spgsitsupport Posted November 9, 2015 Report post Posted November 9, 2015 MDT assisted TS. I can see that client package is downloaded during TS, but when the install happens (in Setup Windows and ConfigMgr step), it does not use local source, but tries to pull it via https:// I would expect it to install from existing local source (as it is all there) Anybody has any ideas why? Seb Quote Share this post Link to post Share on other sites More sharing options...
spgsitsupport Posted November 10, 2015 Report post Posted November 10, 2015 Anybody? After domain join (it is without reboot, as Setup Windows and ConfigMgr step does NOT have it programmed), CCM client setup insists on downloading setup files from https:// (instead of using local package) Download fails: Begin to select client certificate The 'Certificate Selection Criteria' was not specified, counting number of certificates present in 'MY' store of 'Local Computer'. There are no certificates in the 'MY' store. GetSSLCertificateContext failed with error 0x87d00280 Failed to get client version for sending state messages. Error 0x8004100e Params to send '5.0.8239.1203 Deployment Error: 0x87d00280, A Fallback Status Point has not been specified and no client was installed. Message with STATEID='315' will not be sent. Failed to send status 315. Error (87D00215) GetHttpRequestObjects failed for verb: 'CCM_POST', url: 'https://domain.local/ccm_system/request' GetDPLocations failed with error 0x87d00280 Failed to get DP locations as the expected version from MP 'https://domain.local'. Error 0x87d00280 Failed to get client version for sending state messages. Error 0x8004100e Params to send '5.0.8239.1203 Deployment Error: 0x87d00280, A Fallback Status Point has not been specified and no client was installed. Message with STATEID='101' will not be sent. Failed to send status 101. Error (87D00215) I can F8 & at command prompt import, import reg file Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Cryptography\AutoEnrollment] "AEPolicy"=dword:00000007 run certutil -pulse to obtain certificates, but by then I get error from ccmsetup: Downloading C:\_SMSTaskSequence\Packages\SP1000D6\ccmsetup.exe to C:\WINDOWS\ccmsetup\ccmsetup.exe Running as user "SYSTEM" Only one MP https://domain.local is specified. Use it. Domain joined client is in Intranet >>> Client selected the PKI Certificate [Thumbprint 5363BAB0A1546520B9D7C824F0154BF6EB883DEB] issued to 'MAINT-JVZHQ52.DOMAIN.local' File 'C:\WINDOWS\ccmsetup\vc50727_x64.exe' doesn't exist. File 'C:\WINDOWS\ccmsetup\MicrosoftPolicyPlatformSetup.msi' doesn't exist. File 'C:\WINDOWS\ccmsetup\WindowsFirewallConfigurationProvider.msi' doesn't exist. File 'C:\WINDOWS\ccmsetup\Silverlight.exe' doesn't exist. File 'C:\WINDOWS\ccmsetup\SCEPInstall.exe' doesn't exist. Failed to download client files by BITS. Error 0x800704dd Failed to get client version for sending state messages. Error 0x8004100e Params to send '5.0.8239.1203 Deployment Error 0x800704dd. Path https://domain.local/NOCERT_SMS_DP_SMSPKG$/SP100017' A Fallback Status Point has not been specified and no client was installed. Message with STATEID='309' will not be sent. Failed to send status 309. Error (87D00215) ccmsetup 10/11/2015 12:20:57 1864 (0x0748) Failed to download from DP 'https://domain.local/NOCERT_SMS_DP_SMSPKG$/SP100017', error 0x800704dd. PROPFIND 'https://domain.local/SMS_DP_SMSPKG$/SP100017' Using DP location https://domain.local/SMS_DP_SMSPKG$/SP100017 Failed to download client files by BITS. Error 0x800704dd Failed to download from DP 'https://domain.local/SMS_DP_SMSPKG$/SP100017', error 0x800704dd. Enumerated all 2 local DP locations but none of them is good. Fallback to MP. Failed to download client files by BITS. Error 0x800704dd Deleted file C:\WINDOWS\ccmsetup\ccmsetup.xml CcmSetup failed with error code 0x800704dd Obviously something is not happy (including me) How do people deal with SSL on MP? Is there a way to specify /source: switch for Setup Windows and ConfigMgr step? Or is that another design quirk? Seb Quote Share this post Link to post Share on other sites More sharing options...
spgsitsupport Posted November 11, 2015 Report post Posted November 11, 2015 Still no joy! Added certificate during Windows setup as per this or this Lost all https errors in the log, but client install still errors out. It still insist on downloading the source files INSTEAD of using the lot on the local drive (even the setup line specifies this!) Command line: "C:\_SMSTaskSequence\OSD\SP1000D6\ccmsetup.exe" /useronly /source:C:\_SMSTaskSequence\OSD\SP1000D6 /config:MobileClient.TCF /status:572 Copying config file from C:\_SMSTaskSequence\OSD\SP1000D6\MobileClient.TCF to folder C:\WINDOWS\ccmsetup\. Return result: 0x0 SslState value: 224 CCMHTTPPORT: 80 CCMHTTPSPORT: 443 CCMHTTPSSTATE: 31 CCMHTTPSCERTNAME: Lookup MP: HTTPS://sccm.sccm.domain.LOCAL FSP: sccm.domain.LOCAL CCMFIRSTCERT: 1 Config file: C:\WINDOWS\ccmsetup\MobileClientUnicode.tcf Retry time: 10 minute(s) MSI log file: C:\WINDOWS\ccmsetup\Logs\client.msi.log MSI properties: INSTALL="ALL" FSP="sccm.domain.LOCAL" SMSMP="HTTPS://sccm.domain.LOCAL" CCMDEBUGLOGGING="1" CCMLOGLEVEL="0" CCMLOGMAXSIZE="52488000" CCMLOGMAXHISTORY="5" CCMHTTPSSTATE="31" SMSCACHEFLAGS="PERCENTDISKSPACE;NTFSONLY" SMSCACHESIZE="15" SMSPROVISIONINGMODE="1" SMSSITECODE="SP1" CCMHTTPPORT="80" CCMHTTPSPORT="443" SMSSLP="HTTPS://sccm.domain.LOCAL" CCMFIRSTCERT="1" Source List: \\sccm.domain.local\SMSClient C:\_SMSTaskSequence\OSD\SP1000D6 \\sccm.domain.LOCAL\SMSClient MPs: https://sccm.domain.local No version of the client is currently detected. . . . . PROPFIND 'https://sccm.domain.local/NOCERT_SMS_DP_SMSPKG$/SP100017' Got 401 challenge Retrying with Windows Auth... PROPFIND 'https://sccm.domain.local/NOCERT_SMS_DP_SMSPKG$/SP100017' No transform available for this locale. Installation will proceed with no transformation. File 'C:\WINDOWS\ccmsetup\vcredist_x86.exe' doesn't exist. File 'C:\WINDOWS\ccmsetup\vcredist_x64.exe' doesn't exist. File 'C:\WINDOWS\ccmsetup\vc50727_x64.exe' doesn't exist. File 'C:\WINDOWS\ccmsetup\MicrosoftPolicyPlatformSetup.msi' doesn't exist. File 'C:\WINDOWS\ccmsetup\WindowsFirewallConfigurationProvider.msi' doesn't exist. File 'C:\WINDOWS\ccmsetup\Silverlight.exe' doesn't exist. File 'C:\WINDOWS\ccmsetup\SCEPInstall.exe' doesn't exist. Failed to download client files by BITS. Error 0x800704dd Failed to get client version for sending state messages. Error 0x8004100e Enumerated all 2 local DP locations but none of them is good. Fallback to MP. Failed to download client files by BITS. Error 0x800704dd Deleted file C:\WINDOWS\ccmsetup\ccmsetup.xml CcmSetup failed with error code 0x800704dd Quote Share this post Link to post Share on other sites More sharing options...
spgsitsupport Posted November 12, 2015 Report post Posted November 12, 2015 Days & days of testing & it always fails the same What is the purpose of client setup trying to download components from server when local copy is already available? Seb Quote Share this post Link to post Share on other sites More sharing options...
spgsitsupport Posted November 20, 2015 Report post Posted November 20, 2015 Seems that solution to this would be to make sure that there is NO MobileClient.tcf in the Client Package used for Setup Windows and ConfigMgr TS step WITHOUT MobileClient.tcf it does work Seb Quote Share this post Link to post Share on other sites More sharing options...