<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Intel Communities: Message List</title>
    <link>http://communities.intel.com/index.jspa?view=discussions</link>
    <description>Most recent forum messages</description>
    <language>en</language>
    <pubDate>Mon, 25 Jun 2012 14:38:01 GMT</pubDate>
    <generator>Jive SBS 5.0.2.0  (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2012-06-25T14:38:01Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Common Name on VeriSign Certificate</title>
      <link>http://communities.intel.com/message/159896?tstart=0#159896</link>
      <description>&lt;!-- [DocumentBodyStart:c3b9bb0a-889f-471e-a53e-ae68dc83a7a9] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;Hi,&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I'm in the process of purchasing an AMT provisioning certificate from VeriSign and when generating the CSR on the SCCM server which the OOB Management point is installed on, one of the field require that you enter the Common Name for the certificte. Reviewing a number of articles the common name should consist of the hostname + domain name (FQDN) which is the internal FQDN of the server.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;However, when requesting a certifcate from VeriSign I'm not able to do so and VeriSign informend me that they do not provide certificates for internal domains anymore. The only solutions they've provided me with are:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;1. use the hostname + public domain name for the common name and add the internal IP address of the server as a Subject Alternative Name&lt;/p&gt;&lt;p&gt;2. use the hostname + public domain name for the common name, however this will required that the public DNS zone is configured on your internal DNS servers and a host record created for this server.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Has anyone come across this problem and do anyone have any suggestions please. Also, unfortunately I can only use VeriSign and none of the other providers.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Any suggestions will be greatly appreciated.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Many thanks&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Pierre&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:c3b9bb0a-889f-471e-a53e-ae68dc83a7a9] --&gt;</description>
      <pubDate>Mon, 25 Jun 2012 14:38:01 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/159896?tstart=0#159896</guid>
      <dc:date>2012-06-25T14:38:01Z</dc:date>
      <clearspace:dateToText>11 months, 15 hours ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
    </item>
    <item>
      <title>Re: Not able to connect over SOL using a Digest Master Password</title>
      <link>http://communities.intel.com/message/156115?tstart=0#156115</link>
      <description>&lt;!-- [DocumentBodyStart:619fd013-9689-4b3b-812f-07fd2e1c5996] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;Hi all, I'm pleased to report that this issue has been resolved in Intel AMT SDK 8.0, where you can now pass the default admin user name and calculated Digest Master Password credentials through to establish a Serial Over LAN session.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;On a personal note, I'm also pleased to report that the Intel team do take issues we come accross serious and are actively improving Intel vPro and associated tool sets. As with this problem I was facing, it was esculated to the Engineering/Developers team and within a few days they resolved the issue and released a new version of the SDK.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;So, thank you to the team at Intel!!&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Best Regards,&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Pierre&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:619fd013-9689-4b3b-812f-07fd2e1c5996] --&gt;</description>
      <pubDate>Wed, 09 May 2012 10:01:35 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/156115?tstart=0#156115</guid>
      <dc:date>2012-05-09T10:01:35Z</dc:date>
      <clearspace:dateToText>1 year, 1 week ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
    </item>
    <item>
      <title>Automatically Create a Digest User and Password in AMT</title>
      <link>http://communities.intel.com/message/155011?tstart=0#155011</link>
      <description>&lt;!-- [DocumentBodyStart:65a40a9d-bd0c-4b27-b016-6005e207919b] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;Hi, I&amp;#8217;m trying to create a PowerShell script to automatically create a digest user account and password in AMT and be able to add the account even if the workstation is powered down.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I&amp;#8217;ve been testing the &lt;strong style="mso-bidi-font-weight: normal;"&gt;New-Item AMT:\Config\ACL\Digest\&amp;rdquo;Username&amp;rdquo;&lt;/strong&gt; option as described in the following URL: &lt;a class="" href="http://communities.intel.com/community/openportit/vproexpert/microsoft-vpro/blog/2011/03/30/powershell-module-for-intel-vpro-technology-version-30-amtsystem-powershell-drive-provider"&gt;http://communities.intel.com/community/openportit/vproexpert/microsoft-vpro/blog/2011/03/30/powershell-module-for-intel-vpro-technology-version-30-amtsystem-powershell-drive-provider&lt;/a&gt; - however, I get prompted to manually enter a password which I&amp;#8217;m need to avoid.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The objective of what I&amp;#8217;m trying to achieve is the following:&lt;/p&gt;&lt;p&gt;1. The workstation is vPro enabled using SCS and the default digest admin account and the password is set using the Digest Master Password feature in the SCS. (I cannot use TLS/Kerberos and cannot set a digest account in the profile either).&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;2. PROBLEM: As you cannot establish a SOL session using the default admin account and DMP (as the DMP is 44 characters in lengths and currently SOL only accepts a maximum password length of 32 character), I want to write a script in PowerShell to connect to the vPro enabled workstation and create a digest account and password automatically. &amp;#8211; For additional information on this please refer to: &lt;a class="" href="http://communities.intel.com/message/152489#152489"&gt;http://communities.intel.com/message/152489&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;3. I&amp;#8217;ll then Invoke-AMTForceBoot to establish a SOL session, and once complete, automatically delete the account again.&lt;/p&gt;&lt;p&gt;Below is a copy of the script I&amp;#8217;m working on and it works fine when I manually enter the password for the created digest user when prompted (Currently in the script I&amp;#8217;m prompting for the hostname and default admin account and DMP, however I&amp;#8217;ll be passing these through from the extended script automatically)&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="LINE-HEIGHT: normal; MARGIN-BOTTOM: 0pt; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;# Begin flow template&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="LINE-HEIGHT: normal; MARGIN-BOTTOM: 0pt; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;Import-Module 'IntelvPro'&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="LINE-HEIGHT: normal; MARGIN-BOTTOM: 0pt; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;$hostname = read-Host ("Workstation Name")&lt;/p&gt;&lt;p style="LINE-HEIGHT: normal; MARGIN-BOTTOM: 0pt; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;p style="LINE-HEIGHT: normal; MARGIN-BOTTOM: 0pt; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;$Cred_DMP = Get-Credential #DMP Credentials&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="LINE-HEIGHT: normal; MARGIN-BOTTOM: 0pt; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;# Add Digest User Account for SOL connection&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="LINE-HEIGHT: normal; MARGIN-BOTTOM: 0pt; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;New-PSDrive -Name AMT -PSProvider amtsystem -Root "/" -ComputerName $hostname -Credential $Cred_DMP&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="LINE-HEIGHT: normal; MARGIN-BOTTOM: 0pt; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;New-Item AMT:\Config\ACL\Digest\TestUser #Digest Username is hard coded&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="LINE-HEIGHT: normal; MARGIN-BOTTOM: 0pt; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;&lt;em style="mso-bidi-font-style: normal;"&gt;At this section part I get prompted to enter a password for the digest user account &amp;lsquo;TestUser&amp;#8217; &lt;/em&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="LINE-HEIGHT: normal; MARGIN-BOTTOM: 0pt; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;Set-ItemProperty AMT:\Config\ACL\Digest\TestUser -Name Privileges -Value RC,REDIR,EVTLOG&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="LINE-HEIGHT: normal; MARGIN-BOTTOM: 0pt; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;# Connect to workstation with SOL&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="LINE-HEIGHT: normal; MARGIN-BOTTOM: 0pt; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;Invoke-AMTForceBoot -ComputerName $hostname -Port 16992 -Operation reset -Device BIOSSetup -Console SOL -SOLTerminalPath "telnet" -SOLTerminalArgList "-t ANSI 127.0.0.1 %Port" -Username TestUser -Password P@ssw0rd&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="LINE-HEIGHT: normal; MARGIN-BOTTOM: 0pt; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;&lt;em style="mso-bidi-font-style: normal;"&gt;Currently the username and password is both hard coded, but aiming to be able to pass this through as &amp;#8211;Credential $SOL_CRED&lt;/em&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="LINE-HEIGHT: normal; MARGIN-BOTTOM: 0pt; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;# Remove Digest User Account for SOL&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="LINE-HEIGHT: normal; MARGIN-BOTTOM: 0pt; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;Start-Sleep -Seconds 40&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="LINE-HEIGHT: normal; MARGIN-BOTTOM: 0pt; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;Remove-Item AMT:\Config\ACL\Digest\TestUser&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="LINE-HEIGHT: normal; MARGIN-BOTTOM: 0pt; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;Remove-Module 'IntelvPro'&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;# End flow template&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;As mentioned before, when I run the script and manually enter the password for the created digest user &amp;lsquo;TestUser&amp;#8217; the script works as it should.&lt;/p&gt;&lt;p&gt;It would be create if I could get a script to create the necessary digest account and password automatically.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Regards,&lt;/p&gt;&lt;p&gt;Pierre&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:65a40a9d-bd0c-4b27-b016-6005e207919b] --&gt;</description>
      <pubDate>Fri, 27 Apr 2012 14:53:58 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/155011?tstart=0#155011</guid>
      <dc:date>2012-04-27T14:53:58Z</dc:date>
      <clearspace:dateToText>1 year, 3 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <clearspace:objectType>0</clearspace:objectType>
    </item>
    <item>
      <title>Not able to connect over SOL using a Digest Master Password</title>
      <link>http://communities.intel.com/message/152489?tstart=0#152489</link>
      <description>&lt;!-- [DocumentBodyStart:76c80131-6c54-4086-ac1b-aac8f11a8368] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;A bit a background to my problem:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Due to a number of reasons I can only use the SCS service and digest authentication and cannot use AD Integration or PKI and TLS for security to provision and access the workstation. Also, the workstations are pre-configured at the factory with a PSK for zero touch provisioning.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Due to these restrictions and security requirements we can only use the default digest user account, &lt;strong&gt;admin&lt;/strong&gt; and no additional manually created digest accounts in the SCS profile. To satisfy security requirements further, we need to set the admin account password using the Digest Master Password (DMP)setting within SCS.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I can successfully connect to a workstation via WebUI and VNC Viewer Plus using the default account, admin and the calculated DMP. Also, I can successfully connect to the workstation using the Manageability Commander Tool using these credentials. However, when I go to the Remote Control Tab and select Take Control to connect to the workstation via SOL I get the following error: Serial-over-LAN error: IMR_RES_INVALID_PARAMETER - when I select OK the Manageability Terminal Tool window launch and the status of Serial-over-LAN is Disconnected.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Doing research I found the following extract in the Intel AMT Implementation and Reference Guide in the TCP Parameters, Redirection Sample Console GUI section:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;em style="mso-bidi-font-style: normal;"&gt;The lengths of the user name and user password are limited by the Redirection SDK to 32 characters. If either the user name or password exceeds this limit, IMR_RES_INVALID_PARAMETER, will be returned.&lt;/em&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The length of the digest master password is 44 characters&amp;hellip;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I then tested SOL with the default admin account and a password I set manually which is less than 32 characters and SOL connects successfully.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Therefore, I have the following questions and am hoping that someone is able to answer my questions:&lt;/p&gt;&lt;ol start="1"&gt;&lt;li&gt;How to get SOL working with the default admin account using a Digest Master Password or is this not possible?&lt;br/&gt;&lt;/li&gt;&lt;li&gt;Is there a way to truncate the DMP to conform to the maximum password length requirements?&lt;br/&gt;&lt;/li&gt;&lt;li&gt;Is there an alternative tool or utility to connect via SOL using the digest account, admin and DMP password?&lt;br/&gt;&lt;/li&gt;&lt;li&gt;Am I able to increase the length of the password in the Redirection SDK?&lt;br/&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Many thanks&lt;/p&gt;&lt;p&gt;Pierre&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:76c80131-6c54-4086-ac1b-aac8f11a8368] --&gt;</description>
      <pubDate>Wed, 28 Mar 2012 15:24:36 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/152489?tstart=0#152489</guid>
      <dc:date>2012-03-28T15:24:36Z</dc:date>
      <clearspace:dateToText>1 year, 1 month ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <clearspace:objectType>0</clearspace:objectType>
    </item>
    <item>
      <title>Re: RCS-Backup.ps1 issue</title>
      <link>http://communities.intel.com/message/151611?tstart=0#151611</link>
      <description>&lt;!-- [DocumentBodyStart:daaf97c2-72a1-4d79-a913-79704e395617] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;Hi Josh, I found some part of the solution to the problem.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;If you register the RCS Service under a local or domain user account during installation and run the backup script under this account the backup is successfull. However if you register the RCS Service under the Network Service system account (most secure) you cannot do a backup.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I've trawled through the Intel Setup and configuration Service - User Guide a few times and I found the following:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;On page 27 the guide tells you that you can run the RCS using a built-in Security account, extract below:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Note:&lt;br/&gt;&amp;#8226; You can also run the RCS using a built-in security account. To do this, enter &amp;#8220;Network Service&amp;rdquo; in the Username field or click Browse to select it. If you want to use this account, see &amp;#8220;Using the Network Service Account&amp;rdquo; on page 30.&lt;br/&gt;&amp;#8226; The user you select to run the RCS must have a password (unless it is the Network Service user account).&lt;/em&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;On page 30 it informs you that using this account is the most secure option, extract below:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;em&gt;The Windows operating system includes a built-in security account named &amp;#8220;Network Security&amp;rdquo;. During installation of the RCS you can select this account to run the RCS. When the RCS runs under this account, the RCS communicates on the network using the credentials of the computer running the RCS. This can increase security because it is not easy to impersonate a computer.&lt;/em&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;To do a succesfull backup using the Network Service account it states on page 31 you need to create a task in Task Scheduler that runs under the Network Service account, extract below:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Backup User Verification&lt;br/&gt;Make sure that you run the backup using the Network Service account. To do this, you can create a task in Task Scheduler that runs under the Network Service account. If you use the RCS-Backup.ps1 Powershell cmdlet, make sure that you use the -SkipUserVerification parameter.&lt;/em&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;However, to be able to schedule a task with task scheduler to run under the "NT AUTHORITY\NETWORKSERVICE" account you require Task Scheduler 2.0. see URL: &lt;a class="jive-link-external-small" href="http://msdn.microsoft.com/en-us/library/windows/desktop/bb736357(v=vs.85).aspx" target="_blank"&gt;http://msdn.microsoft.com/en-us/library/windows/desktop/bb736357(v=vs.85).aspx&lt;/a&gt; - extract&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;dl&gt;&lt;dt&gt;&lt;em&gt;&lt;strong&gt;/RU&lt;/strong&gt; &lt;strong&gt;username&lt;/strong&gt;&lt;/em&gt;&lt;/dt&gt;&lt;dd&gt;&lt;/dd&gt;&lt;/dl&gt;&lt;p&gt;&lt;em&gt;A value that specifies the user context under which the task runs. For the system account, valid values are "", "NT AUTHORITY\SYSTEM", or "SYSTEM". For Task Scheduler 2.0 tasks, "NT AUTHORITY\LOCALSERVICE", and "NT AUTHORITY\NETWORKSERVICE" are also valid values.&lt;/em&gt;&lt;/p&gt;&lt;dl&gt;&lt;/dl&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Task Scheduler 2.0 is only available on Windows 2008 and Windows Vista, see URL: &lt;a class="jive-link-external-small" href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa383614(v=vs.85).aspx" target="_blank"&gt;http://msdn.microsoft.com/en-us/library/windows/desktop/aa383614(v=vs.85).aspx&lt;/a&gt; - extract&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;em&gt;The Task Scheduler requires the following operating systems.&lt;/em&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Task Scheduler 1.0: Client requires Windows Vista, Windows XP, Windows 2000 Professional, Windows Me, or Windows 98. Server requires Windows Server 2008, Windows Server 2003 or Windows 2000 Server.&lt;/em&gt;&lt;br/&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;Task Scheduler 2.0: Client requires Windows Vista. Server requires Windows Server 2008.&lt;/em&gt;&lt;br/&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;In my environment I've installed RCS on a Windows 2003 server, therefore I'm not able to run the backup under the NT Authority\NetworkService account due to the version of Task Scheduler.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Regards,&lt;/p&gt;&lt;p&gt;Pierre&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:daaf97c2-72a1-4d79-a913-79704e395617] --&gt;</description>
      <pubDate>Wed, 14 Mar 2012 09:38:47 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/151611?tstart=0#151611</guid>
      <dc:date>2012-03-14T09:38:47Z</dc:date>
      <clearspace:dateToText>1 year, 2 months ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
      <clearspace:objectType>0</clearspace:objectType>
    </item>
    <item>
      <title>Re: RCS-Backup.ps1 issue</title>
      <link>http://communities.intel.com/message/151415?tstart=0#151415</link>
      <description>&lt;!-- [DocumentBodyStart:ace8e6e6-2d19-451f-97f9-22405e3ba407] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;span&gt;&lt;p class="s2"&gt;&lt;span class="s2"&gt;Hi, further to this, I've created an empty scsadmin.dat file in the directory, now I'm getting a different error:&lt;/span&gt;&lt;/p&gt;&lt;p class="s2" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s2"&gt;PS D:\SOURCE\vPro\vpro &lt;/span&gt;&lt;span class="s2"&gt;powershell&lt;/span&gt;&lt;span class="s2"&gt;&amp;gt; .\RCS-Backup.ps1 -&lt;/span&gt;&lt;span class="s2"&gt;SkipUserVerification&lt;/span&gt;&lt;span class="s2"&gt; $True&lt;/span&gt;&lt;a name="_GoBack"&gt;&lt;/a&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s4"&gt;DEBUG: RCS-Backup: backup with "D:\SOURCE\vPro\vpro&lt;/span&gt;&lt;span class="s4"&gt;powershell&lt;/span&gt;&lt;span class="s4"&gt;\Backup\&lt;/span&gt;&lt;span class="s4"&gt;prof.bak&lt;/span&gt;&lt;span class="s4"&gt;", "D:\SOURCE\vPr&lt;/span&gt;&lt;span class="s4"&gt;o\vpro&lt;/span&gt;&lt;span class="s4"&gt;powershell&lt;/span&gt;&lt;span class="s4"&gt;\Backup\&lt;/span&gt;&lt;span class="s4"&gt;psk.ba&lt;/span&gt;&lt;span class="s4"&gt;k&lt;/span&gt;&lt;span class="s4"&gt;" [ ]&lt;/span&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s4"&gt;DEBUG: &lt;/span&gt;&lt;span class="s4"&gt;RCSServer's&lt;/span&gt;&lt;span class="s4"&gt; status is &lt;/span&gt;&lt;span class="s4"&gt;Running&lt;/span&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s4"&gt;DEBUG: &lt;/span&gt;&lt;span class="s4"&gt;RCSServer's&lt;/span&gt;&lt;span class="s4"&gt; status is &lt;/span&gt;&lt;span class="s4"&gt;Running&lt;/span&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s4"&gt;DEBUG: Stopping &lt;/span&gt;&lt;span class="s4"&gt;RCSServer&lt;/span&gt;&lt;span class="s4"&gt; .&lt;/span&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s4"&gt;DEBUG: Waiting for &lt;/span&gt;&lt;span class="s4"&gt;RCSServer&lt;/span&gt;&lt;span class="s4"&gt; to be &lt;/span&gt;&lt;span class="s4"&gt;Stopped&lt;/span&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s4"&gt;DEBUG: &lt;/span&gt;&lt;span class="s4"&gt;RCSServer's&lt;/span&gt;&lt;span class="s4"&gt; status is &lt;/span&gt;&lt;span class="s4"&gt;Stopped&lt;/span&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s4"&gt;DEBUG:&lt;/span&gt;&lt;span class="s4"&gt; &lt;/span&gt;&lt;span class="s4"&gt;RCSServer's&lt;/span&gt;&lt;span class="s4"&gt; start mode is Auto&lt;/span&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s4"&gt;DEBUG: &lt;/span&gt;&lt;span class="s4"&gt;RCSServer&lt;/span&gt;&lt;span class="s4"&gt; Disabled&lt;/span&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s4"&gt;DEBUG: &lt;/span&gt;&lt;span class="s4"&gt;DpDecrypt&lt;/span&gt;&lt;span class="s4"&gt;-File: C:\Documents and Settings\All Users\Application Data\&lt;/span&gt;&lt;span class="s4"&gt;Intel_Corporation&lt;/span&gt;&lt;span class="s4"&gt;\&lt;/span&gt;&lt;span class="s4"&gt;RCSConfServer&lt;/span&gt;&lt;span class="s4"&gt;\Profile.xml start&lt;/span&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s5"&gt;ConvertTo-&lt;/span&gt;&lt;span class="s5"&gt;SecureString&lt;/span&gt;&lt;span class="s5"&gt; :&lt;/span&gt;&lt;span class="s5"&gt; Key not valid for use in specified state.&lt;/span&gt;&lt;/p&gt;&lt;p class="s3" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;span&gt; &lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s5"&gt; &lt;/span&gt;&lt;span class="s5"&gt;At D:\SOURCE\vPro\vpro &lt;/span&gt;&lt;span class="s5"&gt;powershell&lt;/span&gt;&lt;span class="s5"&gt;\RCS-Backup.ps1:361 char&lt;/span&gt;&lt;span class="s5"&gt;:32&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s5"&gt;+&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; $&lt;/span&gt;&lt;span class="s5"&gt;sstr&lt;/span&gt;&lt;span class="s5"&gt; = &lt;/span&gt;&lt;span class="s5"&gt;ConvertTo-SecureString&lt;/span&gt;&lt;span class="s5"&gt; &amp;lt;&amp;lt;&amp;lt;&lt;/span&gt;&lt;span class="s5"&gt;&amp;lt;&amp;nbsp; (&lt;/span&gt;&lt;span class="s5"&gt;[&lt;/span&gt;&lt;span class="s5"&gt;BitConverter&lt;/span&gt;&lt;span class="s5"&gt;]::&lt;/span&gt;&lt;span class="s5"&gt;ToString&lt;/span&gt;&lt;span class="s5"&gt;($&lt;/span&gt;&lt;span class="s5"&gt;ba&lt;/span&gt;&lt;span class="s5"&gt;) -replace ('-',''))&lt;/span&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s5"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span class="s5"&gt; &lt;/span&gt;&lt;span class="s5"&gt;+ &lt;/span&gt;&lt;span class="s5"&gt;CategoryInfo&lt;/span&gt;&lt;span class="s5"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : &lt;/span&gt;&lt;span class="s5"&gt;InvalidArgument&lt;/span&gt;&lt;span class="s5"&gt;: (:) [&lt;/span&gt;&lt;span class="s5"&gt;ConvertTo-Secure&lt;/span&gt;&lt;span class="s5"&gt;String&lt;/span&gt;&lt;span class="s5"&gt;], &lt;/span&gt;&lt;span class="s5"&gt;CryptographicException&lt;/span&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s5"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span class="s5"&gt; + &lt;/span&gt;&lt;span class="s5"&gt;FullyQualifiedErrorId&lt;/span&gt;&lt;span class="s5"&gt; :&lt;/span&gt;&lt;span class="s5"&gt;ImportSecureString_InvalidArgument_CryptographicError,Microsoft&lt;/span&gt;&lt;span class="s5"&gt;.PowerShell.Commands.ConvertToS&lt;/span&gt;&lt;span class="s5"&gt;ecureStringCommand&lt;/span&gt;&lt;/p&gt;&lt;p class="s3" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;span&gt; &lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s4"&gt; &lt;/span&gt;&lt;span class="s4"&gt;DEBUG: &lt;/span&gt;&lt;span class="s4"&gt;DpDecrypt&lt;/span&gt;&lt;span class="s4"&gt;-Bytes: could not be decrypted.&lt;/span&gt;&lt;span class="s4"&gt;Exception&lt;/span&gt;&lt;span class="s4"&gt;:Value&lt;/span&gt;&lt;span class="s4"&gt; cannot be null.&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s4"&gt;Parameter name: s&lt;/span&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s4"&gt;DEBUG: Exception caught&lt;/span&gt;&lt;span class="s4"&gt;:21&lt;/span&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s4"&gt;DEBUG: &lt;/span&gt;&lt;span class="s4"&gt;RCSServer's&lt;/span&gt;&lt;span class="s4"&gt; start mode is &lt;/span&gt;&lt;span class="s4"&gt;Disabled&lt;/span&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s4"&gt;DEBUG: &lt;/span&gt;&lt;span class="s4"&gt;RCSServer&lt;/span&gt;&lt;span class="s4"&gt; Auto&lt;/span&gt;&lt;/p&gt;&lt;p class="s3"&gt;&lt;span class="s4"&gt;DEBUG: Restarting &lt;/span&gt;&lt;span class="s4"&gt;RCSServer&lt;/span&gt;&lt;/p&gt;&lt;p class="s2" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;span&gt; &lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="s2"&gt;&lt;span class="s2"&gt;I also get the above error when #blocked out any references to scsadmin.dat file.&lt;/span&gt;&lt;/p&gt;&lt;p class="s2"&gt;&lt;span class="s2"&gt;Regards,&lt;/span&gt;&lt;/p&gt;&lt;p class="s2"&gt;&lt;span class="s2"&gt;Pierre&lt;/span&gt;&lt;/p&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:ace8e6e6-2d19-451f-97f9-22405e3ba407] --&gt;</description>
      <pubDate>Mon, 12 Mar 2012 14:27:55 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/151415?tstart=0#151415</guid>
      <dc:date>2012-03-12T14:27:55Z</dc:date>
      <clearspace:dateToText>1 year, 2 months ago</clearspace:dateToText>
      <clearspace:replyCount>4</clearspace:replyCount>
      <clearspace:objectType>0</clearspace:objectType>
    </item>
    <item>
      <title>RCS-Backup.ps1 issue</title>
      <link>http://communities.intel.com/message/151413?tstart=0#151413</link>
      <description>&lt;!-- [DocumentBodyStart:a7fdd5a9-c6b4-40a4-808b-214d994c979e] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;Hi, I&amp;#8217;m having the following problem:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;When I try and do a backup using the RCS-Backup.ps1 PowerShell script included in the SCS 7.1 download the backup fails.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;After turning on debugging in the script I identified the following error:&lt;/p&gt;&lt;p&gt;&lt;em style="mso-bidi-font-style: normal;"&gt;C:\Documents and Settings\All Users\Application Data\Intel_Corporation\RCSConfServer\scsadmin.dat Does not exist (or permissions problem).&lt;/em&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;em&gt; &lt;/em&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;This refers to the following file: &lt;em&gt;scsadmin.dat &lt;/em&gt;&amp;#8212; Contains a record for each system configured using Intel SCS 5.x/6.x and the password of its default Digest admin user. This file only exists if the admin passwords were migrated from Intel SCS 5.x/6.x.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I do not have this file in the RCSConfServer directory as I did not do an upgrade/migrate from an earlier versions, I did a clean install of V7.1.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The syntax I&amp;#8217;m using is as follows:&lt;/p&gt;&lt;p&gt;.\RCS-Backup.ps1 -Operation Backup -Password "********" -Profiles "D:\SOURCE\vPro\vpro powershell\Backup\profiles.bak" -PSK "D:\SOURCE\vPro\vpro powershell\Backup\PSK.bak" -Cred "D:\SOURCE\vPro\vpro powershell\Backup\cred.bak" -DMP "D:\SOURCE\vPro\vpro powershell\Backup\dmp.bak" -SkipUserVerification $True&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;However, if I remove the &amp;#8211;cred parameter I still get the same error.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Any assistance will be greatly appreciated.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Many thanks&lt;/p&gt;&lt;p&gt;Pierre&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:a7fdd5a9-c6b4-40a4-808b-214d994c979e] --&gt;</description>
      <pubDate>Mon, 12 Mar 2012 12:17:26 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/151413?tstart=0#151413</guid>
      <dc:date>2012-03-12T12:17:26Z</dc:date>
      <clearspace:dateToText>1 year, 2 months ago</clearspace:dateToText>
      <clearspace:replyCount>5</clearspace:replyCount>
      <clearspace:objectType>0</clearspace:objectType>
    </item>
  </channel>
</rss>

