SCCM 2012 R2, workgroup clients... MP critical status:  HttpSendRequestSync failed port 443 (error code 404), and other errors

Hi, dear mates...
Firstly, I would like to say thanks for many of the posts about SCCM2012 that have helped me to know better SCCM2012 and begin to understand it. Anyway, I'm still a rookie on this system.
On the other hand I've several problems configuriying my SCCM environment. This is my scenario:
I have all the infraestructure in one server, located on Azure. The server is only for admin SCCM 2012 R2 (version 5.0.8239.100, (with the hotfix KB3073015 installed -CU5  not applicable-). WS 2012 R2 and SQL2012.  I need it ,basically,  for admin the security and updates of 30 workgroup windows machines (Win7 pro and W embeded 7) that connect to internet via 3G.
Now I'm working in a lab environment with the SCCM server and two machines (one with W7 and the other with WEmbedded 7. NOTE:  As soon as I got the clients set-up, I had problems with Guid's duplication,  so I issued a new client certificate, and currently both  computers have its own client certificate, but the GUID duplication (after permormed the recommended actions) hasn't solved, but I'll send another post about it)
I've got to solve many problems about PKi infraestructure, finding out for just the ccmpsetup.exe parameters that I needed to setup the clients, etc... After I have solved many errors about MP, checking right all the prerequisites regarding the software needed (all about differential comppresion, .net Framework, ASP.NET 4.5, Visual c++ etc...),  applicable hotfixes, reinstalling SCCM, IIS, Wsus, the clients, Check and configuration of Webdav, test the consitency of WMI ... test the access to ?mp_list and ?mpcert successfully etc...
Anyway,  I would need to fix the below errors, to be able to carry on with the sccm administration.
MPSETUP.LOG ----> ok, without errors
MPMSI.LOG...
[13:09:36] IGNORE: Failed to delete extension 'C:\Program Files\SMS_CCM\getpolicy.dll'. Return Code = 0x80020009 (The extension might not be registered)...[13:09:36] Method 'DeleteExtensionFileRecord' failed with 80020009
MSI (s) (08:E8) [13:10:22:986]: Executing op: ServiceInstall(Name=CcmExec,DisplayName=SMS Agent Host,ImagePath="C:\Program Files\SMS_CCM\CcmExec.exe",ServiceType=16,StartType=2,ErrorControl=1,,Dependencies=winmgmt[~][~][~],,StartName=LocalSystem,Password=**********,Description=Provides change and configuration services for computer management systems.,,)
Property(S): InstallErrorDialog_Title = Setup Aborted ..... Property(S): InstallErrorDialog_SubTitle = Setup failed....Property(S): InstallErrorDialog_Info = Setup encountered an error and could not continue.
CTR:MessagesFailed,164,165,65792,novice,0
MSI (s) (08:E8) [13:09:39:644]: Executing op: TypeLibraryRegister(,,FilePath=C:\Windows\system32\ccmcore.dll,LibID={90C7E669-C86D-48A6-8F7A-B16521DB52BD},,,Language=0,,BinaryType=1,IgnoreRegistrationFailure=0,
MSI (s) (08:E8) [13:10:26:654]: Windows Installer installed the product. Product Name: ConfigMgr Management Point. Product Version: 5.00.8239.1000. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
MPCONTROL.LOG
Call to HttpSendRequestSync failed for port 443 with status code 404, text: Not Found
Http test request failed, status code is 404, 'Not Found'.
ReadMPStringSettings(): RegQueryValueExW() failed - 0x80070002

Eventviewer...

Log Name:      Application
Source:        SMS Server
Date:          8/7/2015 3:47:13 PM
Event ID:      5436
Task Category: SMS_MP_CONTROL_MANAGER
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      pudocontrol.domain-name.cloudapp.net
Description:
On 8/7/2015 3:47:13 PM, component SMS_MP_CONTROL_MANAGER on computer pudocontrol.pudocontrol.cloudapp.net reported:  MP Control Manager detected management point is not responding to HTTP requests.  The HTTP status code and text is 404, Not Found.

Possible cause: Management point encountered an error when connecting to SQL Server.
Solution: Verify that the SQL Server is properly configured to allow Management Point access. Verify that management point computer account or the Management Point Database Connection Account is a member of Management Point Role (msdbrole_MP) in the SQL Server database.

Possible cause:  The SQL Server Service Principal Names (SPNs) are not registered correctly in Active Directory
Solution:  Ensure SQL Server SPNs are correctly registered.  Review Q829868.

Possible cause: Internet Information Services (IIS) isn't configured to listen on the ports over which the site is configured to communicate.
Solution: Verify that the designated Web Site is configured to use the same ports which the site is configured to use.

Possible cause: The designated Web Site is disabled in IIS.
Solution: Verify that the designated Web Site is enabled, and functioning properly.

Possible cause: The MP ISAPI Application Identity does not have the requisite logon privileges.
Solution: Verify that the account that the MP ISAPI is configured to run under has not been denied batch logon rights through group policy.



-----------------------------------------------------------------------------


Log Name:      Application
Source:        MSSQLSERVER
Date:          8/7/2015 1:10:50 PM
Event ID:      17806
Task Category: Logon
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      pudocontrol.domain-name.cloudapp.net
Description:
SSPI handshake failed with error code 0x80090304, state 14 while establishing a connection with integrated security;
the connection has been closed. Reason: AcceptSecurityContext failed.
The Windows error code indicates the cause of failure. The Local Security Authority cannot be contacted
[CLIENT: <local machine>]

-------------------------------------------------------------------------------




Log Name:      Application
Source:        Microsoft-Windows-CertificationAuthority
Date:          8/7/2015 1:12:20 PM
Event ID:      91
Task Category: None
Level:         Error
Keywords:      
User:          SYSTEM
Computer:      pudocontrol.domain-name.cloudapp.net
Description:
Could not connect to the Active Directory.  Active Directory Certificate Services will retry when processing
requires Active Directory access.

---------------------------------------------------------------------------------






Log Name:      Microsoft-Windows-WMI-Activity/Operational
Source:        Microsoft-Windows-WMI-Activity
Date:          8/7/2015 4:39:38 AM
Event ID:      5858
Task Category: None
Level:         Error
Keywords:      
User:          SYSTEM
Computer:      pudocontrol.domain-name.cloudapp.net
Description:
Id = {BCC1EB23-D052-0000-121C-C2BC52D0D001}; ClientMachine = PUDOCONTROL; User = NT AUTHORITY\SYSTEM;
ClientProcessId = 4316; Component = Unknown; Operation = Start IWbemServices::CreateInstanceEnum -
root\CCM : SMS_Authority; ResultCode = 0x80041010; PossibleCause = Unknown



----------


Log Name:      Application
Source:        Microsoft-Windows-WMI
Date:          8/7/2015 1:12:02 PM
Event ID:      10
Task Category: None
Level:         Error
Keywords:      
User:          SYSTEM
Computer:      pudocontrol.domain-name.cloudapp.net
Description:
Event filter with query "SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA "ccm_siteassignment""
could not be reactivated in namespace "//./root/ccm/Policy/Machine" because of error 0x80041010.
Events cannot be delivered through this filter until the problem is corrected.

------------


Log Name:      Application
Source:        Microsoft-Windows-WMI
Date:          8/10/2015 3:05:35 PM
Event ID:      63
Task Category: None
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      pudocontrol.pudocontrol.cloudapp.net
Description:
A provider, PolicyAgentInstanceProvider, has been registered in the Windows Management Instrumentation namespace
 root\CCM\Policy\Machine to use the LocalSystem account. This account is privileged and the provider may cause a
security violation if it does not correctly impersonate user requests.

Log Name:      Application
Source:        Microsoft-Windows-WMI
Date:          8/10/2015 6:10:13 PM
Event ID:      63
Task Category: None
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      pudocontrol.pudocontrol.cloudapp.net
Description:
A provider, SMSDPProvider, has been registered in the Windows Management Instrumentation namespace root\SCCMDP
 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if
it does not correctly impersonate user requests.
-------------------------------------------------------------------------------------------------------------------------

If somebody had a similar case, please, request me and I'll be very very grateful. I've been reading many posts about the errors I have, but the scenarios were different, so I think that the solutions weren't applicable to my case. Anyway, I've done many things explained on forums, without success.

Thank you in advance and Greetings from Spain.

Roberto

August 11th, 2015 7:28am

The only relevant part from the logs is
"MPCONTROL.LOG
Call to HttpSendRequestSync failed for port 443 with status code 404, text: Not Found
Http test request failed, status code is 404, 'Not Found'."

Are all certs in place? Where did you get the certs from?

Free Windows Admin Tool Kit Click here and download it now
August 11th, 2015 8:35am

Hi Torsten, Thanks for your reply...

Regarding the Certs, I think that they are fine.

I 've created and Issued 3 certs (for DP, for IIS, and for the client -all of them with private Key) with the configuration especified here:

https://technet.microsoft.com/en-us/library/gg699362.aspx

http://sccmguy.com/2013/11/26/pki-certificates-for-configuration-manager-2012-r2-part-1-of-4-web-server-certificate/ (doing the steps from part 1 to 4,  configuring the II'S bindings, ports 80 and 443 (this one with the IIS certificate created before), installing the roles MP, FSP ... Installing and configuring the DP role (HTTPS only, without SSL -I clicked firstly for SSL's using, but its didn't run-),  Importing its DP's Certificate, importing the client certificate to the client machine, etc..

Also, I've fixed the registry error 403 16
http://blogs.technet.com/b/configurationmgr/archive/2013/08/13/support-tip-a-configmgr-2012-management-point-enabled-for-ssl-fails-with-403-forbidden.aspx

then, I've installed the client

CCMSETUP.EXE /USEPKICERT /NOCRLCHECK /CCMHTTPSPORT=443 CCMHOSTNAME=domain.cloudapp.net CCMALWAYSINF=1 SMSMP=servername.domain.cloudapp.net SMSSITECODE=PD1 FSP=servername.domain.cloudapp.net DNSSUFFIX=domain.cloudapp.net CCMCERTSEL="SubjectStr:Work"

Then, the client gets the PKI successfully and I can see the client on SCCM, I can access to https://servername.cloudapp.net/sms_mp/.sms_aut?mpcert and mplist ....

... But the MP gets on "critical status" and I cannot admin any client...

Anyway, keeping in mind that I've the server located on azure, after of re-installations and re-configurations, I'm worried about this...

https://support.microsoft.com/en-us/kb/2889321

A moderator mate from the TN's spanish forum, told me yesterday that my scenario is not supported, 'cause I have the server with all the SCCM and Winserver2012 roles in the same machine, and the clients are workgroup's computers connected to internet via 3G....

Thanx a bunch and Best Regards,

Roberto

August 12th, 2015 3:46am

Hi Torsten, Thanks for your reply...

Regarding the Certs, I think that they are fine.

I 've created and Issued 3 certs (for DP, for IIS, and for the client -all of them with private Key) with the configuration especified here:

https://technet.microsoft.com/en-us/library/gg699362.aspx

http://sccmguy.com/2013/11/26/pki-certificates-for-configuration-manager-2012-r2-part-1-of-4-web-server-certificate/ (doing the steps from part 1 to 4,  configuring the II'S bindings, ports 80 and 443 (this one with the IIS certificate created before), installing the roles MP, FSP ... Installing and configuring the DP role (HTTPS only, without SSL -I clicked firstly for SSL's using, but its didn't run-),  Importing its DP's Certificate, importing the client certificate to the client machine, etc..

Also, I've fixed the registry error 403 16
http://blogs.technet.com/b/configurationmgr/archive/2013/08/13/support-tip-a-configmgr-2012-management-point-enabled-for-ssl-fails-with-403-forbidden.aspx

then, I've installed the client

CCMSETUP.EXE /USEPKICERT /NOCRLCHECK /CCMHTTPSPORT=443 CCMHOSTNAME=domain.cloudapp.net CCMALWAYSINF=1 SMSMP=servername.domain.cloudapp.net SMSSITECODE=PD1 FSP=servername.domain.cloudapp.net DNSSUFFIX=domain.cloudapp.net CCMCERTSEL="SubjectStr:Work"

Then, the client gets the PKI successfully and I can see the client on SCCM, I can access to https://servername.cloudapp.net/sms_mp/.sms_aut?mpcert and mplist ....

... But the MP gets on "critical status" and I cannot admin any client...

Anyway, keeping in mind that I've the server located on azure, after of re-installations and re-configurations, I'm worried about this...

https://support.microsoft.com/en-us/kb/2889321

A moderator mate from the TN's spanish forum, told me yesterday that my scenario is not supported, 'cause I have the server with all the SCCM and Winserver2012 roles in the same machine located on Azure, and the clients are workgroup's computers connected to internet via 3G....

Is it means that my scenario won't run fine, unless I change the SCCM server on Azure to an on-premises location???

Thanx a bunch and Best Regards,

Roberto



Free Windows Admin Tool Kit Click here and download it now
August 12th, 2015 7:45am

Hi Torsten, Thanks for your reply...

Regarding the Certs, I think that they are fine.

I 've created and Issued 3 certs (for DP, for IIS, and for the client -all of them with private Key) with the configuration especified here:

https://technet.microsoft.com/en-us/library/gg699362.aspx

http://sccmguy.com/2013/11/26/pki-certificates-for-configuration-manager-2012-r2-part-1-of-4-web-server-certificate/ (doing the steps from part 1 to 4,  configuring the II'S bindings, ports 80 and 443 (this one with the IIS certificate created before), installing the roles MP, FSP ... Installing and configuring the DP role (HTTPS only, without SSL -I clicked firstly for SSL's using, but its didn't run-),  Importing its DP's Certificate, importing the client certificate to the client machine, etc..

Also, I've fixed the registry error 403 16
http://blogs.technet.com/b/configurationmgr/archive/2013/08/13/support-tip-a-configmgr-2012-management-point-enabled-for-ssl-fails-with-403-forbidden.aspx

then, I've installed the client

CCMSETUP.EXE /USEPKICERT /NOCRLCHECK /CCMHTTPSPORT=443 CCMHOSTNAME=domain.cloudapp.net CCMALWAYSINF=1 SMSMP=servername.domain.cloudapp.net SMSSITECODE=PD1 FSP=servername.domain.cloudapp.net DNSSUFFIX=domain.cloudapp.net CCMCERTSEL="SubjectStr:Work"

Then, the client gets the PKI successfully and I can see the client on SCCM, I can access to https://servername.cloudapp.net/sms_mp/.sms_aut?mpcert and mplist ....

... But the MP gets on "critical status" and I cannot admin any client...

Anyway, keeping in mind that I've the server located on azure, after of re-installations and re-configurations, I'm worried about this...

https://support.microsoft.com/en-us/kb/2889321

A moderator mate from the TN's spanish forum, told me yesterday that my scenario is not supported, 'cause I have the server with all the SCCM and Winserver2012 roles in the same machine located on Azure, and the clients are workgroup's computers connected to internet via 3G....

Is it means that my scenario won't run fine, unless I change the SCCM server on Azure to an on-premises location???

Thanx a bunch and Best Regards,

Roberto



August 12th, 2015 7:45am

Hi,

Have you resolved this problem?

In ConfigMgr 2012 we do currently support managing azure virtual machines, but not on-premises clients.

 

For more information please refer to:
http://blogs.technet.com/b/breben/archive/2013/01/14/pros-and-cons-of-a-cloud-based-dp.aspx
http://blogs.technet.com/b/configmgrteam/archive/2013/10/23/configmgr-and-endpoint-protection-support-for-windows-azure-vms.aspx

Free Windows Admin Tool Kit Click here and download it now
August 19th, 2015 9:27pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics