16, 2015 Report post Posted January 16, 2015 To prevent jumping back-and-forth between threads, see the reply's here: https://social.technet.microsoft.com/Forums/en-US/7f087548-c4ff-42b5-a6ac-18e2cde123ba/internet-mp-not-allowing-clients-to-connect?forum=configmanagerdeployment Quote Share this post Link to post Share on other sites More sharing options...
Jeff K Posted January 16, 2015 Report post Posted January 16, 2015 Thanks, Peter, I am just trying to get all the help I can. for some reason this Internet MP is not working or there is something else wrong some where. Quote Share this post Link to post Share on other sites More sharing options...