Client Upgrade - Console shows not approved
In the middle of a SMS to SCCM upgrade. I am running into a few clients who have the new client installed (upgraded from SMS client), yet are not Approved in the console, thus we can not remote tools them, etc. The status of them states: N/A What stops the client from becoming Approved? I suppose alot of things. I have uninstalled the SCCM client on the PC, and reinstalled, still says the same thing: "N/A". Ran a Machine and User Policy update as well. Any help would be greatly appreciated!
August 19th, 2010 11:40pm

N/A has been discussed over and over in these forums. It is not an issue and should be ignored. John Marcum | http://myitforum.com/cs2/blogs/jmarcum |
Free Windows Admin Tool Kit Click here and download it now
August 19th, 2010 11:57pm

It is a problem though as these certain clients showing up as N/A are not able to be remote controlled via Remote Tools. They also show up as having the old client (I have a collection that shows any version of the client under 4.x) even though when I sit down on the machine, I see the new client. I have even tried uninstalling the new and old client and installing the new client from scratch, yet they don't get Approved and we cannot manage them.
August 20th, 2010 12:55am

Have a look at the clientidmanagerstartup.log file on the client. That the log that records the registration.Kent Agerlund | http://scug.dk/members/Agerlund/default.aspx | The Danish community for System Center products
Free Windows Admin Tool Kit Click here and download it now
August 20th, 2010 7:22am

Have a look at the clientidmanagerstartup.log file on the client. That the log that records the registration. Kent Agerlund | http://scug.dk/members/Agerlund/default.aspx | The Danish community for System Center products The log states the following. Looks to be something with client certificate. <![LOG[RegTask - Executing registration task synchronously.]LOG]!><time="08:15:21.635+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="1" thread="3720" file="regtask.cpp:779"> <![LOG[Failed to find the certificate in the store, retry 1.]LOG]!><time="08:15:21.635+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="2" thread="3720" file="ccmgencert.cpp:1143"> <![LOG[Failed to find the certificate in the store, retry 2.]LOG]!><time="08:15:21.744+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="2" thread="3720" file="ccmgencert.cpp:1143"> <![LOG[Failed to find the certificate in the store, retry 3.]LOG]!><time="08:15:21.854+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="2" thread="3720" file="ccmgencert.cpp:1143"> <![LOG[Failed to find the certificate in the store, retry 4.]LOG]!><time="08:15:21.963+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="2" thread="3720" file="ccmgencert.cpp:1143"> <![LOG[Failed to find the certificate in the store, retry 5.]LOG]!><time="08:15:22.072+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="2" thread="3720" file="ccmgencert.cpp:1143"> <![LOG[RegEndPoint: Event notification: CCM_RemoteClient_Reassigned]LOG]!><time="08:15:23.854+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="1" thread="664" file="regendpoint.cpp:198"> <![LOG[RegEndPoint: Received notification for site assignment change from '<none>' to 'GOV'.]LOG]!><time="08:15:23.870+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="1" thread="664" file="regendpoint.cpp:226"> <![LOG[Failed to find the certificate in the store, retry 1.]LOG]!><time="08:15:23.995+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="2" thread="3720" file="ccmgencert.cpp:1143"> <![LOG[Failed to find the certificate in the store, retry 2.]LOG]!><time="08:15:24.104+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="2" thread="3720" file="ccmgencert.cpp:1143"> <![LOG[Failed to find the certificate in the store, retry 3.]LOG]!><time="08:15:24.214+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="2" thread="3720" file="ccmgencert.cpp:1143"> <![LOG[Failed to find the certificate in the store, retry 4.]LOG]!><time="08:15:24.323+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="2" thread="3720" file="ccmgencert.cpp:1143"> <![LOG[Failed to find the certificate in the store, retry 5.]LOG]!><time="08:15:24.432+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="2" thread="3720" file="ccmgencert.cpp:1143"> <![LOG[RegTask: Failed to get certificate. Error: 0x80004005]LOG]!><time="08:15:24.542+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="3" thread="3720" file="regtask.cpp:326"> <![LOG[Read SMBIOS (encoded): 43004E0055003700330030003100300035003000]LOG]!><time="08:15:24.604+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="1" thread="3720" file="smbiosident.cpp:118"> <![LOG[Evaluated SMBIOS (encoded): 43004E0055003700330030003100300035003000]LOG]!><time="08:15:24.651+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="1" thread="3720" file="smbiosident.cpp:185"> <![LOG[No SMBIOS Changed]LOG]!><time="08:15:24.651+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="1" thread="3720" file="smbiosident.cpp:65"> <![LOG[SMBIOS unchanged]LOG]!><time="08:15:24.651+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="1" thread="3720" file="ccmid.cpp:919"> <![LOG[SID unchanged]LOG]!><time="08:15:24.667+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="1" thread="3720" file="ccmid.cpp:936"> <![LOG[HWID unchanged]LOG]!><time="08:15:24.808+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="1" thread="3720" file="ccmid.cpp:952"> <![LOG[RegTask: Initial backoff interval: 1 minutes]LOG]!><time="08:15:25.808+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="1" thread="3720" file="regtask.cpp:1830"> <![LOG[RegTask: Reset backoff interval: 257 minutes]LOG]!><time="08:15:25.808+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="1" thread="3720" file="regtask.cpp:1831"> <![LOG[Failed to find the certificate in the store, retry 1.]LOG]!><time="08:15:25.808+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="2" thread="3720" file="ccmgencert.cpp:1143"> <![LOG[Failed to find the certificate in the store, retry 2.]LOG]!><time="08:15:25.917+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="2" thread="3720" file="ccmgencert.cpp:1143"> <![LOG[Failed to find the certificate in the store, retry 3.]LOG]!><time="08:15:26.027+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="2" thread="3720" file="ccmgencert.cpp:1143"> <![LOG[Failed to find the certificate in the store, retry 4.]LOG]!><time="08:15:26.136+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="2" thread="3720" file="ccmgencert.cpp:1143"> <![LOG[Failed to find the certificate in the store, retry 5.]LOG]!><time="08:15:26.246+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="2" thread="3720" file="ccmgencert.cpp:1143"> <![LOG[Already refreshed within the last 10 minutes, Sleeping for the next 9 minutes before reattempt.]LOG]!><time="08:15:26.355+300" date="08-20-2010" component="ClientIDManagerStartup" context="" type="1" thread="3720" file="regtask.cpp:146">
August 20th, 2010 4:21pm

