Failed to reset certificate request times. (0x80041002) - SCCM Client deployment
Hi Guys
We have a problem here while deploying sccm clients to computers that belongs to a particular primary site server (PS3). We are running Mixed mode and Active directory already extended for SCCM. Also there is no firewall.
We have tier 3 structure (SCCM SP2R2) as below
CentralSite (CTS)
Primary Site 1 (PS1)
Primary Site 2 (PS2)
Primary Site 3 (PS3)
60 Secondary Site (S01-S60) 60 Secondary Site (T01-T60)
60 Secondary Site (U01-U60)
We are installing client through client push. It is reporting fine for PS1 and PS2 with correct site code but with PS3 it is either coming with site code of seconday sites or of Central site (CTS). Status of client says Yes and Approved but we are unable
to deploy packages to PCs.
Checking logs of one of the client under PS3 as follows:
ClientLocation.log
Getting Assigned Site 15/05/2010 10:50:24 AM 984 (0x03D8)
Setting Assigned Site 17/11/2010 10:33:27 AM 5640 (0x1608)
Assigning client to site 'PS3' 17/11/2010 10:33:27 AM 5640 (0x1608)
Getting Assigned Site 17/11/2010 10:33:27 AM 5640 (0x1608)
Client is currently not assigned to any site 17/11/2010 10:33:27 AM 5640 (0x1608)
Removing client site assignments 17/11/2010 10:33:27 AM 5640 (0x1608)
Raising event:
instance of CCM_RemoteClient_Reassigned
{
DateTime = "20101117010327.624000+000";
LastAssignedSite = "";
NewAssignedSite = "PS3";
ProcessID = 2952;
ThreadID = 5640;
};
17/11/2010 10:33:27 AM 5640 (0x1608)
Client assigned to site 'PS3' 17/11/2010 10:33:27 AM 5640 (0x1608)
GetCurrentManagementPointEx 17/11/2010 10:33:28 AM 2252 (0x08CC)
Current Management Point is centralsiteserver.domain.NET with version 6487 and capabilities: <Capabilities SchemaVersion="1.0">
</Capabilities>. 17/11/2010 10:33:28 AM 2252 (0x08CC)
GetCurrentManagementPointEx 17/11/2010 10:34:28 AM 2252 (0x08CC)
Current Management Point is centralsiteserver.domain.NET with version 6487 and capabilities: <Capabilities SchemaVersion="1.0">
</Capabilities>. 17/11/2010 10:34:28 AM 2252 (0x08CC)
GetCurrentManagementPointEx 17/11/2010 10:35:28 AM 2252 (0x08CC)
ClientIDManagerStartup.log
RegTask: Client is not registered. Sending registration request... 19/11/2010 8:26:59 AM 5640 (0x1608)
RegTask: Failed to send registration request message. Error: 0x80040231 19/11/2010 8:27:00 AM 5640 (0x1608)
RegTask: Failed to send registration request. Error: 0x80040231 19/11/2010 8:27:00 AM 5640 (0x1608)
RegTask: Client is not registered. Sending registration request... 19/11/2010 10:44:02 AM 5640 (0x1608)
RegTask: Failed to send registration request message. Error: 0x8000ffff 19/11/2010 10:44:06 AM 5640 (0x1608)
RegTask: Failed to send registration request. Error: 0x8000ffff 19/11/2010 10:44:06 AM 5640 (0x1608)
LocationServices.log
Sending Fallback Status Point message, STATEID='500'. 17/11/2010 10:33:27 AM 5640 (0x1608)
Current AD site of machine is SECSITE 17/11/2010 10:33:27 AM 5640 (0x1608)
LSGetAssignedSiteFromAD : Trying to Assign to the Site <PS3> 17/11/2010 10:33:27 AM 5640 (0x1608)
LSVerifySiteVersion : Verifying Site Version for <PS3> 17/11/2010 10:33:27 AM 5640 (0x1608)
LSGetSiteVersionFromAD : Successfully retrieved version '4.00.6487.0000' for site 'PS3' 17/11/2010 10:33:27 AM 5640 (0x1608)
LSVerifySiteVersion : Verified Client Version '4.00.6487.2000' is not greater than Site Version '4.00.6487.0000'. Client can be assigned to site <PS3>. 17/11/2010 10:33:27 AM 5640 (0x1608)
Current assigned site code for the client is 'PS3' 17/11/2010 10:33:27 AM 5640 (0x1608)
Sending Fallback Status Point message, STATEID='700'. 17/11/2010 10:33:27 AM 5640 (0x1608)
Unknown task LSProxyMPModificationTask in non-quarantine - ignoring. 17/11/2010 10:33:27 AM 696 (0x02B8)
Attempting to retrieve default management point from AD 17/11/2010 10:33:27 AM 5640 (0x1608)
Retrieved Default Management Point from AD: Centralsiteserver.domain.NET 17/11/2010 10:33:27 AM 5640 (0x1608)
Persisting the default management point in WMI 17/11/2010 10:33:27 AM 5640 (0x1608)
Failed to reset certificate request times. (0x80041002) 17/11/2010 10:33:27 AM 5640 (0x1608)
Persisted Default Management Point Location locally 17/11/2010 10:33:27 AM 5640 (0x1608)
Failed to reset certificate request times. (0x80041002) 17/11/2010 10:33:27 AM 5640 (0x1608)
Attempting to retrieve local MP from AD 17/11/2010 10:33:27 AM 5640 (0x1608)
Current AD site of machine is SECSITE 17/11/2010 10:33:27 AM 5640 (0x1608)
Retrieved local Management Point from AD: SECSITE1.domain.NET 17/11/2010 10:33:27 AM 5640 (0x1608)
The 'Certificate Store' is empty in the registry, using default store name 'MY'. 17/11/2010 10:33:27 AM 5640 (0x1608)
Refreshing client operational settings over AD 17/11/2010 10:33:27 AM 5640 (0x1608)
Refreshed security settings over AD 17/11/2010 10:33:27 AM 5640 (0x1608)
No security settings update detected. 17/11/2010 10:33:27 AM 5640 (0x1608)
Attempting to retrieve default management point from AD 18/11/2010 12:39:20 PM 5640 (0x1608)
Retrieved Default Management Point from AD: Centralsiteserver.domain.NET 18/11/2010 12:39:21 PM 5640 (0x1608)
Persisting the default management point in WMI 18/11/2010 12:39:21 PM 5640 (0x1608)
Persisted Default Management Point Location locally 18/11/2010 12:39:21 PM 5640 (0x1608)
Certificatemaintenance.log
MP site code 'CTS' on server auth header does not match any known site code. 18/11/2010 3:49:26 PM 5640 (0x1608)
MP site code 'CTS' on server auth header does not match any known site code. 19/11/2010 10:44:06 AM 5640 (0x1608)
CCMEXEC.log
SystemTaskProcessor::QueueEvent(PowerChanged, 0) 19/11/2010 9:44:46 AM 4108 (0x100C)
SystemTaskProcessor::QueueEvent(PowerChangedEx, 0) 19/11/2010 9:44:46 AM 4108 (0x100C)
SystemTaskProcessor::QueueEvent(PowerChanged, 0) 19/11/2010 9:56:08 AM 4108 (0x100C)
SystemTaskProcessor::QueueEvent(PowerChangedEx, 0) 19/11/2010 9:56:08 AM 4108 (0x100C)
SystemTaskProcessor::QueueEvent(PowerChanged, 0) 19/11/2010 10:16:20 AM 4108 (0x100C)
SystemTaskProcessor::QueueEvent(NetworkChangedRaw, 1) 19/11/2010 10:16:21 AM 2588 (0x0A1C)
SystemTaskProcessor::QueueEvent(PowerChanged, 0) 19/11/2010 10:44:03 AM 4108 (0x100C)
Raising event:
instance of CCM_CcmHttp_Status
{
DateTime = "20101119011406.752000+000";
HostName = "CentralSiteServer.domain.NET";
HRESULT = "0x00000000";
ProcessID = 2952;
StatusCode = 0;
ThreadID = 5640;
};
19/11/2010 10:44:06 AM 5640 (0x1608)
HandleRemoteSyncSend failed (0x8000ffff). 19/11/2010 10:44:06 AM 5640 (0x1608)
CForwarder_Sync::Send failed (0x8000ffff). 19/11/2010 10:44:06 AM 5640 (0x1608)
CForwarder_Base::Send failed (0x8000ffff). 19/11/2010 10:44:06 AM 5640 (0x1608)
SystemTaskProcessor::QueueEvent(NetworkChangedRaw, 1) 19/11/2010 10:44:07 AM 3280 (0x0CD0)
I went through many posts and test management points at all tiers and its working fine. Uninstalled and reinstalled client many time.. same issue. I
Please advise some more areas to troubleshoot
Thanks
Veday
Server Engineer
November 19th, 2010 12:45am
Is there a default MP defined on PR3?
have you configured client boundaries on PR3 site properly?
verify hman.log and sitecomp.log on PR3 and make sure it is publishing the information properly on AD.
Regards, Madan
Free Windows Admin Tool Kit Click here and download it now
November 19th, 2010 1:22am
Thanks Madan.
Yes there is MP on PS3. I did mpcert,mplist and mpcontrol.log check and its responding fine.
Both logs looks alright. Double checked bounderies for PS3. It includes all PS3 sites and is protected.
Issue still persists?? Please advise ////Thanks
hman.log showing all respective secondary site with correct info
sitecomp.log
Publish Servers in Active Directory. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
DS Root:DC=domain,DC=net SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Searching for the System Management Container. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
LDAP://CN=System Management,CN=System,DC=domain,DC=net container exists. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Site System <Primarysite3> is the Default Management Point. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
No Fallback Status Point installed on the Site SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Size of Signing Certificate: 0 SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Signing Certificate: SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Checking configuration information for server: Primarysite3. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Primarysite3 is the Default MP. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
MP Configuration for Primarysite3 is correct. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Installing Security settings on site system ... SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Security settings are up to date for Primarysite3. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Installing DNS publishing settings on site system ... SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
DNS publishing settings are up to date for Primarysite3. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Publishing Primarysite3(CentralSiteServer.domain.NET) as a Management Point into Active Directory. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
SMS-MP-PS3-Primarysite3 successfully updated. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Waiting for changes to the "C:\Program Files (x86)\Microsoft Configuration Manager\inboxes\sitectrl.box" or "C:\Program Files (x86)\Microsoft Configuration Manager\inboxes\sitecomp.box" directories, servers will be polled in 1 hour... SMS_SITE_COMPONENT_MANAGER 19/11/2010
3:06:42 PM 1836 (0x072C)
Server Engineer
November 19th, 2010 1:34am
Thanks Madan. Both logs looks alright. Double checked bounderies for PS3. It includes all PS3 sites and is protected.
Issue still persists?? Please advise ////Thanks
hman.log showing all respective secondary site with correct info
sitecomp.log
Publish Servers in Active Directory. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
DS Root:DC=domain,DC=net SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Searching for the System Management Container. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
LDAP://CN=System Management,CN=System,DC=domain,DC=net container exists. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Site System <Primarysite3> is the Default Management Point. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
No Fallback Status Point installed on the Site SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Size of Signing Certificate: 0 SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Signing Certificate: SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Checking configuration information for server: Primarysite3. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Primarysite3 is the Default MP. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
MP Configuration for Primarysite3 is correct. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Installing Security settings on site system ... SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Security settings are up to date for Primarysite3. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Installing DNS publishing settings on site system ... SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
DNS publishing settings are up to date for Primarysite3. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Publishing Primarysite3(CentralSiteServer.domain.NET) as a Management Point into Active Directory. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
SMS-MP-PS3-Primarysite3 successfully updated. SMS_SITE_COMPONENT_MANAGER 19/11/2010 3:06:42 PM 1836 (0x072C)
Waiting for changes to the "C:\Program Files (x86)\Microsoft Configuration Manager\inboxes\sitectrl.box" or "C:\Program Files (x86)\Microsoft Configuration Manager\inboxes\sitecomp.box" directories, servers will be polled in 1 hour... SMS_SITE_COMPONENT_MANAGER 19/11/2010
3:06:42 PM 1836 (0x072C)
Server Engineer
Free Windows Admin Tool Kit Click here and download it now
November 19th, 2010 1:38am
What is the FQDN name for your PR3 site?
Are the following correct?
NetBIOS Name of PR3 site system: Primarysite3
FQDN name for PR3 site system: CentralSiteServer.domain.NET
I'm suspecting that the fully qualifyed domain name for this server is wrong.
Could you confirm.
Regards, Madan
November 19th, 2010 7:41am
Thanks...Good pick
NetBIOS Name of PR3 site system: Primarysite3
FQDN name for PR3 site system: Primarysite3.domain.NET
i checked everywhere in DNS, configuration settings in console but it is correctly stated as above. I don't know why sitecomp.log is picking CentralSiteServer.domain.NET
Can you please provide some information where it can be wrong?
Thanks & Regards
Veday
Server Engineer
Free Windows Admin Tool Kit Click here and download it now
November 19th, 2010 7:57am
Bring up the properties of your site server in the ConfigMgr console (site settings -> site systems -> ConfigMgr site system). That's where you can enter an FQDN.
November 19th, 2010 8:27am
Hi, Correct the FQDN name as suggested by Torsten.
PR3 site -> site settings -> site systems -> click on your PR2 server name
and in the right hand side select ConfigMgr site system, right click and select properties. Here you can change the FQDN name.
After you connected the FQDN, make sure the data is published again in the AD(watch Hman.log and sitecomp.log)
Restart the client and see whether the problem is resolved or not.Regards, Madan
Free Windows Admin Tool Kit Click here and download it now
November 19th, 2010 8:41am
Thanks Torsten & Madan
You were right on spot.. FQDN was incorrect. Corrected FQDN. checked sitecomp.log and is all good.
But some strange thing happened. There were 144 computers were in collection out of which 104 computers were installed with client using client push before. Client were installed with status yes and approved but there site code was not of Primary site but
of their secondary site itself. After this change, 104 computers disappeared from collection and only left with 40 where client was not installed before. These 144 computers were added explicitely to collection and not discovered using query.
Again started installing client on few computers that were visible in console. ccmsetup.log reveals client is successfully installed but client status is No, not approved and with incorrect sitecode.
Checked clientidmanagerstaartup.log. It is still coming up with as below:
RegTask: Client is not registered. Sending registration request... 20/11/2010 8:43:11 AM 1420 (0x58C)
RegTask: Failed to send registration request message. Error: 0x80040231 20/11/2010 8:43:11 AM 1420 (0x58C)
RegTask: Failed to send registration request. Error: 0x80040231 20/11/2010 8:43:11 AM 1420 (0x58C)
I am not sure, why those PCs suddenly disappeared from collection.
Server Engineer
November 19th, 2010 6:32pm
Please ping your management point server from your client machines and check the IP address of the MP is correct or not?
Regards, Madan
Free Windows Admin Tool Kit Click here and download it now
November 20th, 2010 12:48am
Its seems to be all working now. It might be just timing issue after i changed FQDN. I should have waited for sometime.
Thanks Madan and Torsten for your help.
But
Computers disappeared from collection after I changed to correct FQDN is still a mystery. :)
Server Engineer
November 20th, 2010 3:22am