Task Sequence does not start
Hi
I get the following error when trying to capture an image
ulHashSize == ulHashedSize, HRESULT=80004005 (e:\nts_sms_fre\sms\framework\osdmessaging\libcrypt.cpp,444) TSPxe 2011/05/09 07:11:56 AM 1292 (0x050C)
VerifyHashedBuffer ((BYTE*) pServerReply, nReplySize, pDecodedSignature, nSize, dwAlgID), HRESULT=80004005 (e:\nts_sms_fre\sms\framework\osdmessaging\libsmsmessaging.cpp,4436) TSPxe 2011/05/09 07:11:56 AM 1292 (0x050C)
failed to verify the policy hash TSPxe 2011/05/09 07:11:56 AM 1292 (0x050C)
oPolicy.RequestPolicy((GetPolicyFlags() & POLICY_SECURE) != 0), HRESULT=80004005 (e:\nts_sms_fre\sms\framework\tscore\tspolicy.cpp,1841) TSPxe 2011/05/09 07:11:56 AM 1292 (0x050C)
Failed to download policy {cbd54ad0-cb84-442a-880b-9e51628b8581} (Code 0x80004005). TSPxe 2011/05/09 07:11:56 AM 1292 (0x050C)
DownloadPolicyBody(), HRESULT=80004005 (e:\nts_sms_fre\sms\framework\tscore\tspolicy.cpp,1927) TSPxe 2011/05/09 07:11:56 AM 1292 (0x050C)
m_pPolicyManager->GetPolicyXML(L"NAP", sPolicyXML ), HRESULT=80004005 (e:\nts_sms_fre\sms\client\tasksequence\tsmbootstrap\tsmediawizardcontrol.cpp,1631) TSPxe 2011/05/09 07:11:56 AM 1292 (0x050C)
May 9th, 2011 9:26am
80004005 is an access denied error. Verify that the machine has access to the share where the image will be stored.
Edit: I see now that it appears this error occurs ealier than the capture phase. Please tell us the details of your configuration.
Free Windows Admin Tool Kit Click here and download it now
May 9th, 2011 9:55am
Hi Eirik
What specific details should i post?
We are in native mode
Have setup all the certs as per microsoft instructions.
May 10th, 2011 2:45am
Did you enter the correct username and password?
Free Windows Admin Tool Kit Click here and download it now
May 10th, 2011 3:53am
Do other task sequences work? And if so, do you use the same boot image for those?
May 10th, 2011 4:11am
This is the first time we are using OSD so this is the only task sequence
Free Windows Admin Tool Kit Click here and download it now
May 10th, 2011 4:35am
Here's a good post for the "Failed to download policy" error message.
ConfigMgr 2007: OSD Task Sequence Fails with the error "An error occurred while retrieving policy for this computer (0x80004005)"
http://blogs.technet.com/b/smsandmom/archive/2008/10/23/configmgr-2007-osd-task-sequence-fails-with-the-error-an-error-occurred-while-retrieving-policy-for-this-computer-0x80004005.aspx
and: SCCM OSD Error: Failed To Download Policy (Code 0x80004005)
http://www.dreamension.net/index.php?option=com_content&view=article&id=86%3Asccm-osd-error-failed-to-download-policy-code-0x80004005&catid=1%3Alatest&Itemid=9
My ConfigMgr blog: http://henkhoogendoorn.blogspot.com Follow me on Twitter: @henkhoogendoorn
May 10th, 2011 6:05pm
Hi Henk
Thanks for the reply, i have though gone through those 2 articles before and everything on my side looks 100%
Is there a way to check which cert is applicable for the PXE point, the reason i ask is that i also used the self signing option before and all of those certs are still visable. I have now created a proper cert but maybe it is still using one of the self
signed certs. Hope this make sense.
Is there a way to see what the policy "Failed to download policy {cbd54ad0-cb84-442a-880b-9e51628b8581} (Code 0x80004005)" actually does because this is the policy it says "failed to verify the policy hash"
I tried to see in the database what it does and only came up with 'compliance'
Free Windows Admin Tool Kit Click here and download it now
May 11th, 2011 2:52am
Have you used the following guides for setting up native mode functionality?
Certificate Requirements for Native Mode
http://technet.microsoft.com/en-us/library/bb680733.aspx
Step-By-Step Example Deployment of the PKI Certificates Required for Configuration Manager Native Mode: Windows Server 2003 Certification Authority
http://technet.microsoft.com/en-us/library/bb694035.aspx
Step-by-Step Example Deployment of the PKI Certificates Required for Configuration Manager Native Mode: Windows Server 2008 Certification Authority
http://technet.microsoft.com/en-us/library/cc872789.aspx
In Certificates / PXE have a look if certificates are blocked/unblocked there (with the option to block and unblock certificates yourself)
In properties of the PXE service point / Database have a look at Import certificate.
When using native mode the management point will no longer accept OSD client connections that use a self-signed certificate.
My ConfigMgr blog: http://henkhoogendoorn.blogspot.com Follow me on Twitter: @henkhoogendoorn
May 11th, 2011 4:14am
Yes we used all those guides when we went to native mode and have been running in native mode for past 7 months.
I have been successfull with OSD on our test domain which has basically the same setup(also in native mode)
I did import the proper cert in properties of the PXE service point / Database
Free Windows Admin Tool Kit Click here and download it now
May 11th, 2011 4:51am
When looking at the error message "Failed to download policy {cbd54ad0-cb84-442a-880b-9e51628b8581} (Code 0x80004005)" have a look at this one.
OSD TS: Failed to download policy - TS does not start in WinPE http://social.technet.microsoft.com/Forums/en/configmgrosd/thread/3b88f926-8565-4e71-9fcb-551490c08745
It was my user id's lack of access rights within SCCM that caused the error. The PXE SP installed OK without any warnings and the pxesetup.log file did not report anything wrong. However the real problem was that the certificate never reached "Site Management
- Site Name - Site settings - Certificates - PXE. You could see that the certificate was in place on the PXE SP role itself, but since I had uninstalled the PXE SP and installed it over again, I missed the exact date expiry date time. It looked very much to
be the same, but it was some hours off and the old one had not been blocked, so due to this together with to little attention to a minor detail it pretty much had me pretty far off the where the solution was.
Can you confirm that the PXE certificate is available in Certificates / PXE without a block and with the right date/time?
Have a look at Certificates / PXE also to check if "cbd54ad0-cb84-442a-880b-9e51628b8581" is the right one.My ConfigMgr blog: http://henkhoogendoorn.blogspot.com Follow me on Twitter: @henkhoogendoorn
May 11th, 2011 5:46am
The certificate is unblocked and the cert guid is 5db1f922-b11f-40fa-bd9f-e20fd94e3d30 which in the logs looks like it is working 100%
Is there not a way to see what policy "cbd54ad0-cb84-442a-880b-9e51628b8581" does or is supposed to do as this is the one it is reporting an error on
Free Windows Admin Tool Kit Click here and download it now
May 12th, 2011 4:44am
Check the certificates under the Site Settings node to if any certificates are blocked or missing. Open the certificates to ensure that the certificates are installed into the certificate store. If not, install the certificates.
Try the steps in this post for that: SCCM OSD/PXE Issues in Native Mode
http://idamd.blogspot.com/2010/05/sccm-osdpxe-issues-in-native-mode.html
My ConfigMgr blog: http://henkhoogendoorn.blogspot.com Follow me on Twitter: @henkhoogendoorn
May 18th, 2011 5:54pm