Well that could be the problem, now we just need to solve it :-) The problem is "LOG[RegTask: Failed to get certificate. Error: 0x80004005" Check this thread for a similar problem and answer - http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/1b6662aa-aba0-495f-b925-45ec2441b984Kent Agerlund | http://scug.dk/members/Agerlund/default.aspx | The Danish community for System Center products
Free Windows Admin Tool Kit Click here and download it now
August 20th, 2010 4:27pm

Yikes, so remove the PC from the domain, clean, and rejoin. Ok, I will give this a shot. Thanks man.
August 20th, 2010 5:40pm

before you go down that road make sure you also check http://blogs.technet.com/b/smsandmom/archive/2008/07/21/configmgr-2007-clients-not-installed-regtask-failed-to-get-certificate-error-0x80004005.aspxKent Agerlund | http://scug.dk/members/Agerlund/default.aspx | The Danish community for System Center products
Free Windows Admin Tool Kit Click here and download it now
August 20th, 2010 5:42pm

before you go down that road make sure you also check http://blogs.technet.com/b/smsandmom/archive/2008/07/21/configmgr-2007-clients-not-installed-regtask-failed-to-get-certificate-error-0x80004005.aspx Kent Agerlund | http://scug.dk/members/Agerlund/default.aspx | The Danish community for System Center products You the man! The above link worked great! Thank you very much. Now all the tabs on the Config Mgr Client are showing up as well, and it says the client is now approved. I have about 30 of these that need to get done so you saved me a ton of time. I'll post the answer in case the link ever goes away. ============ Issue: Some clients may not show as being installed when viewed through the System Center Configuration Manager 2007 admin console. From the target computers themselves the agents appear to function properly. When viewing the ClientLocation.log file you may also see the following error: RegTask: Failed to get certificate. Error: 0x80004005 Cause: This is caused by an issue with the RSA machine keys on the client. Resolution: To resolve this issue complete the following steps: Backup all files in the C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys folder (or the corresponding folder on your specific clients). Restart the SMS Agent Host Service to recreate these certificates. At this point the clients should start showing up in the console. If not, remove and push the client agent to the affected computers again.
August 20th, 2010 7:17pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics