Trouble installing SCCM 2012 R2 SP1 client on workgroup computers

Peter, thanks for your reply (and I just noticed I referenced your blog in my question...neat!)

Yes, I can resolve the FQDN of the management point.  I've checked several logs, but I'll admit I hadn't checked ClientIDManagerStartup.log (I'm still learning all of the various log files).  

Looking at that log it suggests I'm having a PKI issue: "Unable to find PKI Certificate matching SCCM certificate selection criteria. 0x87d00280".  A little further up in the log it says "There are no certificates in the "MY" store."  I'll go back through your blog and make certain I've created the template and certificate correctly.  In the meantime I've included a portion of the log below.

<![LOG[[----- STARTUP -----]]LOG]!><time="16:49:06.387+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmidstore.cpp:414">
<![LOG[Machine: TESTCOMPUTER]LOG]!><time="16:49:06.402+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmid.cpp:1408">
<![LOG[OS Version: 6.3]LOG]!><time="16:49:06.402+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmid.cpp:1412">
<![LOG[SCCM Client Version: 5.00.8239.1000]LOG]!><time="16:49:06.402+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmid.cpp:1416">
<![LOG[Client is set to use HTTPS when available. The current state is 448.]LOG]!><time="16:49:06.402+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmutillib.cpp:414">
<![LOG['RDV' Identity store does not support backup.]LOG]!><time="16:49:06.402+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmidstore.cpp:372">
<![LOG[CCM Identity is in sync with Identity stores]LOG]!><time="16:49:06.402+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmid.cpp:1455">
<![LOG[Begin searching client certificates based on Certificate Issuers]LOG]!><time="16:49:06.434+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmcert.cpp:4541">
<![LOG[Completed searching client certificates based on Certificate Issuers]LOG]!><time="16:49:06.434+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmcert.cpp:4700">
<![LOG[Begin to select client certificate]LOG]!><time="16:49:06.434+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmcert.cpp:4856">
<![LOG[There are no certificates in the 'MY' store.]LOG]!><time="16:49:06.434+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmcert.cpp:4914">
<![LOG[Raising event:

instance of CCM_ServiceHost_CertRetrieval_Status
{
	DateTime = "20150610214906.449000+000";
	HRESULT = "0x87d00280";
	ProcessID = 580;
	ThreadID = 816;
};
]LOG]!><time="16:49:06.449+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="event.cpp:715">
<![LOG[Failed to submit event to the Status Agent. Attempting to create pending event.]LOG]!><time="16:49:06.449+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="2" thread="816" file="event.cpp:737">
<![LOG[Raising pending event:

instance of CCM_ServiceHost_CertRetrieval_Status
{
	DateTime = "20150610214906.449000+000";
	HRESULT = "0x87d00280";
	ProcessID = 580;
	ThreadID = 816;
};
]LOG]!><time="16:49:06.449+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="event.cpp:770">
<![LOG[Unable to find PKI Certificate matching SCCM certificate selection criteria. 0x87d00280]LOG]!><time="16:49:06.449+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="2" thread="816" file="ccmgencert.cpp:3698">
<![LOG[Initializing registration renewal for potential PKI issued certificate changes.]LOG]!><time="16:49:07.298+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="regtask.cpp:485">
<![LOG[Succesfully intialized registration renewal.]LOG]!><time="16:49:07.298+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="regtask.cpp:527">
<![LOG[[RegTask] - Executing registration task synchronously.]LOG]!><time="16:49:07.298+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="regtask.cpp:891">
<![LOG[Read SMBIOS (encoded): 56004D0077006100720065002D00340032002000330065002000340065002000360064002000620065002000630030002000360063002000620065002D0065003300200063006300200064003800200036006200200039003700200039003800200031006500200066006500]LOG]!><time="16:49:07.298+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="smbiosident.cpp:118">
<![LOG[Evaluated SMBIOS (encoded): 56004D0077006100720065002D00340032002000330065002000340065002000360064002000620065002000630030002000360063002000620065002D0065003300200063006300200064003800200036006200200039003700200039003800200031006500200066006500]LOG]!><time="16:49:07.298+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="smbiosident.cpp:184">
<![LOG[No SMBIOS Changed]LOG]!><time="16:49:07.298+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="smbiosident.cpp:65">
<![LOG[SMBIOS unchanged]LOG]!><time="16:49:07.298+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="ccmid.cpp:671">
<![LOG[SID unchanged]LOG]!><time="16:49:07.298+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="ccmid.cpp:688">
<![LOG[HWID unchanged]LOG]!><time="16:49:08.334+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="ccmid.cpp:705">
<![LOG[RegTask: Failed to refresh site code. Error: 0x8000ffff]LOG]!><time="16:49:09.407+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="2" thread="2492" file="regtask.cpp:218">
<![LOG[Sleeping for 297 seconds before refreshing location services.]LOG]!><time="16:49:11.416+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="regtask.cpp:196">
<![LOG[RenewalTask: Executing renewal task.]LOG]!><time="16:50:44.990+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="regtask.cpp:2311">
<![LOG[Begin searching client certificates based on Certificate Issuers]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="ccmcert.cpp:4541">
<![LOG[Completed searching client certificates based on Certificate Issuers]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="ccmcert.cpp:4700">
<![LOG[Begin to select client certificate]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="ccmcert.cpp:4856">
<![LOG[Begin validation of Certificate [Thumbprint 785FC46BD5074C1989713D343F1EC7EDA9D13E4F] issued to 'TESTCOMPUTER']LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="ccmcert.cpp:1715">
<![LOG[Failed to get certificate key provider information. Error 0x80092004]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="3" thread="2288" file="ccmcert.cpp:1228">
<![LOG[Completed validation of Certificate [Thumbprint 785FC46BD5074C1989713D343F1EC7EDA9D13E4F] issued to 'TESTCOMPUTER']LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="ccmcert.cpp:1862">
<![LOG[>>> Client selected the PKI Certificate [Thumbprint 785FC46BD5074C1989713D343F1EC7EDA9D13E4F] issued to 'TESTCOMPUTER']LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="ccmcert.cpp:5000">
<![LOG[Raising event:

instance of CCM_ServiceHost_CertRetrieval_Status
{
	DateTime = "20150610215045.006000+000";
	HRESULT = "0x00000000";
	ProcessID = 580;
	ThreadID = 2288;
};
]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="event.cpp:715">
<![LOG[Client PKI cert is available.]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="ccmgencert.cpp:3704">
<![LOG[RenewalTask: Certificate has changed, initiating a renewal.]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="regtask.cpp:2334">
<![LOG[Aborting any pending registration.]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="regtask.cpp:2431">
<![LOG[Re-registration/renewal initiated. Restarting the service.]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="regtask.cpp:2437">
<![LOG[[----- SHUTDOWN -----]]LOG]!><time="16:50:45.147+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmidstore.cpp:512">



June 11th, 2015 10:03am

We have a small SCCM 2012 R2 SP 1 environment that we're evaluating to replace our existing desktop management solution.  Pushing clients to our domain-bound computers was a breeze, but I'm running into issues with workgroup-based computers.  Here's what I did...

I installed a client certificate on the test computer using instructions I found here.  I then copied the Client directory from the MP and ran CcmSetup using both the SMSSITECODE and SMSMP options.  CcmSetup exited with a 0 return code.  However, when I check Configuration Manager in the Control Panel, the General tab indicates there is no client certificate and the Site tab has a blank site code.

I've obviously missed something, but I'll be hanged if I can't figure out what.  Your thoughts are greatly appreciated.
Free Windows Admin Tool Kit Click here and download it now
June 11th, 2015 1:13pm

Can you resolve the FQDN of the management point? Also, please check the client logs for more information and start with the ClientIDManagerStartup.log.
June 11th, 2015 1:20pm

Peter, thanks for your reply (and I just noticed I referenced your blog in my question...neat!)

Yes, I can resolve the FQDN of the management point.  I've checked several logs, but I'll admit I hadn't checked ClientIDManagerStartup.log (I'm still learning all of the various log files).  

Looking at that log it suggests I'm having a PKI issue: "Unable to find PKI Certificate matching SCCM certificate selection criteria. 0x87d00280".  A little further up in the log it says "There are no certificates in the "MY" store."  I'll go back through your blog and make certain I've created the template and certificate correctly.  In the meantime I've included a portion of the log below.

<![LOG[[----- STARTUP -----]]LOG]!><time="16:49:06.387+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmidstore.cpp:414">
<![LOG[Machine: TESTCOMPUTER]LOG]!><time="16:49:06.402+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmid.cpp:1408">
<![LOG[OS Version: 6.3]LOG]!><time="16:49:06.402+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmid.cpp:1412">
<![LOG[SCCM Client Version: 5.00.8239.1000]LOG]!><time="16:49:06.402+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmid.cpp:1416">
<![LOG[Client is set to use HTTPS when available. The current state is 448.]LOG]!><time="16:49:06.402+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmutillib.cpp:414">
<![LOG['RDV' Identity store does not support backup.]LOG]!><time="16:49:06.402+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmidstore.cpp:372">
<![LOG[CCM Identity is in sync with Identity stores]LOG]!><time="16:49:06.402+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmid.cpp:1455">
<![LOG[Begin searching client certificates based on Certificate Issuers]LOG]!><time="16:49:06.434+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmcert.cpp:4541">
<![LOG[Completed searching client certificates based on Certificate Issuers]LOG]!><time="16:49:06.434+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmcert.cpp:4700">
<![LOG[Begin to select client certificate]LOG]!><time="16:49:06.434+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmcert.cpp:4856">
<![LOG[There are no certificates in the 'MY' store.]LOG]!><time="16:49:06.434+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmcert.cpp:4914">
<![LOG[Raising event:

instance of CCM_ServiceHost_CertRetrieval_Status
{
	DateTime = "20150610214906.449000+000";
	HRESULT = "0x87d00280";
	ProcessID = 580;
	ThreadID = 816;
};
]LOG]!><time="16:49:06.449+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="event.cpp:715">
<![LOG[Failed to submit event to the Status Agent. Attempting to create pending event.]LOG]!><time="16:49:06.449+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="2" thread="816" file="event.cpp:737">
<![LOG[Raising pending event:

instance of CCM_ServiceHost_CertRetrieval_Status
{
	DateTime = "20150610214906.449000+000";
	HRESULT = "0x87d00280";
	ProcessID = 580;
	ThreadID = 816;
};
]LOG]!><time="16:49:06.449+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="event.cpp:770">
<![LOG[Unable to find PKI Certificate matching SCCM certificate selection criteria. 0x87d00280]LOG]!><time="16:49:06.449+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="2" thread="816" file="ccmgencert.cpp:3698">
<![LOG[Initializing registration renewal for potential PKI issued certificate changes.]LOG]!><time="16:49:07.298+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="regtask.cpp:485">
<![LOG[Succesfully intialized registration renewal.]LOG]!><time="16:49:07.298+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="regtask.cpp:527">
<![LOG[[RegTask] - Executing registration task synchronously.]LOG]!><time="16:49:07.298+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="regtask.cpp:891">
<![LOG[Read SMBIOS (encoded): 56004D0077006100720065002D00340032002000330065002000340065002000360064002000620065002000630030002000360063002000620065002D0065003300200063006300200064003800200036006200200039003700200039003800200031006500200066006500]LOG]!><time="16:49:07.298+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="smbiosident.cpp:118">
<![LOG[Evaluated SMBIOS (encoded): 56004D0077006100720065002D00340032002000330065002000340065002000360064002000620065002000630030002000360063002000620065002D0065003300200063006300200064003800200036006200200039003700200039003800200031006500200066006500]LOG]!><time="16:49:07.298+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="smbiosident.cpp:184">
<![LOG[No SMBIOS Changed]LOG]!><time="16:49:07.298+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="smbiosident.cpp:65">
<![LOG[SMBIOS unchanged]LOG]!><time="16:49:07.298+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="ccmid.cpp:671">
<![LOG[SID unchanged]LOG]!><time="16:49:07.298+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="ccmid.cpp:688">
<![LOG[HWID unchanged]LOG]!><time="16:49:08.334+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="ccmid.cpp:705">
<![LOG[RegTask: Failed to refresh site code. Error: 0x8000ffff]LOG]!><time="16:49:09.407+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="2" thread="2492" file="regtask.cpp:218">
<![LOG[Sleeping for 297 seconds before refreshing location services.]LOG]!><time="16:49:11.416+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2492" file="regtask.cpp:196">
<![LOG[RenewalTask: Executing renewal task.]LOG]!><time="16:50:44.990+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="regtask.cpp:2311">
<![LOG[Begin searching client certificates based on Certificate Issuers]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="ccmcert.cpp:4541">
<![LOG[Completed searching client certificates based on Certificate Issuers]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="ccmcert.cpp:4700">
<![LOG[Begin to select client certificate]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="ccmcert.cpp:4856">
<![LOG[Begin validation of Certificate [Thumbprint 785FC46BD5074C1989713D343F1EC7EDA9D13E4F] issued to 'TESTCOMPUTER']LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="ccmcert.cpp:1715">
<![LOG[Failed to get certificate key provider information. Error 0x80092004]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="3" thread="2288" file="ccmcert.cpp:1228">
<![LOG[Completed validation of Certificate [Thumbprint 785FC46BD5074C1989713D343F1EC7EDA9D13E4F] issued to 'TESTCOMPUTER']LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="ccmcert.cpp:1862">
<![LOG[>>> Client selected the PKI Certificate [Thumbprint 785FC46BD5074C1989713D343F1EC7EDA9D13E4F] issued to 'TESTCOMPUTER']LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="ccmcert.cpp:5000">
<![LOG[Raising event:

instance of CCM_ServiceHost_CertRetrieval_Status
{
	DateTime = "20150610215045.006000+000";
	HRESULT = "0x00000000";
	ProcessID = 580;
	ThreadID = 2288;
};
]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="event.cpp:715">
<![LOG[Client PKI cert is available.]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="ccmgencert.cpp:3704">
<![LOG[RenewalTask: Certificate has changed, initiating a renewal.]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="regtask.cpp:2334">
<![LOG[Aborting any pending registration.]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="regtask.cpp:2431">
<![LOG[Re-registration/renewal initiated. Restarting the service.]LOG]!><time="16:50:45.006+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="2288" file="regtask.cpp:2437">
<![LOG[[----- SHUTDOWN -----]]LOG]!><time="16:50:45.147+300" date="06-10-2015" component="ClientIDManagerStartup" context="" type="1" thread="816" file="ccmidstore.cpp:512">



  • Edited by Bill Curnow Thursday, June 11, 2015 2:03 PM
Free Windows Admin Tool Kit Click here and download it now
June 11th, 2015 2:02pm

Two things I would check based on the error message:

  • Did you install the root certificate on the client?
  • Can the client access the certificate revocation list?
June 11th, 2015 2:14pm

What is your install string?
Free Windows Admin Tool Kit Click here and download it now
June 11th, 2015 3:27pm

Yes to both.  We installed the root CA on the client and we can access the CRL in a browser on the client.

I did find one thing that might be causing issues.  According to Microsoft, one of the prerequisites for installing the Client on a Workgroup computer is a Network Access Account.  We'd overlooked this step.  I've created the NAA and am working on giving it permissions to everything it might need.  I'll update this thread once I'm done and have had a chance to test installation again.

June 11th, 2015 3:51pm

...and shoot.  Creating and defining the NAA was not the magic bullet I was looking for.
Free Windows Admin Tool Kit Click here and download it now
June 11th, 2015 4:20pm

What is your install string?
ccmsetup.exe SMSSITECODE=S01 SMSMP=lbksvsccm.pcca.local /UsePKICert /NoCRLCheck


June 11th, 2015 4:23pm

I would add a couple of things to the install string: CCMALWAYSINF=1 (this will force the client to always look to the internet) and ccmhostname=<YourInternetMP.ManagementPoint.com>
Free Windows Admin Tool Kit Click here and download it now
June 11th, 2015 6:24pm

I would add a couple of things to the install string: CCMALWAYSINF=1 (this will force the client to always look to the internet) and ccmhostname=<YourInternetMP.ManagementPoint.com>

"CCMALWAYSINF"?  I wonder if that's what our problem is.  Right now, when I install the client I can see that its Connection Type is "internet", which has always struck me as odd as the computer is on our intranet.  I've skipped the "Planning for Internet-Based Client Management" article simply because we won't be managing any computers that aren't on our network.  Am I to understand that the only way to manage intranet-based, workgroup-bound computers is via the public internet?

*edit*

I went ahead and created another server and designated it as an "internet-only" MP and modified my installation script to point to that server (using the CCMALWAYSINF and CCMHOSTNAME command-line options that had been suggested.  I figured I had nothing to lose.  Unfortunately, this resulted in the same results.

I can't help but keep coming back to this "intranet" vs "Internet" issue.  In my mind this is a clear intranet layout, but I'm still getting used to ConfigMan's eccentricities. 

Still reading and testing...

June 12th, 2015 3:31pm

I'm an idiot.  Short answer, it's working now.  Longer answer: I'm not sure exactly when it started working.

I'm using a VM to test and, somewhere along the way yesterday afternoon, I managed to remove the SSL certificate from the image but kept "PKI Cert installed" in the description of the snapshot.  I've been testing all day thinking I had an SSL certificate installed on the test VM.

I suspect jorlando82 nudged me in the right direction (intranet VS Internet).  

  • Marked as answer by Bill Curnow 4 hours 13 minutes ago
Free Windows Admin Tool Kit Click here and download it now
June 12th, 2015 6:10pm

I would add a couple of things to the install string: CCMALWAYSINF=1 (this will force the client to always look to the internet) and ccmhostname=<YourInternetMP.ManagementPoint.com>

"CCMALWAYSINF"?  I wonder if that's what our problem is.  Right now, when I install the client I can see that its Connection Type is "internet", which has always struck me as odd as the computer is on our intranet.  I've skipped the "Planning for Internet-Based Client Management" article simply because we won't be managing any computers that aren't on our network.  Am I to understand that the only way to manage intranet-based, workgroup-bound computers is via the public internet?

*edit*

I went ahead and created another server and designated it as an "internet-only" MP and modified my installation script to point to that server (using the CCMALWAYSINF and CCMHOSTNAME command-line options that had been suggested.  I figured I had nothing to lose.  Unfortunately, this resulted in the same results.

I can't help but keep coming back to this "intranet" vs "Internet" issue.  In my mind this is a clear intranet layout, but I'm still getting used to ConfigMan's eccentricities. 

Still reading and testing...

June 12th, 2015 7:30pm

I'm an idiot.  Short answer, it's working now.  Longer answer: I'm not sure exactly when it started working.

I'm using a VM to test and, somewhere along the way yesterday afternoon, I managed to remove the SSL certificate from the image but kept "PKI Cert installed" in the description of the snapshot.  I've been testing all day thinking I had an SSL certificate installed on the test VM.

I suspect jorlando82 nudged me in the right direction (intranet VS Internet).  

  • Marked as answer by Bill Curnow Saturday, June 13, 2015 3:33 AM
Free Windows Admin Tool Kit Click here and download it now
June 12th, 2015 10:09pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics