Configuration Manager Internet Clients and Native Mode ForumDiscussion on the Internet Based Clients and running sites in Native Mode, certificate and SSL issues for System Center Configuration Manager© 2009 Microsoft Corporation. All rights reserved.Wed, 25 Nov 2009 21:32:42 Z20595b10-3c77-42f9-9b12-582bc73df5a3http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/5d5fa42a-0087-4bdf-8fe2-045618bfee43http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/5d5fa42a-0087-4bdf-8fe2-045618bfee43barrymcconnell62http://social.technet.microsoft.com/Profile/en-US/?user=barrymcconnell62native mode sccm client appears not to be using right certificate.I presently have a few computers that have multiple certs in the personal store. But i also have a cert that coresponds to the sccm  but it seems that my client is using a different cert that has been expired but for other reasons(being and edge exchange 2007 server)it can not be moved or deleted. any help would be greatly appreciated. <br/> <br/> <br/> <br/> ![LOG[Certificate issued to 'EDGE103' has expired.]LOG]!&gt;&lt;time=&quot;15:47:32.379+300&quot; date=&quot;11-19-2009&quot; component=&quot;ClientIDManagerStartup&quot; context=&quot;&quot; type=&quot;3&quot; thread=&quot;3832&quot; file=&quot;ccmcert.cpp:962&quot;&gt;<br/> &lt;![LOG[Certificate issued to 'EDGE103' has expired.]LOG]!&gt;&lt;time=&quot;15:47:32.379+300&quot; date=&quot;11-19-2009&quot; component=&quot;ClientIDManagerStartup&quot; context=&quot;&quot; type=&quot;3&quot; thread=&quot;3832&quot; file=&quot;ccmcert.cpp:962&quot;&gt;<br/> &lt;![LOG[Raising event:<br/> <br/> instance of CCM_ServiceHost_CertRetrieval_Status<br/> {<br/>     DateTime = &quot;20091119204732.379000+000&quot;;<br/>     HRESULT = &quot;0x80040282&quot;;<br/>     ProcessID = 1904;<br/>     ThreadID = 3832;<br/> };<br/> ]LOG]!&gt;&lt;time=&quot;15:47:32.379+300&quot; date=&quot;11-19-2009&quot;Thu, 19 Nov 2009 21:06:33 Z2009-11-25T21:32:42Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/754f5c7d-e2f9-4ae6-b0ad-53a6bcb723dfhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/754f5c7d-e2f9-4ae6-b0ad-53a6bcb723df.Tim Harrisonhttp://social.technet.microsoft.com/Profile/en-US/?user=.Tim%20HarrisonMachines downloading policy but not returning hardware/software reportsI have a strange issue occurring in my system right now where machines are downloading and receiving policy, but aren't returning hardware and software reports.  About half of my machines <strong>are</strong> returning hardware and software reports.  The machines are all imaged the same way, so I don't understand whats going on.  At first, I thought these machines weren't downloading policy, but just for testing purposes, I created an advertisement for one that wasn't reporting sw/hw and within minutes it &quot;Accepted&quot; the mandatory advertisement.  This tells me its receiving policy - please correct me if I'm wrong.<br/> <br/> What could cause this?  Some of the machines not reporting have been in the field well over a month and have had plenty of time to upload the reports.Mon, 14 Sep 2009 20:28:14 Z2009-11-25T12:58:33Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/b0f1f100-c1f5-4b6d-8085-fe02d551f485http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/b0f1f100-c1f5-4b6d-8085-fe02d551f485Jake Cohenhttp://social.technet.microsoft.com/Profile/en-US/?user=Jake%20CohenInternet only based workgroup clients won't install and Site Server signing certificate has the wrong OID value...I've come in to help out with a SCCM 2007 site where there were a few problems left after the installation was completed.  Primarily I was called in to get Internet only workgroup systems installed as SCCM 2007 clients.  The site is already in native mode and there is a subordinate CA and an Internet MP residing in the DMZ. <div><br/></div> <div>Let's put the internet clients aside for a minute...</div> <div><br/></div> <div>In trying to research <em>why</em> the internet clients won't install I found that the OID value entered into the CA template for the Site Server signing certificate is wrong, in fact I can't find the number anywhere on the internet.</div> <div><br/></div> <div>I've followed this article to ensure that the other certificates are correct and that the Site Server signing certificate is wrong:  <a href="http://technet.microsoft.com/en-us/library/bb680733.aspx">http://technet.microsoft.com/en-us/library/bb680733.aspx</a></div> <div><br/></div> <div>I've also found this problem, and while the solution sounds workable I am not sure as I've never had to replace a signing certificate.  <a href="http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/74abda47-33a0-4e0c-9516-eed2dc301ba5">http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/74abda47-33a0-4e0c-9516-eed2dc301ba5</a></div> <div><br/></div> <div>So what will I run into when I replace the signing certificate with one that has the correct OID information in it?  Is it likely that this problem also is part of why I cannot get my internet based clients up and running?</div> <div><br/></div> <div><br/></div> <div><br/></div> <div>Now back to the internet based clients...</div> <div><br/></div> <div>I have the Site Server signing certificate exported so that I can include it with the client install for the internet clients.  Also, currently there are no clients installed and running as internet only.</div> <div><br/></div> <div>Good news first.  We built a machine on the intranet and made it a part of AD, confirmed that the SCCM client was functional then moved the machine to the internet.  Once it was on the internet we initiated a HINV and verify that the inventory came back to the SCCM dB before we moved the system back to the intranet.  So we know that the MP is working, well at least to me that means the MP is working.</div> <div><br/></div> <div>For the internet clients, we are manually requesting a Client Authentication certificate from the subordinate CA in the DMZ (via the /certsrv website), approving the certificate, then retrieving it from the website.</div> <div><br/></div> <div>After the certificate is received we install the SCCM client using the following command via a batch file.</div> <div><br/></div> <div>ccmsetup.exe /source:C:\mylocalfolder /native:CRL CCMHOSTNAME=INETMPFQDN.domain.com SMSSIGNCERT=C:\mylocalfolder\SiteSignCert.cer SMSSITECODE=XYZ FSP=INETMPFQDN.domain.com CCMALWAYSINF=1</div> <div><br/></div> <div>Here are a few things that I've already found and corrected:</div> <div><ol> <li>The Subordinate CA did not have an internet accessible CRL or AIA, this was corrected and verified with Certutil - URL.</li> <li>The OID originally used for the internet client certificates was wrong, actually it was the same OID used for the Site signing certificates.</li> </ol> <div>And here is what I have in log files...</div> <div><br/></div> <div><span style="text-decoration:underline">IIS W3SVC1 log</span> from the internet MP (i've only included the relevant entries for my test system):</div> <div><br/></div> <div><span style="font-family:arial, sans-serif;font-size:13px;border-collapse:collapse;color:#222222">2009-11-19 19:02:00 W3SVC1 10.100.1.21 GET /sms_mp/.sms_aut mplist 443 - 71.71.194.84 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.1;+SV1) 403 7 64<br/>2009-11-19 19:13:43 W3SVC1 10.100.1.21 POST /SMS_FSP/.sms_fsp - 80 - 71.71.194.84 SMS+FSP 200 0 0<br/>2009-11-19 19:13:59 W3SVC1 10.100.1.21 POST /SMS_FSP/.sms_fsp - 80 - 71.71.194.84 ccmhttp 200 0 0</span></div> </div> <div><br/></div> <div><br/></div> <div><span style="text-decoration:underline">ClientLocation.log</span></div> <div><br/></div> <div> <div>Client assigned to site 'XYZ'<span style="white-space:pre"> </span>ClientLocation<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>GetCurrentManagementPointEx<span style="white-space:pre"> </span>ClientLocation<span style="white-space:pre"> </span>11/19/2009 2:14:02 PM<span style="white-space:pre"> </span>4008 (0x0FA8)</div> <div>Current Management Point is INETMPFQDN.domain.com with version 0 and capabilities: .<span style="white-space:pre"> </span>ClientLocation<span style="white-space:pre"> </span>11/19/2009 2:14:02 PM<span style="white-space:pre"> </span>4008 (0x0FA8)</div> <div><br/></div> <div><br/></div> <div><span style="text-decoration:underline">ClientIDManagerStartup.log</span></div> <div><br/></div> <div> <div>RegTask: Client is not registered. Sending registration request...<span style="white-space:pre"> </span>ClientIDManagerStartup<span style="white-space:pre"> </span>11/19/2009 2:24:03 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div>RegTask: Failed to send registration request message. Error: 0x80040231<span style="white-space:pre"> </span>ClientIDManagerStartup<span style="white-space:pre"> </span>11/19/2009 2:24:03 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div>RegTask: Failed to send registration request. Error: 0x80040231<span style="white-space:pre"> </span>ClientIDManagerStartup<span style="white-space:pre"> </span>11/19/2009 2:24:03 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div><br/></div> </div> <div><br/></div> <div><span style="text-decoration:underline">LocationServices.log</span></div> <div><br/></div> <div> <div>Sending Fallback Status Point message, STATEID='500'.<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:41 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>Processing pending site assignment.<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>Assigning to site 'XYZ'<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>LSVerifySiteVersion : Verifying Site Version for &lt;XYZ&gt;<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>LSVerifySiteVersion: Client is on Internet Enabled - skipping version verification.<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>Sending Fallback Status Point message, STATEID='700'.<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>Unknown task LSProxyMPModificationTask in non-quarantine - ignoring.<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>1124 (0x0464)</div> <div>Successfully processed pending site assignment.<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>Security settings update detected, restarting CcmExec.<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>3764 (0x0EB4)</div> <div>Security settings update detected, restarting CcmExec.<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>3764 (0x0EB4)</div> <div>Successfully stored new site signing certificate...<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>Name      : The site code of this site server is XYZ<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>Sha1 Hash : xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>Valid From: 2009-11-09, 21:27<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>Valid To  : 2010-11-09, 21:27<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>LSGetManagementPointForSite: Client is always on Internet - skipping AD look up.<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>Failed to retrieve AMP for site code 'XYZ' with error (0x80004005). Nulling existing entry in WMI<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>Persisted Default Management Point Location locally<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>Failed to reset certificate request times. (0x80041002)<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>Security settings update detected, restarting CcmExec.<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>3764 (0x0EB4)</div> <div>Security settings update detected, restarting CcmExec.<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>1712 (0x06B0)</div> <div>No security settings update detected.<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:46 PM<span style="white-space:pre"> </span>316 (0x013C)</div> <div>LSGetManagementPointForSite: Client is always on Internet - skipping AD look up.<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:57 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div>Failed to retrieve AMP for site code 'XYZ' with error (0x80004005). Nulling existing entry in WMI<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:57 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div>Persisted Default Management Point Location locally<span style="white-space:pre"> </span>LocationServices<span style="white-space:pre"> </span>11/19/2009 2:13:57 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div><br/></div> <div><br/></div> <div><span style="text-decoration:underline">CCMExec.log</span></div> <div><br/></div> <div> <div>The 'Certificate Store' is empty in the registry, using default store name 'MY'.<span style="white-space:pre"> </span>CCMEXEC<span style="white-space:pre"> </span>11/19/2009 2:13:57 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div>Raising event:</div> <div><br/></div> <div>instance of CCM_ServiceHost_CertRetrieval_Status</div> <div>{</div> <div><span style="white-space:pre"> </span>DateTime = &quot;20091119191357.477000+000&quot;;</div> <div><span style="white-space:pre"> </span>HRESULT = &quot;0x00000000&quot;;</div> <div><span style="white-space:pre"> </span>ProcessID = 2064;</div> <div><span style="white-space:pre"> </span>ThreadID = 2168;</div> <div>};</div> <div><span style="white-space:pre"> </span>CCMEXEC<span style="white-space:pre"> </span>11/19/2009 2:13:57 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div>[CCMHTTP] AsyncCallback(): -----------------------------------------------------------------<span style="white-space:pre"> </span>CCMEXEC<span style="white-space:pre"> </span>11/19/2009 2:14:02 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div>[CCMHTTP] AsyncCallback(): WINHTTP_CALLBACK_STATUS_SECURE_FAILURE Encountered<span style="white-space:pre"> </span>CCMEXEC<span style="white-space:pre"> </span>11/19/2009 2:14:02 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div>[CCMHTTP]                : dwStatusInformationLength is 4</div> <div><span style="white-space:pre"> </span>CCMEXEC<span style="white-space:pre"> </span>11/19/2009 2:14:02 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div>[CCMHTTP]                : *lpvStatusInformation is 0x1</div> <div><span style="white-space:pre"> </span>CCMEXEC<span style="white-space:pre"> </span>11/19/2009 2:14:02 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div>[CCMHTTP]            : WINHTTP_CALLBACK_STATUS_FLAG_CERT_REV_FAILED is set</div> <div><span style="white-space:pre"> </span>CCMEXEC<span style="white-space:pre"> </span>11/19/2009 2:14:02 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div>[CCMHTTP] AsyncCallback(): -----------------------------------------------------------------<span style="white-space:pre"> </span>CCMEXEC<span style="white-space:pre"> </span>11/19/2009 2:14:02 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div>Raising event:</div> <div><br/></div> <div>instance of CCM_CcmHttp_Status</div> <div>{</div> <div><span style="white-space:pre"> </span>DateTime = &quot;20091119191402.547000+000&quot;;</div> <div><span style="white-space:pre"> </span>HostName = &quot;INETFQDN.domain.com&quot;;</div> <div><span style="white-space:pre"> </span>HRESULT = &quot;0x80072f8f&quot;;</div> <div><span style="white-space:pre"> </span>ProcessID = 2064;</div> <div><span style="white-space:pre"> </span>StatusCode = 1;</div> <div><span style="white-space:pre"> </span>ThreadID = 2168;</div> <div>};</div> <div><span style="white-space:pre"> </span>CCMEXEC<span style="white-space:pre"> </span>11/19/2009 2:14:02 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div>Failed in WinHttpSendRequest API, ErrorCode = 0x2f8f<span style="white-space:pre"> </span>CCMEXEC<span style="white-space:pre"> </span>11/19/2009 2:14:02 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div>[CCMHTTP] HTTP ERROR: URL=http://INETMPFQDN.domain.com/ccm_system/request, Port=443, Protocol=https, SSLOptions=63, Code=12175, Text=ERROR_WINHTTP_SECURE_FAILURE<span style="white-space:pre"> </span>CCMEXEC<span style="white-space:pre"> </span>11/19/2009 2:14:02 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div>HandleRemoteSyncSend failed (0x80040231).<span style="white-space:pre"> </span>CCMEXEC<span style="white-space:pre"> </span>11/19/2009 2:14:02 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div>CForwarder_Sync::Send failed (0x80040231).<span style="white-space:pre"> </span>CCMEXEC<span style="white-space:pre"> </span>11/19/2009 2:14:02 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div>CForwarder_Base::Send failed (0x80040231).<span style="white-space:pre"> </span>CCMEXEC<span style="white-space:pre"> </span>11/19/2009 2:14:02 PM<span style="white-space:pre"> </span>2168 (0x0878)</div> <div><br/></div> <div><br/></div> <div>One last thing, there is no MP_RegistrationManager.log on the internet MP yet...</div> <div><br/></div> <div><br/></div> <div>Well I believe that is about it  any help would be greatly appreciated!</div> <div><br/></div> <div>-Jake Cohen</div> </div> </div> </div>Fri, 20 Nov 2009 01:58:21 Z2009-11-24T23:04:42Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/5f3782a7-5746-4161-b843-9553cc957de2http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/5f3782a7-5746-4161-b843-9553cc957de2.Tim Harrisonhttp://social.technet.microsoft.com/Profile/en-US/?user=.Tim%20HarrisonProblem with machines moving into and out of the domainI'm having a problem with some laptops that were recently imaged onto the domain (with certs, client configured for LAN, etc.)  for a two-day training class and then re-imaged with our external, non-domain image (with certs, client configured for IBCM, etc.).  It seems that when they're imaged to the domain, they register with the SCCM server with no problems, send in hardware scans, etc., but then when they're re-imaged again with an external image, they don't seem to overwrite the &quot;domain version&quot;.  So, I end up with either the old &quot;domain version&quot; of the machine in the SCCM database or two machines with the same system name but one on the domain and the other in a workgroup.  The computer account will not be removed automatically until it hasn't contacted the domain in 90 days.  Is SCCM supposed to be able to manage machines that are moved to and from the domain or should I have deleted the computer account in both AD and SCCM before re-imaging them to be used on a workgroup via IBCM?<br/> <br/> ThanksTue, 24 Nov 2009 20:47:49 Z2009-11-24T20:47:50Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/61a461d8-831e-4890-9b28-ff5cf490ed9ahttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/61a461d8-831e-4890-9b28-ff5cf490ed9aJames_Tiger_Woodshttp://social.technet.microsoft.com/Profile/en-US/?user=James_Tiger_WoodsPossible incorrectly named certificate on the Internet facing site systemThis is an extension to the question I asked earlier. I think the problem I have is related to certificates as I am now getting some other errors.<br/> <br/> In the mpcontrol log, I have an error about certificates not being in the MY store. Resolved that, but now I get these: <br/> <br/> <blockquote>The 'Certificate Selection Criteria' was not specified, counting number of certificates present in 'MY' of 'Local Computer' store.    SMS_MP_CONTROL_MANAGER    04/11/2009 11:01:18    4012 (0x0FAC) <br/> <br/> The 'MY' of 'Local Computer' store has 2 certificate(s).~Using custom selection criteria based on the machine name.    SMS_MP_CONTROL_MANAGER    04/11/2009 11:01:18    4012 (0x0FAC) <br/> <br/> Machine name is '2k3internet'.    SMS_MP_CONTROL_MANAGER    04/11/2009 11:01:18    4012 (0x0FAC) <br/> <br/> There are no certificate(s) that meet the criteria.    SMS_MP_CONTROL_MANAGER    04/11/2009 11:01:18    4012 (0x0FAC) <br/> <br/> Performing machine FQDN to SAN2 search.    SMS_MP_CONTROL_MANAGER    04/11/2009 11:01:18    4012 (0x0FAC) <br/> <br/> Certificate doesn't have SAN2 extension.    SMS_MP_CONTROL_MANAGER    04/11/2009 11:01:18    4012 (0x0FAC) <br/> <br/> Found a certificate with subject name as ‘sccm-ent.SCCM_ENT.local’, but will continue to look for the certificate with subject name as ‘2k3internet’.    SMS_MP_CONTROL_MANAGER    04/11/2009 11:01:18    4012 (0x0FAC) <br/> <br/> Using custom selection criteria based on the machine NetBIOS name.    SMS_MP_CONTROL_MANAGER    04/11/2009 11:01:18    4012 (0x0FAC) <br/> <br/> Machine name is '2K3INTERNET'.    SMS_MP_CONTROL_MANAGER    04/11/2009 11:01:18    4012 (0x0FAC) <br/> <br/> There are no certificate(s) that meet the criteria.    SMS_MP_CONTROL_MANAGER    04/11/2009 11:01:18    4012 (0x0FAC) <br/> <br/> Call to HttpSendRequestSync failed for port 443 with an error code.    SMS_MP_CONTROL_MANAGER    04/11/2009 11:01:18    4012 (0x0FAC) <br/> <br/> Successfully performed Management Point availability check against local computer.    SMS_MP_CONTROL_MANAGER    04/11/2009 11:01:18    4012 (0x0FAC) <br/> <br/> Initialization still in progress.    SMS_MP_CONTROL_MANAGER    04/11/2009 11:01:18    4012 (0x0FAC) <br/></blockquote> <br/> The plot thickens. In the mpretry log, I've gone from this: <br/> <br/> <blockquote> Hinv Retry: ******************* Start of Task *********************    RetryManager    04/11/2009 11:07:28    2788 (0x0AE4)<br/> CMPDBConnection::Init(): IDBInitialize::Initialize() failed with 0x80004005    RetryManager    04/11/2009 11:08:31    2788 (0x0AE4)<br/> =======================================    RetryManager    04/11/2009 11:08:31    2788 (0x0AE4)<br/> <br/> MPDB ERROR - CONNECTION PARAMETERS<br/> SQL Server Name     : SCCM-ENT<br/> SQL Database Name   : SMS_SC0<br/> Integrated Auth     : True<br/> <br/> MPDB ERROR - EXTENDED INFORMATION<br/> MPDB Method         : Init()<br/> MPDB Method HRESULT : 0x80004005<br/> Error Description   : [DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.<br/> OLEDB IID           : {0C733A8B-2A1C-11CE-ADE5-00AA0044773D}<br/> ProgID              : Microsoft OLE DB Provider for SQL Server<br/> <br/> MPDB ERROR - INFORMATION FROM DRIVER<br/> Native Error no.  : 17<br/> Error State       : 1<br/> Class (Severity)  : 16<br/>     RetryManager    04/11/2009 11:08:31    2788 (0x0AE4)<br/> =======================================<br/>     RetryManager    04/11/2009 11:08:31    2788 (0x0AE4)<br/> Hinv Retry: IMPDBConnection::Init() for class failed.    RetryManager    04/11/2009 11:08:31    2788 (0x0AE4)</blockquote> To this:<br/> <blockquote>Hinv Retry: ******************* Start of Task *********************    RetryManager    04/11/2009 11:18:31    2176 (0x0880)<br/> Hinv Retry: Loaded class definition map; DB policy timestamp: 2009-05-27 21:56:17.597    RetryManager    04/11/2009 11:18:36    2176 (0x0880)<br/> Hinv Retry: Normalized DB policy timestamp: 20090527215617.000000+000.    RetryManager    04/11/2009 11:18:36    2176 (0x0880)<br/> Hinv Retry: Looking for retry files in C:\SMS\mp\outboxes\hinv.box\retry\*.hml    RetryManager    04/11/2009 11:18:36    2176 (0x0880)<br/> Hinv Retry: no files found in the HINV retry directory    RetryManager    04/11/2009 11:18:36    2176 (0x0880)<br/> Hinv Retry: ******************* End of Task *********************    RetryManager    04/11/2009 11:18:36    2176 (0x0880)</blockquote> Not sure how, but I'm happy so far.<br/> <br/> The error in the MPControl log is as at the beginning which suggests that the certificate is wrong.<br/> <br/> However, the Internet facing machine isn't in the same domain so the certificate that I brought over (the Web and Client) originates from the domain/machine as the Primary server. As a result, the name is incorrect, which I assume is why I get this:<br/> <blockquote>Found a certificate with subject name as ‘sccm-ent.SCCM_ENT.local’, but will continue to look for the certificate with subject name as ‘2k3internet’.    SMS_MP_CONTROL_MANAGER    04/11/2009 11:01:18    4012 (0x0FAC) <br/></blockquote> What do I need to check or do as I can't find anything anywhere to help...Wed, 04 Nov 2009 11:46:43 Z2009-11-23T18:38:21Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/fa059170-6635-4e51-b183-6f3520677815http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/fa059170-6635-4e51-b183-6f3520677815James_Tiger_Woodshttp://social.technet.microsoft.com/Profile/en-US/?user=James_Tiger_WoodsInternet based site server connection problemI hope this is a simple one (!)..... <br/> <br/> I'm doing internet based management which, I'm sure has been done by someone here nicely. <br/> <br/> However, in my test environment, my MP, DP and SUP site server isn't working properly. The Primary server is in Domain &quot;A&quot; and the site system is, currently, in a workgroup - in my live environment, like my test environment, there will be no trust between the two as the internet facing component is in a DMZ and the firewall will allow the relevant traffic. The Site is also in Native mode and the certificates are, I believe, set up properly and placed on both the Primary and the site server (the site server has the certificates in the relevant stores for IIS and for the MP) <br/> <br/> My site server is showing these errors in the MP_Retry log file: <br/> <blockquote>MPDB ERROR - CONNECTION PARAMETERS <br/> SQL Server Name     : SCCM-ENT <br/> SQL Database Name   : SMS_SC0 <br/> Integrated Auth     : True <br/> <br/> MPDB ERROR - EXTENDED INFORMATION <br/> MPDB Method         : Init() <br/> MPDB Method HRESULT : 0x80004005 <br/> Error Description   : [DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied. <br/> OLEDB IID           : {0C733A8B-2A1C-11CE-ADE5-00AA0044773D} <br/> ProgID              : Microsoft OLE DB Provider for SQL Server <br/> <br/> MPDB ERROR - INFORMATION FROM DRIVER <br/> Native Error no.  : 17 <br/> Error State       : 1 <br/> Class (Severity)  : 16 <br/></blockquote> Which I would expect as the site server does not, as yet, have rights back to the Primary server. <br/> <br/> To complicate things, the Primary server (due to limited resources) is also a DC but I don't think that's the cause of the problem. <br/> <br/> My question really is - How do I allow the Site system to talk back to the Primary?Wed, 04 Nov 2009 09:44:11 Z2009-11-23T18:37:14Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/f51813e4-2f8e-465a-b4c7-a4722c60aa5ehttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/f51813e4-2f8e-465a-b4c7-a4722c60aa5eRuamazedhttp://social.technet.microsoft.com/Profile/en-US/?user=RuamazedScenario 3 with SQL Server Replica - setup guide or how to<p class=MsoNormal style="margin:0in 0in 10pt"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt">I'm in the process of implementing Scenario 3 with SQL Server Replica in the DMZ server interent clients and am getting stuck implementing. <a href="http://technet.microsoft.com/en-us/library/bb694250.aspx">http://technet.microsoft.com/en-us/library/bb694250.aspx</a><br/><br/>Architecture<br/><br/>central site with secondary’s and a primary child with secondaries. Central site and child primary both have clients reporting directly to them, I would like to setup the DMZ server to serve all internet clients, but I can have another DMZ server for the other sites internet clients.<br/><br/>PKI is inplace internally and passes native mode test.<br/><br/>The DMZ is off the central site in a firewalled segment DMZ and I have AD, SQL and prerequisites installed.<br/><br/><br/>Next steps:<br/><br/>1. create a SQL replica from the central site to the DMZ server in SQL ?? then??<br/>2. ?<br/>3. ?<br/><br/>Thanks for any help<br style=""><br style=""></span></p>Mon, 09 Nov 2009 17:37:40 Z2009-11-23T18:33:13Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/501be2dc-264b-415f-a096-dc2b1d756e14http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/501be2dc-264b-415f-a096-dc2b1d756e14Jason Oglehttp://social.technet.microsoft.com/Profile/en-US/?user=Jason%20OgleSCCM (configmgr) 2007 Native Mode Client Install Fails on SCVMM and Hyper-V Hosts due to Certificate ErrorHello.<br/>I'm running configmgr 2007 with SP2 RTM and the R2 components. Using native mode and the software update point as the client install mehod fails on my VMM 08 R2 server. It also fails on all of my Server 2008 R2 hyper-v hosts. The cause of the failure is that when the client installer looks for the client certificates it uses the first one that matches, as configured under site properties. The problem there is that the first cert to match is the self-signed certificate from VMM, named SCVMM_CERTIFICATE_KEY_CONTAINER<em>&lt;fqdn of hyper-v host&gt;</em>. <br/><br/>Is this a known issue?<br/><br/>Are there any known workarounds?<br/><br/>So far the answer has been to uninstall the VMM certificate from the store. I haven't seen any adverse affects from this yet, but I assume the VMM server/client install puts it there for a reason.Thu, 05 Nov 2009 20:53:18 Z2009-11-07T21:37:15Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/16c84ef2-432d-4bad-9e1a-6d4d8ce09235http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/16c84ef2-432d-4bad-9e1a-6d4d8ce09235Benjamin Niaulinhttp://social.technet.microsoft.com/Profile/en-US/?user=Benjamin%20NiaulinSCCM Client Installation (installed but now showing up)<p align=left><font face=Arial size=2></font> </p> <p>Hey everyone,</p> <p align=left> </p> <p align=left> </p> <p align=left>Thanks in advance for taking the time and reading about my situation.</p> <p align=left> </p> <p align=left> </p> <p align=left> </p> <p align=left>I had previously set up SCCM back when it first came out, but due to so many problems i first had and the lack of time i decided to uninstall. I was previously in mixed mode and clients were installed and setup properly.</p> <p align=left>I was able to push software packages and so on.</p> <p align=left> </p> <p align=left>Recently i decided to go back into sccm, so i set myself up in native mode this time on a sql cluster</p> <p align=left> </p> <p align=left> </p> <p align=left>So here is the deal, i tried doing a push installation to my systems with the ccmhttpsstate=1 parameter i think it was</p> <p align=left>ccmsetup.log doesnt show any problems, says needs a reboot so i rebooted my systems.</p> <p align=left>but they dont show up as &quot;Client = yes&quot; in my collections, it still assigned but with no client</p> <p align=left> </p> <p align=left>when i look on a system in control panel for the config manager settings, i see that it is installed (possibly from previous sccm installation back in the day) but it is properly configured as well, i see the correct site code, i re-do a manually discovery for the site code and it says im already assigned to it.</p> <p align=left> </p> <p align=left> </p> <p align=left>So why does it not show up as installed in my collection?</p>Fri, 01 Aug 2008 12:48:32 Z2009-11-06T18:58:50Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/9fee30b8-4af8-4f8e-87be-5e7fa6bd32eehttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/9fee30b8-4af8-4f8e-87be-5e7fa6bd32eeMTU SAShttp://social.technet.microsoft.com/Profile/en-US/?user=MTU%20SASRemote Tools Available Outside of Local Network<p class=MsoNormal>Is it possible to install the SCCM Client on, say a laptop that is used outside of our network and be able to use Remote Tools to assist them? We have multiple users that go to conferences and travel in general, is it possible to use Remote Tools with them. These users can have VPN access giving them an IP on the same subnet as the SCCM server. These laptops are not on our domain, just their local workgroup.</p> <p class=MsoNormal>I have installed the client using “CCMSetup.exe /native CCMALWAYSINF=1 CCMHOSTNAME=SERVER.CONTOSO.COM SMSSITECODE=ABC”, while being connected to our VPN and not. The client computer says it was successful in installing, I just do not see the client in any collection.</p>Thu, 05 Nov 2009 21:12:09 Z2009-11-06T02:41:24Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/04b8dc4c-6e92-4a94-afff-7b8c87068d69http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/04b8dc4c-6e92-4a94-afff-7b8c87068d69andyjharperhttp://social.technet.microsoft.com/Profile/en-US/?user=andyjharperNew client installs no longer communicating with MP and not pulling policy<p class=MsoNormal style="margin:5pt 0in;line-height:normal"><span style="font-size:12pt;font-family:'Times New Roman','serif'">Good morning,<br/><br/>All of a sudden when new clients are being installed, they are not communicating with the MP or SLP properly (I can't really tell which). For example I am using a GPO startup script to install the SCCM client with the appropriate parameters. The client is installed fine but it does not look like any of the parameters took. In the general tab it shows &quot;unknown&quot; for ConfigMgr Connection Type and Site Mode. The site code does not appear in the &quot;Advanced&quot; tab and the actions tab only shows &quot;Machine Policy Retrieval &amp; Evaluation Cycle&quot; and &quot;User Policy Retrieval &amp; Evaluation Cycle&quot;. The &quot;Components&quot; tab shows all installed, but none show enabled for the various components.<span style="">  </span>When I initiate a user and machine policy cycle, nothing happens.<br/><br/>Nothing has changed from my end as far as I know. The group policy is still the same and as far as I know nothing has changed with the domain.<span style="">  </span>I can't see any obvious errors in the logs on the SCCM server.<span style="">  </span>Does anyone know what I can check to try and see why this stopped working?<span style="">  </span>It seems that any new clients aren't working properly.  Thanks.</span></p>Tue, 27 Oct 2009 14:11:48 Z2009-11-05T20:51:05Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/7b922255-4ed0-496c-bb33-dd634c0e3bddhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/7b922255-4ed0-496c-bb33-dd634c0e3bdd.Tim Harrisonhttp://social.technet.microsoft.com/Profile/en-US/?user=.Tim%20HarrisonIBCM Problems...I had an issue where I needed to work on my certificate server a few days ago and after ironing out all the issues, I re-deployed certificates to most machines.  One that I forgot to re-deploy until yesterday was the Site Server Signing Cert to the Central Site Server.  Several machines had been imaged, talked to the MP at least long enough to download the Signing Cert and then sent to the field.  I wasn't getting reports from any of the machines.  I re-deployed a new signing cert to the Central Site server, but it seems to be causing problems with machines in the field downloaded the updated cert.<br/> <br/> I have just deployed a handful of laptops with an IBCM-only configuration to the field and I'm only hearing back from a handful of them.  These machines have a proxy configured in IE for internet browsing, but I wouldn't think that would affect the agent.  On some machines I'm getting full reports, on others, I'm only getting software inventories and on others I'm getting them to show up in the collection, but when I go into resource explorer, I have no data.  On my DMZ-based MP, for one of the machines that I'm getting a software inventory but no hardware inventory, under the MP_Status.log, I got one &quot;SMS_ServiceHost_CertificateOperationsFailure&quot; for it, a &quot;DPBITSConfigDeleted&quot;, a couple &quot;SMS_PolicyAgent_PolicyMismatch&quot; events, then a bunch of &quot;SMS_PolicyAgent_BitsPolicyDownloadFailed&quot;, and lastly another &quot;SMS_PolicyAgent_PolicyMismatch&quot; event.  <br/> <br/> For one of the machines that I've gotten nothing from, at first I had a bunch of alternating &quot;SMS_RemoteClient_SiteSigning_AuthFailure_Trust&quot; and &quot;SMS_PolicyAgent_PolicyAuthorizationFailure&quot; events, but now I'm just getting a bunch of &quot;SMS_PolicyAgent_BitsPolicyDownloadFailed&quot; events and one &quot;SMS_PolicyAgent_PolicyMismatch&quot; event.<br/> <br/> All of the machines I'm having problems with are showing up in the MP_Status.log on the DMZ MP with either the &quot;SMS_PolicyAgent_BitsPolicyDownloadFailed&quot; and/or &quot;SMS_PolicyAgent_PolicyAuthorizationFailure&quot;.<br/> <br/> Thanks in advance.Tue, 11 Aug 2009 12:20:12 Z2009-11-05T17:30:41Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/c530c1c0-5cbb-42c1-a0f8-ef8605cab78ehttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/c530c1c0-5cbb-42c1-a0f8-ef8605cab78e.Tim Harrisonhttp://social.technet.microsoft.com/Profile/en-US/?user=.Tim%20HarrisonComputer name and cert validity questionIf I image a machine that uses a script using certreq.exe and certutil.exe to automatically request and install its client and trusted root certs, and later on the computer name changes, will that computer lose the ability to download policy since the hostname no longer matches the subject name on the client certificate?<br/> <br/> I would think it would, but I have a client that seems to be downloading policy anyway... any ideas?Tue, 03 Nov 2009 17:12:06 Z2009-11-04T21:36:36Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/4d3726b9-695e-4105-be5b-083b4b331dadhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/4d3726b9-695e-4105-be5b-083b4b331dadJohnPTurnerhttp://social.technet.microsoft.com/Profile/en-US/?user=JohnPTurnerIBCM Fall-Back Status Point work for Intranet too?<p>I was curious, if I setup a fallback status point on my IBCM server can my intranet clients also use the same server or should I have a fallback status point in both my intranet and perimiter network?</p>Tue, 20 Oct 2009 13:37:33 Z2009-10-28T18:09:38Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/65d70966-c183-4090-9b6c-9d5f8426b2f0http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/65d70966-c183-4090-9b6c-9d5f8426b2f0barrymcconnell62http://social.technet.microsoft.com/Profile/en-US/?user=barrymcconnell62native install client being used for updates<p>hi everyone,<br /><br />we have installed the sccm sp2 in native mode all the computers have been reconized by sccm and have been put into the right site. <br />I have recently been asked to use SCCM to update our computers from our original wsus sp2. I have went in and created the management point and update point and have no erros. I have also went in and installed the wsup for some other catalogue files we need. The problem comes from when i go in and modify the clients to point to the SCCM server for updates in the registry and if there is anythng else i need to look for. <br /><br />Windows Registry Editor Version 5.00</p> <p>[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\windows\WindowsUpdate]<br />"WUServer"="<a href="https://SCCM101.happy.NET:443">https://SCCM101.happy.NET:443</a>"<br />"WUStatusServer"="<a href="https://SCCM101.happy.NET:443">https://SCCM101.happy.NET:443</a>"</p> <p>[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\windows\WindowsUpdate\AU]<br />"UseWUServer"=dword:00000001</p>Thu, 15 Oct 2009 21:25:17 Z2009-10-29T01:48:59Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/4693eb86-66d7-4955-836c-c65352f8f709http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/4693eb86-66d7-4955-836c-c65352f8f709make additonal server exchange to master mail servhttp://social.technet.microsoft.com/Profile/en-US/?user=make%20additonal%20server%20exchange%20to%20master%20mail%20servmake additonal server exchange to master mail server ?I need to convert the additional exchange 2003 to master ?<br/>Tue, 27 Oct 2009 21:34:58 Z2009-10-29T01:49:13Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/782f8b17-1fe1-4840-8cfc-f7675d74bf10http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/782f8b17-1fe1-4840-8cfc-f7675d74bf10Tim McGilveryhttp://social.technet.microsoft.com/Profile/en-US/?user=Tim%20McGilveryNative mode clients downloading via BITS is it always encrypted trafficCustomer has SCCM 2007 SP1 in native mode deployed.  They have Cisco WAAS devices in some remote locations(not WoWaas).  It is their understanding that the WAAS devices are not caching the SCCM download packages because the data is encrypted.  They want to use the WAAS devices(no peer DP's, etc).  If we created protected DPs without web certs .... would the client download via BITS in an unecrypted manor?   Or can you change the IIS config on the site servers DP web shares?   <br/>Thanks<br/>TimWed, 21 Oct 2009 19:01:05 Z2009-10-22T11:51:28Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/a0d82520-0c93-4bf2-9908-45bcc8ac7132http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/a0d82520-0c93-4bf2-9908-45bcc8ac7132David Kraxnerhttp://social.technet.microsoft.com/Profile/en-US/?user=David%20KraxnerSome Clients Not Accepting PKI Certificate for Native MdeI realize that the PKI implentation is outside the scope of this formum, but thought I would post this in hopes that someoine else might have had this problem and provide some guidance on a resolution.<br/>I am in the process of readying my SCCM environment for switching to native mode from mixed mode. I have used the &quot;Step-By-Step Example Deployment of the PKI Certificates Required for Configuration Manager Native Mode Windows Server 2008 Certification Authority&quot; to setup my environment for issuing PKI certificates as part of the preparation to making the switch to native mode. When I run the report &quot;Summary information of clients capable of native mode communication&quot; I have four laptops that fall into the classification of &quot;Native Mode Incapable Clients&quot; and show an error code of -2147220864 , which I believe translates to &quot;<span style="font-family:Calibri;font-size:x-small">A valid certificate was not found in the certificate store</span>&quot;.<br/>When I use the &quot;Certificates&quot; MMC snap-in to check the certificate store, there are not any certificates listed under &quot;personal/certificates&quot; as there is for all of the other PC's in my environment. <br/>The commonality amongst these four laptpos are that they are all new Lenovo T500 laptops. They are in the same orgainzational unit as other PC's that do auto accept the PKI certificates. The event logs on the PC's do not show any errors.<br/>Thanks in advance for anyone that might make a suggestion on how to further troubleshoot this problem and/or provide a work-around on getting the needed certificate installed.Sat, 26 Sep 2009 12:01:09 Z2009-10-23T21:17:14Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/2f1d7a42-8a53-4022-804e-ff948ea2ab72http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/2f1d7a42-8a53-4022-804e-ff948ea2ab72andyjharperhttp://social.technet.microsoft.com/Profile/en-US/?user=andyjharperCan my clients renwew or extend their certificates?Greetings,<br /><br />I should have made my certificate validity longer than the default.&nbsp; I have plenty of time until my client's certificates expire.&nbsp; However, can I extend the exisiting certificate in any way?&nbsp; Can I renew it right now instead of waiting until February?&nbsp; or do I have to create a new certificate for my clients and the two can co-exisit on a machine?&nbsp; Thanks for the help.Fri, 02 Oct 2009 13:06:12 Z2009-11-07T18:53:44Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/ebecc260-ccd1-4fce-a2a0-9152b5fbab6chttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/ebecc260-ccd1-4fce-a2a0-9152b5fbab6cshigenobuchanhttp://social.technet.microsoft.com/Profile/en-US/?user=shigenobuchanSCCM Native Mode broken after CA migration from 2003 >> 2008 Last week, our CA was migrated from 2003 to 2008 server.&nbsp; Now, SCCM isn't working properly.&nbsp; Specifically, getting the following errors in mpcontrol.log<br /> <br /> <br /> <em>CryptVerifyCertificateSignatureEx returned error 0x80090006.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:03 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Certificate doesn't have &quot;SSL Client Authentication&quot; capabilities.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:03 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Skipping certificate that is not valid for ConfigMgr usage.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:03 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> CryptVerifyCertificateSignatureEx returned error 0x80090006.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:03 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Certificate has &quot;SSL Client Authentication&quot; capability.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:03 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> <strong>Call to HttpSendRequestSync failed for port 443 with status code 403, text: Forbidden&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:03 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)</strong> <br /> Successfully performed Management Point availability check against local computer.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:03 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Machine name is 'sccmserver.domain.com'.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:03 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> CryptVerifyCertificateSignatureEx returned error 0x80090006.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:03 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Certificate doesn't have &quot;SSL Client Authentication&quot; capabilities.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:03 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Skipping certificate that is not valid for ConfigMgr usage.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:03 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> CryptVerifyCertificateSignatureEx returned error 0x80090006.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:03 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Certificate has &quot;SSL Client Authentication&quot; capability.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:03 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> <strong>Call to HttpSendRequestSync succeeded for port 443 with status code 200, text: OK&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:03 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)</strong> <br /> Http test request succeeded.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:03 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Successfully performed Device Management Point availability check against local computer.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:03 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Initialization still in progress.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:03 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Machine name is 'sccmserver.domain.com'.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> CryptVerifyCertificateSignatureEx returned error 0x80090006.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Certificate doesn't have &quot;SSL Client Authentication&quot; capabilities.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Skipping certificate that is not valid for ConfigMgr usage.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> CryptVerifyCertificateSignatureEx returned error 0x80090006.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Certificate has &quot;SSL Client Authentication&quot; capability.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> <strong>Call to HttpSendRequestSync failed for port 443 with status code 403, text: Forbidden&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)</strong> <br /> Successfully performed Management Point availability check against local computer.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Machine name is 'sccmserver.domain.com'.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> CryptVerifyCertificateSignatureEx returned error 0x80090006.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Certificate doesn't have &quot;SSL Client Authentication&quot; capabilities.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Skipping certificate that is not valid for ConfigMgr usage.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> CryptVerifyCertificateSignatureEx returned error 0x80090006.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Certificate has &quot;SSL Client Authentication&quot; capability.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> <strong>Call to HttpSendRequestSync succeeded for port 443 with status code 200, text: OK&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)</strong> <br /> Http test request succeeded.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Successfully performed Device Management Point availability check against local computer.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)<br /> Initialization still in progress.&nbsp;&nbsp;&nbsp; SMS_MP_CONTROL_MANAGER&nbsp;&nbsp;&nbsp; 10/12/2009 11:02:33 AM&nbsp;&nbsp;&nbsp; 5664 (0x1620)</em> <br /> <br /> Thoughts?&nbsp; I made sure the new CA was extended to support SAN2 attributes.<br />Mon, 12 Oct 2009 18:05:47 Z2009-10-14T19:39:00Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/0fa3a2a2-409a-4031-a336-9bf566601fc8http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/0fa3a2a2-409a-4031-a336-9bf566601fc8shankar kannappahttp://social.technet.microsoft.com/Profile/en-US/?user=shankar%20kannappaclient installation in 2000 serverHi <br /><br />we are facing issue in installing sccm Client in 2000 server with SP 4. we are getting the following error.<br /><br />and this servers are in child domain<br /><br />error msg :<br />native security mode is invalid on windows 2000<br /><br />already refered the following link but did not helped me<br /><a href="http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/002af352-cd44-4947-8933-7279af32b3d6">http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/002af352-cd44-4947-8933-7279af32b3d6</a><br /><br />Please do the needfulTue, 13 Oct 2009 05:42:47 Z2009-10-14T11:38:10Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/eac07737-53cf-41ec-b537-bfd7846a73cfhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/eac07737-53cf-41ec-b537-bfd7846a73cfJosh_Shttp://social.technet.microsoft.com/Profile/en-US/?user=Josh_SAIA access for internet-based clients in native modeI have an environment where some clients will be&nbsp;primarily internet-based but the issuing CA will be&nbsp;in on the intranet.&nbsp; When clients connect from the Internet and they are configured for CRL checking, they will not be able to access the CRL from the CA.&nbsp; They will also not be able to access the AIA for certificate chaining.&nbsp; I read this article describing how to publish the CRL on a separate web server outside of the forest:<br /><br /><a href="http://blogs.technet.com/configmgrteam/archive/2009/05/01/how-to-publish-the-crl-on-a-separate-web-server.aspx">http://blogs.technet.com/configmgrteam/archive/2009/05/01/how-to-publish-the-crl-on-a-separate-web-server.aspx</a><br /><br />My&nbsp;question is, what about the AIA?&nbsp; Does it need to be available to these internet-based systems as well?&nbsp; Or will the CRL suffice?&nbsp;<br /><br />Thanks!Mon, 05 Oct 2009 19:51:21 Z2009-10-20T20:56:03Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/196f7051-0849-430f-9bc0-4346e435e809http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/196f7051-0849-430f-9bc0-4346e435e809zolgshttp://social.technet.microsoft.com/Profile/en-US/?user=zolgsWindows 2003 Std Server and PKI<p align=left><font face=Arial size=2>Hi Everyone,</font></p> <p align=left> </p> <p align=left>i have a problem with a customer who also wants to upgrade to native mode. Not yet but in the future. The customer has only a Win 2003 Std Server and a PKI on it.</p> <p align=left> </p> <p align=left>So thats my problem. I need WIn2003 Enp to create the certificates for native mode. </p> <p align=left> </p> <p align=left>So my question is, is there a workaround to do this on a WIN2003 Std ? </p> <p align=left> </p> <p align=left>Must the RootCA be a domain controller ? or can i do this also on a member server in a domain ? </p> <p align=left> </p> <p align=left>thanks a lot </p> <p align=left> </p>Tue, 06 May 2008 13:57:46 Z2009-09-30T12:21:05Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/a5307435-1eb6-4362-b616-557017d77fa8http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/a5307435-1eb6-4362-b616-557017d77fa8Sander Verroenhttp://social.technet.microsoft.com/Profile/en-US/?user=Sander%20Verroenreport: all clients connecting through internet?Is it possible to query which clients currently connect through an internet management point, perhaps via a report or through a collection?<br/><br/>A query for the client property:ConfigMgr Connection Status of &quot;Currently Internet&quot; would be great. Is this possible?<br/>Mon, 28 Sep 2009 09:53:34 Z2009-09-28T12:32:09Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/e49bd850-0f70-4824-99cb-3e25fabd1900http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/e49bd850-0f70-4824-99cb-3e25fabd1900Aaron Barlowhttp://social.technet.microsoft.com/Profile/en-US/?user=Aaron%20BarlowIBCM only works for one day at a time, then has to be put back on the internal networkYesterday I thought I made a breakthrough.  I successfully got a laptop to download advertised software via the internet.  I then pulled out half of the ram and a bit after the computer came back up ran a report to check on the installed ram amount.  It changed!  Then I installed some Windows Updates from a deployment that was advertised to the collection.  Also good!  Then today happened.<br/> <br/> I configured an update deployment to hit the laptop late in the night and left the laptop up and running.  I checked in the morning and it never ran.  I tested a software deployment.  The laptop was able to see the list of software advertised to it, but it would fail to download when I told it to install any piece of software.  After a reboot the computer came back up with the same problem.  The ram test now failed.<br/> <br/> I pulled the laptop from the collection for the update deployment and reconnected it to our internal network and rebooted.  Now it can download advertised software.  I took it off of the network again and rebooted once more.  It is still able to download software.  I have now added the laptop back in to the collection for the update deployment (while the laptop is fully off of the internal network), and it worked.  So this seems to be nailed down to some kind of time based problem, as multiple reboots off network don't cause a failure.<br/> <br/> My setup:  A single SCCM server for a site in native mode which is working fine with all computers on the intranet.  We also have a primary child site in mixed mode for a separate forest, but I don't see any relevance for this problem.  My guess is that this is in some way a cert issue.  To that end, the internal and external server name(fqdn) is exactly the same, and I checked and was told I didn't need a SAN specified.<br/> Laptop setup:  Dell Latitude D520 running a Verizon wireless card with all other networking disabled. (nic not plugged in)<br/> <br/> There are errors in many of the client logs, but I'm not sure which would be relevant for the problem, as many of these errors actually show up on intranet computers as well.  I'll post any logs asked of me.<br/> <br/> Thanks,<br/> <br/> Aaron Barlow<br/>Tue, 04 Aug 2009 17:06:46 Z2009-09-24T14:54:35Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/a7659ade-a9fc-44b1-aa66-a069376c9ceehttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/a7659ade-a9fc-44b1-aa66-a069376c9ceeTim McGilveryhttp://social.technet.microsoft.com/Profile/en-US/?user=Tim%20McGilveryTroubleshooting BITS in Native mode with BITSADMINWe are having some wierd network issue's SW downloads (via BITS) on specific subnets and I'm trying to troubleshoot.  We are using SCCM 2007 sp1 in Native mode and I can't get BITSADMIN.EXE to access the NOCERT or regular SMSPKGx$ web links.  I've tried to supply credentials via /setCredentials but its not working.  I also used Aaron C.'s CMD file but still the same issue. (<a href="http://blogs.technet.com/aaronczechowski/archive/2008/03/08/bitsadmin-script.aspx">http://blogs.technet.com/aaronczechowski/archive/2008/03/08/bitsadmin-script.aspx</a>).    It's probably something simple but has anyone tried to do this?<br/><br/>TMMon, 21 Sep 2009 17:04:03 Z2009-09-23T15:12:07Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/b6b3bf7f-213d-4d17-bfa9-3c9348053d7ehttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/b6b3bf7f-213d-4d17-bfa9-3c9348053d7eLA1976http://social.technet.microsoft.com/Profile/en-US/?user=LA1976Windows Server 2008 R2 gives error after installation: The ConfigMgr Advanced Client received policy that could not be verified.<p>I installed 2 2008 R2 servers and did an install of the sccm client.<br/><br/>As soon as the client was installed the errors came.<br/><br/>The client has no advertisments assigned <br/>-------------------------------------------------------------------------------------------------------------------------------<br/><br/>The ConfigMgr Advanced Client received policy that could not be verified.<br/><br/><br/><br/>The following errors are seen in de policyagent log<br/><br/>Requesting policy from authority 'SMS:VEL' PolicyAgent_RequestAssignments 23-9-2009 15:11:33 1120 (0x0460)<br/>Raising event:</p> <p>instance of CCM_PolicyAgent_AssignmentsRequested<br/>{<br/> AuthorityName = &quot;SMS:VEL&quot;;<br/> ClientID = &quot;GUID:ED09C70C-80D0-4456-B297-1DA047562E6E&quot;;<br/> DateTime = &quot;20090923131133.528000+000&quot;;<br/> ProcessID = 736;<br/> ResourceName = &quot;S031-1039&quot;;<br/> ResourceType = &quot;Machine&quot;;<br/> ThreadID = 1120;<br/>};<br/> PolicyAgent_RequestAssignments 23-9-2009 15:11:33 1120 (0x0460)<br/>Processing Machine assignments from 'SMS:VEL'. The new cookie is '2009-09-23 00:05:48.553'. PolicyAgent_ReplyAssignments 23-9-2009 15:11:33 1280 (0x0500)<br/>Raising event:</p> <p>instance of CCM_PolicyAgent_AssignmentsReceived<br/>{<br/> AuthorityName = &quot;SMS:VEL&quot;;<br/> ClientID = &quot;GUID:ED09C70C-80D0-4456-B297-1DA047562E6E&quot;;<br/> DateTime = &quot;20090923131133.665000+000&quot;;<br/> ProcessID = 736;<br/> ReplyType = &quot;Full&quot;;<br/> ResourceName = &quot;S031-1039&quot;;<br/> ResourceType = &quot;Machine&quot;;<br/> ThreadID = 1280;<br/>};<br/> PolicyAgent_ReplyAssignments 23-9-2009 15:11:33 1280 (0x0500)<br/>The 'Certificate Store' is empty in the registry, using default store name 'MY'. PolicyAgent_ReplyAssignments 23-9-2009 15:11:33 1280 (0x0500)<br/>Raising event:</p> <p>instance of CCM_ServiceHost_CertRetrieval_Status<br/>{<br/> ClientID = &quot;GUID:ED09C70C-80D0-4456-B297-1DA047562E6E&quot;;<br/> DateTime = &quot;20090923131133.680000+000&quot;;<br/> HRESULT = &quot;0x00000000&quot;;<br/> ProcessID = 736;<br/> ThreadID = 1280;<br/>};<br/> PolicyAgent_ReplyAssignments 23-9-2009 15:11:33 1280 (0x0500)<br/>Raising event:</p> <p>instance of CCM_PolicyAgent_PolicyAuthorizationFailure<br/>{<br/> ClientID = &quot;GUID:ED09C70C-80D0-4456-B297-1DA047562E6E&quot;;<br/> DateTime = &quot;20090923131133.680000+000&quot;;<br/> PolicyNamespace = &quot;<a>\\\\S031-1039\\ROOT\\ccm\\Policy\\Machine\\RequestedConfig</a>&quot;;<br/> PolicySource = &quot;SMS:VEL&quot;;<br/> ProcessID = 736;<br/> ThreadID = 1280;<br/>};<br/> PolicyAgent_ReplyAssignments 23-9-2009 15:11:33 1280 (0x0500)</p>Wed, 23 Sep 2009 13:18:44 Z2009-09-23T15:44:48Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/e9280fb7-15e3-425c-9642-8938341690d5http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/e9280fb7-15e3-425c-9642-8938341690d5David Kraxnerhttp://social.technet.microsoft.com/Profile/en-US/?user=David%20KraxnerHow to Decipher Error Codes for Clients Incapable of Native Mode CommunicationI have been preparing my site for native mode communication. After setting up PKI and running the sccmnativemodereadiness.exe I have several client PC's showing up on the report named &quot;Clients Incapable of Native Mode Communication&quot;. The error codes listed are 2147220864 and 2147220862, but I have not been able to find a reference to what those codes mean. They do not appear on the document &quot;Custom Error Codes for Configuration Manager 2007. How can I decipher what these codes mean?Fri, 18 Sep 2009 20:40:29 Z2009-09-22T16:26:10Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/3496f2ea-97d3-4cac-a798-96aaea26a8dchttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/3496f2ea-97d3-4cac-a798-96aaea26a8dcSander Verroenhttp://social.technet.microsoft.com/Profile/en-US/?user=Sander%20VerroenFSP for roaming clients<p>How can I have my roaming clients communicate with multiple FSP?<br/><br/>When the laptops are on the intranet, we want them to communicate with an internal FSP and when they are on the internet, with an FSP on the DMZ.<br/>We have a single (native mode) site.</p>Mon, 17 Aug 2009 08:52:09 Z2009-09-16T13:34:01Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/21f13cc6-b67e-4a18-b2cf-2649bb5271e4http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/21f13cc6-b67e-4a18-b2cf-2649bb5271e4andyjharperhttp://social.technet.microsoft.com/Profile/en-US/?user=andyjharperDoes secondary DP have to have the Site Server Signing CertificateGreetings,<br/><br/>I know I had to have my primary site server installed with the SCCM Site Signing Certificate.  Do I need to have that same certificate on any additional site systems?  I set up a second DP (that's all this new site server will do).  Do I have to request the Site Server Signing Certificate or is that only required on my server running the database, acting as site server, etc.  I would assume no, but I figured I'd ask.Tue, 15 Sep 2009 12:33:58 Z2009-09-15T19:37:37Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/14fadd7d-3367-4592-9a5c-533f4a7b8977http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/14fadd7d-3367-4592-9a5c-533f4a7b8977Guy Yardenihttp://social.technet.microsoft.com/Profile/en-US/?user=Guy%20YardeniSite assignment for clients that are Internet and Intranet managedHi all, I have a planning question I'm hoping someone can help with. <div><br/></div> <div>The requirement is to manage a large number of clients on the Internet and Intranet. I'd like the Internet site to be a single site globally (manully assigned of course), but the Intranet site to be automatically assigned based on their location (Asia site, Europe site, US site,etc). Is this possible?</div> <div><br/></div> <div>Thx.</div> <div><br/></div> <div>Guy</div>Tue, 08 Sep 2009 18:31:19 Z2009-09-10T15:16:42Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/01a26ccd-95a9-428d-a169-c5f8453f7816http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/01a26ccd-95a9-428d-a169-c5f8453f7816Mayur Kirtihttp://social.technet.microsoft.com/Profile/en-US/?user=Mayur%20KirtiIBCM ConfigurationI am planning to setup IBCM and wanted to open a thread to see if folks can guide me through the process. I read the possible configuration scenarios for IBCM here: <a href="http://technet.microsoft.com/en-us/library/bb693755.aspx">http://technet.microsoft.com/en-us/library/bb693755.aspx</a>. What is the most commonly used configuration? I know the configuration will depend on the requirements and constraints but I would like to get feedback from people who have successfully implemented IBCM in a secure environment. <div><br/></div> <div>I am working with following configuration:</div> <div><br/></div> <div>Server 2003</div> <div>Primary site</div> <div>Child site</div> <div>Native mode</div> <div>SP1 R2</div> <div><br/></div> <div>Server 1:</div> <div>MP</div> <div>PXE service point</div> <div>Reporting point</div> <div>Site server</div> <div>SUP</div> <div>SQL</div> <div>Distribution point</div> <div><br/></div> <div>Server 2:</div> <div>Windows 2003</div> <div>FSP</div> <div>SLP</div> <div><br/></div><hr class="sig">MayurWed, 09 Sep 2009 14:13:49 Z2009-09-15T21:51:31Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/e8279dd0-0e45-4895-a96c-b218e8f7b858http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/e8279dd0-0e45-4895-a96c-b218e8f7b858David Baurhttp://social.technet.microsoft.com/Profile/en-US/?user=David%20BaurMultiple Non Trusting Forest with "Internet or intranet management" enabled Client Behavior and Design?I saw a posting similar to this (Multiple forests native mode implementation<br/><a href="http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/9302902d-6bf0-4a87-81c7-baba342ecef5">http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/9302902d-6bf0-4a87-81c7-baba342ecef5</a> ), but not quite the same. <br/><br/>Here is the scenario.<br/>5 Forest -Non-Trusting, Each SCCM Site has has Key Exchanged and the Sites are communicating fine. Sender using Mirrored Account (Server to Server).<br/>Clients will be &quot;Internet or Intranet&quot;<br/>There is a Central Sitee, it has a Primary Child Site in each Forest, and one in its own forest that serves the Internet Clients. This primary site server is in the Intranet and uses  Tunneling (Not bridging) from ISA 2006 (so not really on the Internet side of firewall). <br/>The SAN (Subject Alternate Name) is entered into the PKI Certificates for this Primary Sites Internet Name and handed out to all clients in each forest, and the ISA Box forwards Internet Clients via tunnel to this server.<br/>All Clients everywhere can only connect through this location, even if their assigned site is in another forest. <br/><br/> The SCCM Hierarchy encompasses all Forest, but will the clients honor the packages on the Primary Site that is above their own in the Hierarchy. I made a really nice graphic depiciting this, but I don't see a way to share it. PKI Root is in the Top Most forest, and has issuing into each forest as well.<br/>The question or wonder is how will the clients behave? Will they utilize the same Package ID from the Internet SCCM Site? or will they try to traverse to their own forest and to their Primary Site in that forest?<br/><br/>I would like all Primary Site Child Site Clients to be able to communicate with this Internet servicing site when connecting from the internet. <br/><hr class="sig">David BaurThu, 03 Sep 2009 03:39:46 Z2009-09-04T13:46:03Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/107763bc-1a44-4929-ab88-f3dc48012642http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/107763bc-1a44-4929-ab88-f3dc48012642Walshtechhttp://social.technet.microsoft.com/Profile/en-US/?user=WalshtechSCCM Client Expiration???<p>We have 1 SCCM Native Mode Site with approx 500 Clients I have been working on weeding out the issues with Client Installations.  Early this morning I was showing 14 Computers that said that they did not have a SCCM Client installed.  Now I am showing 38.  Some of the machines in the list were imaged with SCCM so I know that they have a client.  What am I missing?  I know that the client will uninstall after 90 days if it has not contacted the site but some of the clients are less than 90 days old.  Is there another expiration that I am missing?<br/><br/>Thanks<br/> <br/>Walshtech </p>Mon, 24 Aug 2009 20:43:05 Z2009-08-27T13:09:55Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/ac9c6b03-acdb-48f9-9b92-e8bb5657cb0ahttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/ac9c6b03-acdb-48f9-9b92-e8bb5657cb0aGiancarlo S.http://social.technet.microsoft.com/Profile/en-US/?user=Giancarlo%20S.Scenario for computer not in domain.Hi,<br/><br/>I need to deploy the SCCM infrastructure in a environment which some computers are joined in the domain and some others not. My question is: to manage the computers that are not joined to the domain do I need to use native mode communication or there is a way to do that using Mixed mode communication?<br/><br/>Thanks in advanceMon, 24 Aug 2009 01:54:07 Z2009-08-24T12:08:02Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/1865a1eb-e983-478f-aa66-a0806fe9d6a6http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/1865a1eb-e983-478f-aa66-a0806fe9d6a6j4sanderhttp://social.technet.microsoft.com/Profile/en-US/?user=j4sanderNew Agent Policy RetrievalI have a SCCM 2007 SP1, single site, native mode install and I have started having problems with new agents.  The agent installes locally (control panel applets, etc) via WSUS deployment and the computer shows up in the 'all systems' collection (Client: YES), but the agent does not download policy.<br/><br/>Previously installed agents are still working properly, installing updates and running advertisements.<br/><br/>I've been looking through the logs but I'm not really sure which log I should be focusing on or what I should be lookign for.  Any direction would be apreciated.<br/>JoeMon, 17 Aug 2009 15:30:56 Z2009-08-21T22:43:04Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/be94be97-04d9-4ab3-9565-85649ebd7323http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/be94be97-04d9-4ab3-9565-85649ebd7323Elaina71http://social.technet.microsoft.com/Profile/en-US/?user=Elaina71DMZ dual-homedAre most machines configured for a DMZ dual-homed?Sun, 16 Aug 2009 19:01:23 Z2009-08-16T19:01:23Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/0abc4423-05ce-49a2-8e3f-a5a70b30b482http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/0abc4423-05ce-49a2-8e3f-a5a70b30b482RobM1971http://social.technet.microsoft.com/Profile/en-US/?user=RobM1971Native Mode Client to Mixed Mode SiteWhat is the best practice when you need to move/reassign a Native Mode client to a Mixed Mode Site? The client reassignment appears to be working, but HW inventory is not getting processed and put into BADMIF. The error received in dataldr.log is &quot;CMachineSource::InsertMachine - could not validate machine&quot;.<br/><br/>Wed, 12 Aug 2009 12:44:12 Z2009-08-12T16:46:28Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/0ed4181a-0f90-483e-936b-dfb3bc0f495bhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/0ed4181a-0f90-483e-936b-dfb3bc0f495bMahinder Chandelhttp://social.technet.microsoft.com/Profile/en-US/?user=Mahinder%20ChandelWhere is SMS client certificate store at client siteHi,<br/>i want to know the exact location where is sms client certificate store after client installtion .Tue, 28 Jul 2009 14:48:37 Z2009-08-21T19:12:38Zhttp://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/985a85a4-6a57-41ba-86ca-0a9b97676084http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/985a85a4-6a57-41ba-86ca-0a9b97676084TomK79http://social.technet.microsoft.com/Profile/en-US/?user=TomK79Client Push to ServersHello,<br/> <br/> I am trying to push install SCCM clients on our servers, but all server installations fail with different erros. Windows Vista and XP clients already have successfully installed clients. My SCCM runs in native mode and certificates are working on Vista and XP.<br/> <br/> CCMsetup.log (windows server 2008 64bit; 2 servers: 1st server = DC; 2nd server = SCCM host):<br/> <pre lang=x-html>&lt;![LOG[==========[ ccmsetup started in process 3572 ]==========]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:8849&quot;&gt; &lt;![LOG[Version: 4.0.6221.1000]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:1907&quot;&gt; &lt;![LOG[Command line parameters for ccmsetup have been specified. No registry lookup for command line parameters is required.]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:3932&quot;&gt; &lt;![LOG[Command line: &quot;C:\Windows\ccmsetup\ccmsetup.exe&quot; /runservice /config:MobileClient.tcf]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:3941&quot;&gt; &lt;![LOG[CCMHTTPPORT: 80]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:7847&quot;&gt; &lt;![LOG[CCMHTTPSPORT: 443]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:7862&quot;&gt; &lt;![LOG[CCMHTTPSSTATE: 63]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:7880&quot;&gt; &lt;![LOG[CCMHTTPSCERTNAME: ]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:7908&quot;&gt; &lt;![LOG[FSP: MESSERSCHMITT.LLB.MW.TU-MUENCHEN.DE]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:7923&quot;&gt; &lt;![LOG[CCMFIRSTCERT: 0]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:7965&quot;&gt; &lt;![LOG[Config file: C:\Windows\ccmsetup\MobileClient.tcf]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:4336&quot;&gt; &lt;![LOG[Retry time: 10 minute(s)]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:4337&quot;&gt; &lt;![LOG[MSI log file: ]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:4338&quot;&gt; &lt;![LOG[MSI properties: INSTALL=&quot;ALL&quot; SMSSITECODE=&quot;LLB&quot; CCMHTTPPORT=&quot;80&quot; CCMHTTPSPORT=&quot;443&quot; CCMHTTPSSTATE=&quot;63&quot; FSP=&quot;MESSERSCHMITT.LLB.MW.TU-MUENCHEN.DE&quot; CCMFIRSTCERT=&quot;0&quot;]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:4339&quot;&gt; &lt;![LOG[Source List:]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:4347&quot;&gt; &lt;![LOG[ \\messerschmitt.llb.mw.tu-muenchen.de\SMSClient]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:4354&quot;&gt; &lt;![LOG[ \\MESSERSCHMITT\SMSClient]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:4363&quot;&gt; &lt;![LOG[MPs:]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:4366&quot;&gt; &lt;![LOG[ messerschmitt.llb.mw.tu-muenchen.de]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:4381&quot;&gt; &lt;![LOG[Updated security on object C:\Windows\ccmsetup\.]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:8688&quot;&gt; &lt;![LOG[Sending Fallback Status Point message, STATEID='100'.]LOG]!&gt;&lt;time=&quot;11:14:59.960+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3804&quot; file=&quot;ccmsetup.cpp:9165&quot;&gt; &lt;![LOG[Request failed: 404 Not Found ]LOG]!&gt;&lt;time=&quot;11:15:00.007+-120&quot; date=&quot;07-13-2009&quot; component=&quot;FSPStateMessage&quot; context=&quot;&quot; type=&quot;3&quot; thread=&quot;3804&quot; file=&quot;fsputillib.cpp:1300&quot;&gt; &lt;![LOG[Running as user &quot;SYSTEM&quot;]LOG]!&gt;&lt;time=&quot;11:15:00.007+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3508&quot; file=&quot;ccmsetup.cpp:2529&quot;&gt; &lt;![LOG[Detected 116459 MB free disk space on system drive.]LOG]!&gt;&lt;time=&quot;11:15:00.007+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3508&quot; file=&quot;ccmsetup.cpp:459&quot;&gt; &lt;![LOG[DetectWindowsEmbeddedFBWF() Detecting OS Version]LOG]!&gt;&lt;time=&quot;11:15:00.007+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3508&quot; file=&quot;ccmsetup.cpp:505&quot;&gt; &lt;![LOG[Client OS is not Windows XP Embedded]LOG]!&gt;&lt;time=&quot;11:15:00.007+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3508&quot; file=&quot;ccmsetup.cpp:542&quot;&gt; &lt;![LOG[Ccmsetup is being restarted due to an administrative action. Installation files will be reset and downloaded again.]LOG]!&gt;&lt;time=&quot;11:15:00.007+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3508&quot; file=&quot;ccmsetup.cpp:2613&quot;&gt; &lt;![LOG[BITS version check will not be run on Vista.]LOG]!&gt;&lt;time=&quot;11:15:00.007+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3508&quot; file=&quot;ccmsetup.cpp:6699&quot;&gt; &lt;![LOG[The 'Certificate Store' is empty in the registry, using default store name 'MY'.]LOG]!&gt;&lt;time=&quot;11:15:00.023+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3508&quot; file=&quot;ccmcert.cpp:204&quot;&gt; &lt;![LOG[The 'Certificate Selection Criteria' was not specified, counting number of certificates present in 'MY' store of 'Local Computer'.]LOG]!&gt;&lt;time=&quot;11:15:00.023+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;3508&quot; file=&quot;ccmcert.cpp:3480&quot;&gt; &lt;![LOG[5 certificate(s) found in the 'MY' certificate store.]LOG]!&gt;&lt;time=&quot;11:15:00.038+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;3508&quot; file=&quot;ccmcert.cpp:3509&quot;&gt; &lt;![LOG[The 'MY' of 'Local Computer' store has 5 certificate(s). Using custom selection criteria based on the machine name.]LOG]!&gt;&lt;time=&quot;11:15:00.038+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;3508&quot; file=&quot;ccmcert.cpp:3548&quot;&gt; &lt;![LOG[Machine name is 'Junkers.llb.mw.tu-muenchen.de'.]LOG]!&gt;&lt;time=&quot;11:15:00.038+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;3508&quot; file=&quot;ccmcert.cpp:1919&quot;&gt; &lt;![LOG[SSL Registry key Software\Microsoft\CCM not found, assuming Client SSL is disabled.]LOG]!&gt;&lt;time=&quot;11:15:00.038+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;2&quot; thread=&quot;3508&quot; file=&quot;ccmutillib.cpp:134&quot;&gt; &lt;![LOG[The certificate issued to 'Junkers.llb.mw.tu-muenchen.de' has 'Client Authentication' capability.]LOG]!&gt;&lt;time=&quot;11:15:00.038+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;3508&quot; file=&quot;ccmcert.cpp:432&quot;&gt; &lt;![LOG[Using the certificate issued to 'Junkers.llb.mw.tu-muenchen.de'.]LOG]!&gt;&lt;time=&quot;11:15:00.038+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;3508&quot; file=&quot;ccmcert.cpp:3593&quot;&gt; &lt;![LOG[Failed to send HTTP request. (Error at WinHttpSendRequest: 12030)]LOG]!&gt;&lt;time=&quot;11:15:00.101+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;2&quot; thread=&quot;3508&quot; file=&quot;ccmsetup.cpp:5740&quot;&gt; &lt;![LOG[DownloadFileByWinHTTP encountered an unrecoverable error.]LOG]!&gt;&lt;time=&quot;11:15:00.101+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;3&quot; thread=&quot;3508&quot; file=&quot;ccmsetup.cpp:5787&quot;&gt; &lt;![LOG[Sending Fallback Status Point message, STATEID='308'.]LOG]!&gt;&lt;time=&quot;11:15:00.101+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;3508&quot; file=&quot;ccmsetup.cpp:9165&quot;&gt; &lt;![LOG[Request failed: 404 Not Found]LOG]!&gt;&lt;time=&quot;11:15:00.117+-120&quot; date=&quot;07-13-2009&quot; component=&quot;FSPStateMessage&quot; context=&quot;&quot; type=&quot;3&quot; thread=&quot;3508&quot; file=&quot;fsputillib.cpp:1300&quot;&gt;</pre> <br/> CCMsetup.log (windows server 2003 32bit):<br/> <pre lang=x-html>&lt;![LOG[==========[ ccmsetup started in process 2256 ]==========]LOG]!&gt;&lt;time=&quot;10:59:31.343+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:8849&quot;&gt;<br/> &lt;![LOG[Version: 4.0.6221.1000]LOG]!&gt;&lt;time=&quot;10:59:31.437+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:1907&quot;&gt;<br/> &lt;![LOG[Command line parameters for ccmsetup have been specified. No registry lookup for command line parameters is required.]LOG]!&gt;&lt;time=&quot;10:59:31.437+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:3932&quot;&gt;<br/> &lt;![LOG[Command line: &quot;C:\WINDOWS\system32\ccmsetup\ccmsetup.exe&quot; /runservice /config:MobileClient.tcf]LOG]!&gt;&lt;time=&quot;10:59:31.437+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:3941&quot;&gt;<br/> &lt;![LOG[CCMHTTPPORT: 80]LOG]!&gt;&lt;time=&quot;10:59:31.531+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:7847&quot;&gt;<br/> &lt;![LOG[CCMHTTPSPORT: 443]LOG]!&gt;&lt;time=&quot;10:59:31.531+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:7862&quot;&gt;<br/> &lt;![LOG[CCMHTTPSSTATE: 63]LOG]!&gt;&lt;time=&quot;10:59:31.531+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:7880&quot;&gt;<br/> &lt;![LOG[CCMHTTPSCERTNAME: ]LOG]!&gt;&lt;time=&quot;10:59:31.531+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:7908&quot;&gt;<br/> &lt;![LOG[FSP: MESSERSCHMITT.LLB.MW.TU-MUENCHEN.DE]LOG]!&gt;&lt;time=&quot;10:59:31.531+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:7923&quot;&gt;<br/> &lt;![LOG[CCMFIRSTCERT: 0]LOG]!&gt;&lt;time=&quot;10:59:31.531+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:7965&quot;&gt;<br/> &lt;![LOG[Config file: C:\WINDOWS\system32\ccmsetup\MobileClient.tcf]LOG]!&gt;&lt;time=&quot;10:59:31.531+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:4336&quot;&gt;<br/> &lt;![LOG[Retry time: 10 minute(s)]LOG]!&gt;&lt;time=&quot;10:59:31.531+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:4337&quot;&gt;<br/> &lt;![LOG[MSI log file: ]LOG]!&gt;&lt;time=&quot;10:59:31.531+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:4338&quot;&gt;<br/> &lt;![LOG[MSI properties: INSTALL=&quot;ALL&quot; SMSSITECODE=&quot;LLB&quot; CCMHTTPPORT=&quot;80&quot; CCMHTTPSPORT=&quot;443&quot; CCMHTTPSSTATE=&quot;63&quot; FSP=&quot;MESSERSCHMITT.LLB.MW.TU-MUENCHEN.DE&quot; CCMFIRSTCERT=&quot;0&quot;]LOG]!&gt;&lt;time=&quot;10:59:31.531+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:4339&quot;&gt;<br/> &lt;![LOG[Source List:]LOG]!&gt;&lt;time=&quot;10:59:31.531+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:4347&quot;&gt;<br/> &lt;![LOG[ \\messerschmitt.llb.mw.tu-muenchen.de\SMSClient]LOG]!&gt;&lt;time=&quot;10:59:31.531+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:4354&quot;&gt;<br/> &lt;![LOG[ \\MESSERSCHMITT\SMSClient]LOG]!&gt;&lt;time=&quot;10:59:31.531+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:4363&quot;&gt;<br/> &lt;![LOG[MPs:]LOG]!&gt;&lt;time=&quot;10:59:31.531+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:4366&quot;&gt;<br/> &lt;![LOG[ messerschmitt.llb.mw.tu-muenchen.de]LOG]!&gt;&lt;time=&quot;10:59:31.531+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:4381&quot;&gt;<br/> &lt;![LOG[Updated security on object C:\WINDOWS\system32\ccmsetup\.]LOG]!&gt;&lt;time=&quot;10:59:31.734+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:8688&quot;&gt;<br/> &lt;![LOG[Sending Fallback Status Point message, STATEID='100'.]LOG]!&gt;&lt;time=&quot;10:59:31.734+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;ccmsetup.cpp:9165&quot;&gt;<br/> &lt;![LOG[State message with TopicType 800 and TopicId {EC5364A1-A6D5-4E6D-AD86-D9203B5A5428} has been sent to the FSP]LOG]!&gt;&lt;time=&quot;10:59:34.437+-120&quot; date=&quot;07-13-2009&quot; component=&quot;FSPStateMessage&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2260&quot; file=&quot;fsputillib.cpp:730&quot;&gt;<br/> &lt;![LOG[Running as user &quot;SYSTEM&quot;]LOG]!&gt;&lt;time=&quot;10:59:34.437+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2408&quot; file=&quot;ccmsetup.cpp:2529&quot;&gt;<br/> &lt;![LOG[Detected 29568 MB free disk space on system drive.]LOG]!&gt;&lt;time=&quot;10:59:34.437+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2408&quot; file=&quot;ccmsetup.cpp:459&quot;&gt;<br/> &lt;![LOG[DetectWindowsEmbeddedFBWF() Detecting OS Version]LOG]!&gt;&lt;time=&quot;10:59:34.437+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2408&quot; file=&quot;ccmsetup.cpp:505&quot;&gt;<br/> &lt;![LOG[Client OS is not Windows XP Embedded]LOG]!&gt;&lt;time=&quot;10:59:34.437+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2408&quot; file=&quot;ccmsetup.cpp:542&quot;&gt;<br/> &lt;![LOG[Successfully ran BITS check.]LOG]!&gt;&lt;time=&quot;10:59:37.015+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2408&quot; file=&quot;ccmsetup.cpp:6944&quot;&gt;<br/> &lt;![LOG[Registry entry 'Certificate Store' is either missing or empty.]LOG]!&gt;&lt;time=&quot;10:59:37.062+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2408&quot; file=&quot;ccmcert.cpp:133&quot;&gt;<br/> &lt;![LOG[The 'Certificate Store' is empty in the registry, using default store name 'MY'.]LOG]!&gt;&lt;time=&quot;10:59:37.062+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2408&quot; file=&quot;ccmcert.cpp:204&quot;&gt;<br/> &lt;![LOG[Registry entry 'Certificate Selection Criteria' is either missing or empty.]LOG]!&gt;&lt;time=&quot;10:59:37.062+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2408&quot; file=&quot;ccmcert.cpp:133&quot;&gt;<br/> &lt;![LOG[The 'Certificate Selection Criteria' was not specified, counting number of certificates present in 'MY' store of 'Local Computer'.]LOG]!&gt;&lt;time=&quot;10:59:37.062+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2408&quot; file=&quot;ccmcert.cpp:3480&quot;&gt;<br/> &lt;![LOG[1 certificate(s) found in the 'MY' certificate store.]LOG]!&gt;&lt;time=&quot;10:59:37.062+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2408&quot; file=&quot;ccmcert.cpp:3509&quot;&gt;<br/> &lt;![LOG[Only one certificate present in the certificate store.]LOG]!&gt;&lt;time=&quot;10:59:37.062+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2408&quot; file=&quot;ccmcert.cpp:3517&quot;&gt;<br/> &lt;![LOG[Client SSL is enabled. The current state is 0x63.]LOG]!&gt;&lt;time=&quot;10:59:37.062+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2408&quot; file=&quot;ccmutillib.cpp:171&quot;&gt;<br/> &lt;![LOG[Sending Fallback Status Point message, STATEID='315'.]LOG]!&gt;&lt;time=&quot;10:59:37.140+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2408&quot; file=&quot;ccmsetup.cpp:9165&quot;&gt;<br/> &lt;![LOG[State message with TopicType 800 and TopicId {178619F1-9CC2-4799-A1AC-82BE576E176D} has been sent to the FSP]LOG]!&gt;&lt;time=&quot;10:59:37.218+-120&quot; date=&quot;07-13-2009&quot; component=&quot;FSPStateMessage&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2408&quot; file=&quot;fsputillib.cpp:730&quot;&gt;</pre> <br/> CCMsetup.log (windows server 2003 64bit; server = DC):<br/> <pre lang=x-html>&lt;![LOG[==========[ ccmsetup started in process 3768 ]==========]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:8849&quot;&gt;<br/> &lt;![LOG[Version: 4.0.6221.1000]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:1907&quot;&gt;<br/> &lt;![LOG[Command line parameters for ccmsetup have been specified. No registry lookup for command line parameters is required.]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:3932&quot;&gt;<br/> &lt;![LOG[Command line: &quot;C:\WINDOWS\ccmsetup\ccmsetup.exe&quot; /runservice /config:MobileClient.tcf]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:3941&quot;&gt;<br/> &lt;![LOG[CCMHTTPPORT: 80]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:7847&quot;&gt;<br/> &lt;![LOG[CCMHTTPSPORT: 443]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:7862&quot;&gt;<br/> &lt;![LOG[CCMHTTPSSTATE: 63]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:7880&quot;&gt;<br/> &lt;![LOG[CCMHTTPSCERTNAME: ]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:7908&quot;&gt;<br/> &lt;![LOG[FSP: MESSERSCHMITT.LLB.MW.TU-MUENCHEN.DE]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:7923&quot;&gt;<br/> &lt;![LOG[CCMFIRSTCERT: 0]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:7965&quot;&gt;<br/> &lt;![LOG[Config file: C:\WINDOWS\ccmsetup\MobileClient.tcf]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:4336&quot;&gt;<br/> &lt;![LOG[Retry time: 10 minute(s)]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:4337&quot;&gt;<br/> &lt;![LOG[MSI log file: ]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:4338&quot;&gt;<br/> &lt;![LOG[MSI properties: INSTALL=&quot;ALL&quot; SMSSITECODE=&quot;LLB&quot; CCMHTTPPORT=&quot;80&quot; CCMHTTPSPORT=&quot;443&quot; CCMHTTPSSTATE=&quot;63&quot; FSP=&quot;MESSERSCHMITT.LLB.MW.TU-MUENCHEN.DE&quot; CCMFIRSTCERT=&quot;0&quot;]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:4339&quot;&gt;<br/> &lt;![LOG[Source List:]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:4347&quot;&gt;<br/> &lt;![LOG[ \\messerschmitt.llb.mw.tu-muenchen.de\SMSClient]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:4354&quot;&gt;<br/> &lt;![LOG[ \\MESSERSCHMITT\SMSClient]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:4363&quot;&gt;<br/> &lt;![LOG[MPs:]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:4366&quot;&gt;<br/> &lt;![LOG[ messerschmitt.llb.mw.tu-muenchen.de]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:4381&quot;&gt;<br/> &lt;![LOG[Updated security on object C:\WINDOWS\ccmsetup\.]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:8688&quot;&gt;<br/> &lt;![LOG[Sending Fallback Status Point message, STATEID='100'.]LOG]!&gt;&lt;time=&quot;10:26:18.246+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;ccmsetup.cpp:9165&quot;&gt;<br/> &lt;![LOG[State message with TopicType 800 and TopicId {89E19F3C-7420-4E0B-8BEC-E449E3D30A51} has been sent to the FSP]LOG]!&gt;&lt;time=&quot;10:26:18.449+-120&quot; date=&quot;07-13-2009&quot; component=&quot;FSPStateMessage&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;8048&quot; file=&quot;fsputillib.cpp:730&quot;&gt;<br/> &lt;![LOG[Running as user &quot;SYSTEM&quot;]LOG]!&gt;&lt;time=&quot;10:26:18.449+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2720&quot; file=&quot;ccmsetup.cpp:2529&quot;&gt;<br/> &lt;![LOG[Detected 88148 MB free disk space on system drive.]LOG]!&gt;&lt;time=&quot;10:26:18.449+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2720&quot; file=&quot;ccmsetup.cpp:459&quot;&gt;<br/> &lt;![LOG[DetectWindowsEmbeddedFBWF() Detecting OS Version]LOG]!&gt;&lt;time=&quot;10:26:18.449+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2720&quot; file=&quot;ccmsetup.cpp:505&quot;&gt;<br/> &lt;![LOG[Client OS is not Windows XP Embedded]LOG]!&gt;&lt;time=&quot;10:26:18.449+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2720&quot; file=&quot;ccmsetup.cpp:542&quot;&gt;<br/> &lt;![LOG[Ccmsetup is being restarted due to an administrative action. Installation files will be reset and downloaded again.]LOG]!&gt;&lt;time=&quot;10:26:18.449+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2720&quot; file=&quot;ccmsetup.cpp:2613&quot;&gt;<br/> &lt;![LOG[The 'Certificate Store' is empty in the registry, using default store name 'MY'.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:204&quot;&gt;<br/> &lt;![LOG[The 'Certificate Selection Criteria' was not specified, counting number of certificates present in 'MY' store of 'Local Computer'.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:3480&quot;&gt;<br/> &lt;![LOG[8 certificate(s) found in the 'MY' certificate store.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:3509&quot;&gt;<br/> &lt;![LOG[The 'MY' of 'Local Computer' store has 8 certificate(s). Using custom selection criteria based on the machine name.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:3548&quot;&gt;<br/> &lt;![LOG[Machine name is 'server1.llb.mw.tu-muenchen.de'.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1919&quot;&gt;<br/> &lt;![LOG[There are no certificate(s) that meet the criteria.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1748&quot;&gt;<br/> &lt;![LOG[Performing search that includes SAN2 extensions...]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1955&quot;&gt;<br/> &lt;![LOG[Certificate doesn't have SAN2 extension.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1307&quot;&gt;<br/> &lt;![LOG[Found a certificate with subject name as ‘server1’, but will continue to look for the certificate with subject name as ‘server1.llb.mw.tu-muenchen.de’.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1284&quot;&gt;<br/> &lt;![LOG[Checking if certificate issued to 'server1.llb.mw.tu-muenchen.de' is valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1233&quot;&gt;<br/> &lt;![LOG[Client SSL is disabled. Setting state to 0x0.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2720&quot; file=&quot;ccmutillib.cpp:184&quot;&gt;<br/> &lt;![LOG[The certificate issued to 'server1' doesn't have 'Client Authentication' capability.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:449&quot;&gt;<br/> &lt;![LOG[The certificate found using 'server1.llb.mw.tu-muenchen.de' as cert name is not valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1275&quot;&gt;<br/> &lt;![LOG[Found a certificate with subject name as ‘server1’, but will continue to look for the certificate with subject name as ‘server1.llb.mw.tu-muenchen.de’.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1284&quot;&gt;<br/> &lt;![LOG[Checking if certificate issued to 'server1.llb.mw.tu-muenchen.de' is valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1233&quot;&gt;<br/> &lt;![LOG[Certificate issued to 'server1' has expired.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;3&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:962&quot;&gt;<br/> &lt;![LOG[The certificate found using 'server1.llb.mw.tu-muenchen.de' as cert name is not valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1275&quot;&gt;<br/> &lt;![LOG[Found a certificate with subject name as ‘server1’, but will continue to look for the certificate with subject name as ‘server1.llb.mw.tu-muenchen.de’.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1284&quot;&gt;<br/> &lt;![LOG[Checking if certificate issued to 'server1.llb.mw.tu-muenchen.de' is valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1233&quot;&gt;<br/> &lt;![LOG[The certificate issued to 'server1' doesn't have 'Client Authentication' capability.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:449&quot;&gt;<br/> &lt;![LOG[The certificate found using 'server1.llb.mw.tu-muenchen.de' as cert name is not valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1275&quot;&gt;<br/> &lt;![LOG[Found a certificate with subject name as ‘server1’, but will continue to look for the certificate with subject name as ‘server1.llb.mw.tu-muenchen.de’.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1284&quot;&gt;<br/> &lt;![LOG[Checking if certificate issued to 'server1.llb.mw.tu-muenchen.de' is valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1233&quot;&gt;<br/> &lt;![LOG[The certificate issued to 'server1' doesn't have 'Client Authentication' capability.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:449&quot;&gt;<br/> &lt;![LOG[The certificate found using 'server1.llb.mw.tu-muenchen.de' as cert name is not valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1275&quot;&gt;<br/> &lt;![LOG[Found a certificate with subject name as ‘server1’, but will continue to look for the certificate with subject name as ‘server1.llb.mw.tu-muenchen.de’.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1284&quot;&gt;<br/> &lt;![LOG[Checking if certificate issued to 'server1.llb.mw.tu-muenchen.de' is valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1233&quot;&gt;<br/> &lt;![LOG[Certificate issued to 'server1' has expired.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;3&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:962&quot;&gt;<br/> &lt;![LOG[The certificate found using 'server1.llb.mw.tu-muenchen.de' as cert name is not valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1275&quot;&gt;<br/> &lt;![LOG[Certificate doesn't have SAN2 extension.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1307&quot;&gt;<br/> &lt;![LOG[Found a certificate with subject name as ‘server1’, but will continue to look for the certificate with subject name as ‘server1.llb.mw.tu-muenchen.de’.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1284&quot;&gt;<br/> &lt;![LOG[Checking if certificate issued to 'server1.llb.mw.tu-muenchen.de' is valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1233&quot;&gt;<br/> &lt;![LOG[The certificate issued to 'server1' doesn't have 'Client Authentication' capability.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:449&quot;&gt;<br/> &lt;![LOG[The certificate found using 'server1.llb.mw.tu-muenchen.de' as cert name is not valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1275&quot;&gt;<br/> &lt;![LOG[Using custom selection criteria based on the machine NetBIOS name.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:3568&quot;&gt;<br/> &lt;![LOG[Machine name is 'SERVER1'.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1919&quot;&gt;<br/> &lt;![LOG[The certificate issued to 'server1' doesn't have 'Client Authentication' capability.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:449&quot;&gt;<br/> &lt;![LOG[Skipping certificate that is not valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1740&quot;&gt;<br/> &lt;![LOG[Certificate issued to 'server1' has expired.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;3&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:962&quot;&gt;<br/> &lt;![LOG[Skipping certificate that is not valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1740&quot;&gt;<br/> &lt;![LOG[The certificate issued to 'server1' doesn't have 'Client Authentication' capability.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:449&quot;&gt;<br/> &lt;![LOG[Skipping certificate that is not valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.481+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1740&quot;&gt;<br/> &lt;![LOG[The certificate issued to 'server1' doesn't have 'Client Authentication' capability.]LOG]!&gt;&lt;time=&quot;10:26:18.496+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:449&quot;&gt;<br/> &lt;![LOG[Skipping certificate that is not valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.496+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1740&quot;&gt;<br/> &lt;![LOG[Certificate issued to 'server1' has expired.]LOG]!&gt;&lt;time=&quot;10:26:18.496+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;3&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:962&quot;&gt;<br/> &lt;![LOG[Skipping certificate that is not valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.496+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1740&quot;&gt;<br/> &lt;![LOG[The certificate issued to 'server1' doesn't have 'Client Authentication' capability.]LOG]!&gt;&lt;time=&quot;10:26:18.496+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:449&quot;&gt;<br/> &lt;![LOG[Skipping certificate that is not valid for ConfigMgr usage.]LOG]!&gt;&lt;time=&quot;10:26:18.496+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1740&quot;&gt;<br/> &lt;![LOG[There are no certificate(s) that meet the criteria.]LOG]!&gt;&lt;time=&quot;10:26:18.496+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;0&quot; thread=&quot;2720&quot; file=&quot;ccmcert.cpp:1748&quot;&gt;<br/> &lt;![LOG[Sending Fallback Status Point message, STATEID='315'.]LOG]!&gt;&lt;time=&quot;10:26:18.496+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2720&quot; file=&quot;ccmsetup.cpp:9165&quot;&gt;<br/> &lt;![LOG[State message with TopicType 800 and TopicId {59BB9AC2-BD7F-474B-9A63-A2B56413DCFF} has been sent to the FSP]LOG]!&gt;&lt;time=&quot;10:26:18.512+-120&quot; date=&quot;07-13-2009&quot; component=&quot;FSPStateMessage&quot; context=&quot;&quot; type=&quot;1&quot; thread=&quot;2720&quot; file=&quot;fsputillib.cpp:730&quot;&gt;<br/> &lt;![LOG[The language specific BITS version wasn't found (Failed to download 'WindowsServer2003.WindowsXP-KB923845-x64-ENU.exe' from 'https://messerschmitt.llb.mw.tu-muenchen.de/CCM_Client/x64/BITS25' with error code 0x80040281).]LOG]!&gt;&lt;time=&quot;10:26:18.512+-120&quot; date=&quot;07-13-2009&quot; component=&quot;ccmsetup&quot; context=&quot;&quot; type=&quot;3&quot; thread=&quot;2720&quot; file=&quot;ccmsetup.cpp:6906&quot;&gt;<br/> </pre> <br/> Both win 2008 servers have the certificates installed, but cannot connect to the SCCM website.<br/> <br/> Both win 2003 servers seem not to get any certificate from the certificate authority (win 2008 DC). If I try to request the certificate manually (as domain admin), I always get the message: &quot;The wizzard cannot be started because of one ore more of the following conditions: - There are no trusted CAs availlable; - you do not have the permission to request certificates from the availlable CAs; - the available CAs issue certificates for which you &quot;do not have permissions&quot;<br/> <br/> Has anyone a solution for that.<br/> <br/> Thanks and Best Regards<br/> <br/> Tom<br/> <br/>Mon, 13 Jul 2009 09:59:50 Z2009-08-06T15:31:22Z