Jump to content


parmenakis

Wrong certificate - Machines disappearing from SCCM Console?

Recommended Posts

Hey guys,

 

I've done some googling a bit on this but can't find something with my specific circumstance, so I'm hoping you all can at least point me in the right direction.

 

We have a fairly simple SCCM instance deployed on our network: 1 site, 2 distribution points. Everything has been working well for the most part, with a couple little hiccups. We're using self-signed certificates for our SCCM infrastructure, but I noticed an issue with it the other day.

 

We have a Microsoft RDS/VDI server (we'll call it VDI1) that provides desktops to some of our employees. It is running all of the components of RDS (gateway, licensing, connection broker, etc), including hosting the website the employees use to connect. I noticed that this server, despite getting application updates and windows patches, the server isn't anywhere in any of my device collections or even under just "devices". It just doesn't exist. I reinstalled the client, and it showed up, but then disappeared 24 hours later.

 

One thing I noticed with this box is the website. It uses a certificate of *.domain.com for its website, and when i look at the configuration manager app in control panel, it shows "PKI" for certificate, instead of Self-Signed like all of the other boxes do. I'm thinking this might have something to do with it? Most of our other boxes that have this cert and are hosting websites are linux boxes, so I don't have a huge sample size. I've thought about rolling PKI out for our entire infrastructure, but I'm concerned that it will break SCCM, as its working well now (but IMO seems a bit fragile in general and doesn't like to be touched...though that could be me and my inexperience with it).

 

Any pointers or suggestions on where to look? Seems like most of the logs on this machine are still firing (though I disabled the SMS host as I didn't wnat it accidentally patching this weekend when I wasn't sure what collection it was a part of).

 

Thanks everyone! Let me know if you need me to attach anything, I'll be more than happy to.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.