Jump to content


TeachMeSCCM

Clients not getting self singed certs

Recommended Posts

Hello

 

New to posting on this forum. I'll try my best

My Mp is setup to http

image.thumb.png.566480c4acbe0bd6e8005b7a0dbafb5b.png

When i changed it back I did reboot it.

I can d

I was having issue with machines losing there certs. Long story short my cert in my MMC store in the SMS folder was expired; I have taken over this 1/2 ass setup and I'm trying my best.

I was told that SCCM would automatically update the cert. This is not happening. I have found if I delete the old cert it created a new one. But now I'm still getting these errors

I have ensured my boundaries are good but I'm unable to get clients to get certificates I am going by IP addresses not subnet. This is happening for new and old clients. 

 

http://mysccm/sms_mp/.sms_aut?mplist goes to the XML file on both of my servers

 

http://mysccm/sms_mp/.sms_aut?mpcert works on both of my servers goes the the MPcertificate path with the long text

 

image.thumb.png.d9df3dc2edbb556ca86c5515aa9f52c2.png

 

image.thumb.png.5986b2b8814480d06022c14621e9bc33.png

 

 

I do have it setup a bit strange I'm doing the point the SMS and use PKI if it's there. I have tired it every other way and none of the ways work for me.

 

image.thumb.png.d0da6b2a0b4f254be5846d18e66efdcc.png

 

I have tired it like every single way and this way I can get a cert and it register but it never registers the client so I get the SCCM to install

Client Cert shows None and my Software store doesn't work won't update ect.

 

Let me know if you need more logs or info. This has been such a paint to figure out.

 

Share this post


Link to post
Share on other sites

So If I change it to just  HTTPS or HTTP check and take off the PKI and CRL uncheck both 

I also unchecked the Use configuration Manger-Gen cert

I get this error 

image.png.b6f43f82574dd9cef575fbae995341f8.png

 

image.thumb.png.bae2e1ee1f924529e2318c2a3bf41c0f.png

This is why I had to setup to look for the SMS cert and it looked like it at least got a cert in the past but same issue with the machine never registering 

Share this post


Link to post
Share on other sites

it's a bit unclear from your post but what is your actual goal here, are you trying to enable ConfigMgr in HTTPS mode (PKI) or are you trying to use e-http (enhanced http), or do you simply have client issues with invalid sms certs ?

 

Share this post


Link to post
Share on other sites

I am trying to use E http and the clients are not getting there certs. I use to get certs and after it expired I deleted the old one; as the system never auto updated it. I am still having this issue with many clients with all of the same error as above

 

SCCM installs but never gets a client cert.

 

I'm stuck with the Key 'ConfigMgrMigrationKey' not found, 0x80090016.    ClientIDManagerStartup  with no luck fixing it. See above errors

Share this post


Link to post
Share on other sites

I'm using the CCMclean and doing a fresh install with both the default ie site code

And the other with command line ccmsetup.exe /mp=Mine.mine.mine SMSSITECODE=mine

Here is what my logs say I am having this issue site wide. Old machines not getting updated certs and fresh installs/test vms all getting the same errors 

Both of my site servers show they have no client installed as well

Almost all my machines are like this

image.png.33ca2db3fa1589be540b453dc7282be7.png

Not getting a Client certificate; I see them in SCCM some say Client installed this is not Ture; when i check the pc's I see this

 

image.thumb.png.212906a65be894f33afe1fb6ecf354aa.png

image.thumb.png.702ff6b29b40e55df057d04c9c1be4f2.png

CCMexec

image.thumb.png.5b4caa24e9e99c77eb1bd8927b42aab2.png

 

Site Services are all green; please let me know if you need more info or logs I'm trying to figure this out. I really appreciate your help 

Edited by TeachMeSCCM
More info

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.