<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Intel Communities: Message List - Get "PKI configuration failed" error when provisioning vPro device</title>
    <link>http://communities.intel.com/community/vproexpert?view=discussions</link>
    <description>Most recent forum messages</description>
    <language>en</language>
    <pubDate>Thu, 12 May 2011 14:13:56 GMT</pubDate>
    <generator>Jive SBS 5.0.2.0  (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2011-05-12T14:13:56Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Re: Get "PKI configuration failed" error when provisioning vPro device</title>
      <link>http://communities.intel.com/message/124709?tstart=0#124709</link>
      <description>&lt;!-- [DocumentBodyStart:661dad16-577f-4b6d-8374-5458f147ce22] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;Hi Bruno,&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Sorry for the delay. We are very busy these days to deal with the issues. Regarding your commments, please see my answers in &lt;span style="color: #ff0000;"&gt;RED&lt;/span&gt;:&lt;/p&gt;&lt;p style="min- padding: 0px;"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Our testing&amp;nbsp; environment:&lt;br/&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min- padding: 0px;"&gt;&lt;/p&gt;&lt;ol start="1"&gt;&lt;li&gt;Server A: Windows 2008 + IIS7.0 + SCS 5.3 + SQL Server 2005 + Domain Controller with DNS Server integrated&lt;br/&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;strong&gt;&amp;gt;&amp;gt; where is your DHCP, for PKI DHCP with option 15 and 81 is a requirement&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong style="color: #ff0000;"&gt;--We didn't enable DHCP before. Once it is enabled, everything is OK.&lt;/strong&gt;&lt;/p&gt;&lt;ol start="1"&gt;&lt;li&gt;Client A:&amp;nbsp; Windows 2003 + vPro 3.2.2 AMT version&lt;br/&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;strong&gt;&amp;gt;&amp;gt; why are you using a server OS instead o client (e.g. Win XP, Vista, 7)? do you have the HECI/LMS driver installed?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong style="color: #ff0000;"&gt;--We built another environment with Windows 7 client. Both Windows 7 and Windows 2003 are provisioned OK. HECI/LMS driver is installed on both client devices&lt;/strong&gt;&lt;/p&gt;&lt;p style="min- padding: 0px;"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The procedure to install and configure vPro testing environment is described below:&lt;br/&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min- padding: 0px;"&gt;&lt;/p&gt;&lt;ol start="1"&gt;&lt;li&gt;We are using PKI mode so we install a Certificate Authority on Server A .&lt;br/&gt;&lt;/li&gt;&lt;li&gt;Create a certificate template and issue the client certificate template on Server A&lt;br/&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;strong&gt;&amp;gt;&amp;gt; Did you follow this procedures to create the template?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong style="color: #ff0000;"&gt;--I created a client authentication template with "Client Authentication" policy and another policy with Oid 2.16.840.1.113741.1.2.1&lt;/strong&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol start="1"&gt;&lt;li&gt;On&amp;nbsp; Server A, request a certificate. In the "Identifying Information For&amp;nbsp; Offline Template, the Name:" field specifiy the fully qualified&lt;br/&gt;name of the Provisioning Server (Server A).&lt;br/&gt;&lt;/li&gt;&lt;li&gt;Install the client certificate on Server A. Export the client certificate.&lt;br/&gt;&lt;/li&gt;&lt;li&gt;Open&amp;nbsp; the root certificate. On the Details tab, note down the certificate&amp;nbsp; hash value in the Thumbprint field. Export the root certificate.&lt;br/&gt;&lt;/li&gt;&lt;li&gt;On Server A, create new Profile in SCS Console. Enable TLS.&lt;br/&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;strong&gt;&amp;gt;&amp;gt; If you would like to use TLS, you must create also a web cliente template&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; You must be aware that provisioning using PKI means use of one certificate for provisioning must be issues, but you don't need issue client certificates to establish TLS connection&amp;nbsp;&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong style="color: #ff0000;"&gt;--I didn't find any reference about the "web client template" . I just create another template with "Server Authentication" policy and another policy with Oid 2.16.840.1.113741.1.2.3&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong style="color: #ff0000;"&gt;--Now we use TLS mutual authentication&lt;/strong&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Create a digest user and give it PT administration right.&lt;/p&gt;&lt;ol start="1"&gt;&lt;li&gt;Start&amp;nbsp; Client A, then press Ctrl+P during startup to enter the Intel MEBX.&amp;nbsp; Manually&amp;nbsp; enter the matching certificate hash value which is obtained&amp;nbsp; from step 5. Input other necessary fields in MEBX.&lt;br/&gt;&lt;/li&gt;&lt;li&gt;vPro&amp;nbsp; Client A is provisioning automatically. The target vPro device appear in&amp;nbsp; SCS console but with its provisioning status "Not Configured".&lt;br/&gt;&lt;/li&gt;&lt;li&gt;We are starting to get the above "PKI configuration failed" errors now.&lt;br/&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;strong style="color: #333333;"&gt;&amp;gt;&amp;gt; DHCP is an important piece here, your client uses suffix DNS presented by DHCP to validate the certificate.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong style="color: #333333;"&gt;&lt;span style="color: #ff0000;"&gt;--After DHCP is enabled, everything is fine.&lt;/span&gt;&lt;br/&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p style="min- padding: 0px;"&gt;&lt;/p&gt;&lt;p&gt;&lt;strong style="color: #333333;"&gt;Best Regards!&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong style="color: #333333;"&gt;-- Bruno Domingues&lt;/strong&gt;&lt;/p&gt;&lt;br/&gt;&lt;br/&gt;&lt;span&gt; &lt;/span&gt;&lt;br/&gt;&lt;br/&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:661dad16-577f-4b6d-8374-5458f147ce22] --&gt;</description>
      <pubDate>Thu, 12 May 2011 09:58:49 GMT</pubDate>
      <author>jing_peng@hotmail.com</author>
      <guid>http://communities.intel.com/message/124709?tstart=0#124709</guid>
      <dc:date>2011-05-12T09:58:49Z</dc:date>
      <clearspace:dateToText>2 years, 1 month ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
    </item>
    <item>
      <title>Re: Get "PKI configuration failed" error when provisioning vPro device</title>
      <link>http://communities.intel.com/message/122213?tstart=0#122213</link>
      <description>&lt;!-- [DocumentBodyStart:c99abc8e-373f-4481-b6c4-89622ca43164] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;Peng,&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have few comments and clues about why you are failing to provisioning your vPro machine (comments inline)&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Our testing&amp;nbsp; environment:&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol start="1"&gt;&lt;li&gt;Server A: Windows 2008 + IIS7.0 + SCS 5.3 + SQL Server 2005 + Domain Controller with DNS Server integrated&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;span style="color: #ff0000;"&gt; &lt;strong&gt;&amp;gt;&amp;gt; where is your DHCP, for PKI DHCP with option 15 and 81 is a requirement&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;ol start="1"&gt;&lt;li&gt;Client A:&amp;nbsp; Windows 2003 + vPro 3.2.2 AMT version&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;span style="color: #ff0000;"&gt;&lt;strong&gt;&amp;gt;&amp;gt; why are you using a server OS instead o client (e.g. Win XP, Vista, 7)? do you have the HECI/LMS driver installed?&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The procedure to install and configure vPro testing environment is described below:&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol start="1"&gt;&lt;li&gt;We are using PKI mode so we install a Certificate Authority on Server A .&lt;/li&gt;&lt;li&gt;Create a certificate template and issue the client certificate template on Server A&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;span style="color: #ff0000;"&gt; &lt;strong&gt;&amp;gt;&amp;gt; Did you follow &lt;a class="jive-link-external-small" href="http://technet.microsoft.com/en-us/library/dd252737.aspx#BKMK_AMTprovisioning22008" target="_blank"&gt;this procedures&lt;/a&gt; to create the template? &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;ol start="1"&gt;&lt;li&gt;On&amp;nbsp; Server A, request a certificate. In the "Identifying Information For&amp;nbsp; Offline Template, the Name:" field specifiy the fully qualified&lt;br/&gt;name of the Provisioning Server (Server A).&lt;/li&gt;&lt;li&gt;Install the client certificate on Server A. Export the client certificate.&lt;/li&gt;&lt;li&gt;Open&amp;nbsp; the root certificate. On the Details tab, note down the certificate&amp;nbsp; hash value in the Thumbprint field. Export the root certificate.&lt;/li&gt;&lt;li&gt;On Server A, create new Profile in SCS Console. Enable TLS.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;span style="color: #ff0000;"&gt; &lt;strong&gt;&amp;gt;&amp;gt; If you would like to use TLS, you must create also a &lt;a class="jive-link-external-small" href="http://technet.microsoft.com/en-us/library/dd252737.aspx#BKMK_AMTwebserver2008" target="_blank"&gt;web cliente template&lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;span style="color: #ff0000;"&gt;You must be aware that provisioning using PKI means use of one certificate for provisioning must be issues, but you don't need issue client certificates to establish TLS connection&amp;nbsp; &lt;/span&gt;&amp;nbsp; &lt;br/&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt; Create a digest user and give it PT administration right.&lt;/p&gt;&lt;ol start="1"&gt;&lt;li&gt;Start&amp;nbsp; Client A, then press Ctrl+P during startup to enter the Intel MEBX.&amp;nbsp; Manually&amp;nbsp; enter the matching certificate hash value which is obtained&amp;nbsp; from step 5. Input other necessary fields in MEBX.&lt;/li&gt;&lt;li&gt;vPro&amp;nbsp; Client A is provisioning automatically. The target vPro device appear in&amp;nbsp; SCS console but with its provisioning status "Not Configured".&lt;/li&gt;&lt;li&gt;We are starting to get the above "PKI configuration failed" errors now.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;strong style="color: #ff0000;"&gt;&amp;gt;&amp;gt; DHCP is an important piece here, your client uses suffix DNS presented by DHCP to validate the certificate.&lt;br/&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong style="color: #ff0000;"&gt;Best Regards!&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong style="color: #ff0000;"&gt;-- Bruno Domingues&lt;br/&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:c99abc8e-373f-4481-b6c4-89622ca43164] --&gt;</description>
      <pubDate>Sat, 23 Apr 2011 01:17:55 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/122213?tstart=0#122213</guid>
      <dc:date>2011-04-23T01:17:55Z</dc:date>
      <clearspace:dateToText>2 years, 1 month ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <clearspace:objectType>0</clearspace:objectType>
    </item>
    <item>
      <title>Re: Get "PKI configuration failed" error when provisioning vPro device</title>
      <link>http://communities.intel.com/message/122475?tstart=0#122475</link>
      <description>&lt;!-- [DocumentBodyStart:7d29d06b-8dc3-426d-ba82-c884c42666f2] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;Hi Steve,&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I enabled DHCP on Server A. On the client computer, set to get IP addresss automatically from DHCP server. After that, the client computer is provisioning correctly without any problems. Thanks! &lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:7d29d06b-8dc3-426d-ba82-c884c42666f2] --&gt;</description>
      <pubDate>Mon, 25 Apr 2011 05:57:17 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/122475?tstart=0#122475</guid>
      <dc:date>2011-04-25T05:57:17Z</dc:date>
      <clearspace:dateToText>2 years, 1 month ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
    </item>
    <item>
      <title>Re: Get "PKI configuration failed" error when provisioning vPro device</title>
      <link>http://communities.intel.com/message/122173?tstart=0#122173</link>
      <description>&lt;!-- [DocumentBodyStart:a069b1c6-f740-457b-b3eb-61078143998d] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt; I don't have an Intel SCS 5.3 user guide, but the 5.2 version did not have a good description of how to add your own PKI certificate.&amp;nbsp; The Intel SCS 6.0 user guide does seem to provide detailed steps.&amp;nbsp; Take a look at the steps in the attached doc.&amp;nbsp; I'll check with the experts here to see if the Intel SCS 6.0 process is the same for Intel SCS 5.3.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:a069b1c6-f740-457b-b3eb-61078143998d] --&gt;</description>
      <pubDate>Fri, 22 Apr 2011 17:57:20 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/122173?tstart=0#122173</guid>
      <dc:date>2011-04-22T17:57:20Z</dc:date>
      <clearspace:dateToText>2 years, 1 month ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <clearspace:objectType>0</clearspace:objectType>
    </item>
    <item>
      <title>Get "PKI configuration failed" error when provisioning vPro device</title>
      <link>http://communities.intel.com/message/122132?tstart=0#122132</link>
      <description>&lt;!-- [DocumentBodyStart:a9ea7e02-b9f9-485e-9eaf-06ec83a005e1] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;Hi,&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;We have built a testing environment to set up vPro using PKI mode. However, the vPro client is not provisioning properly with the following error messages in SCS console event log:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;1214,ERROR!,Error Configuring Intel AMT device: Failed to connect to un-configured Intel AMT device at IP 16.178.122.130: Proper certificate that matches the pre loaded certificate was not found in the user certificate store. PKI configuration failed.,4/22/2011 5:27:07 PM,17410FFB-A956-11DC-BBDA-FE9DD0E9000F,2202,DEVHPCAE\Administrator,WPS2008,&lt;br/&gt;1214,ERROR!,Proper certificate that matches the pre loaded certificate was not found in the user certificate store. PKI configuration failed.,4/22/2011 5:27:07 PM,17410FFB-A956-11DC-BBDA-FE9DD0E9000F,1205,,WPS2008,&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Our testing&amp;nbsp; environment:&lt;br/&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol start="1"&gt;&lt;li&gt;Server A: Windows 2008 + IIS7.0 + SCS 5.3 + SQL Server 2005 + Domain Controller with DNS Server integrated&lt;br/&gt;&lt;/li&gt;&lt;li&gt;Client A:&amp;nbsp; Windows 2003 + vPro 3.2.2 AMT version&lt;br/&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The procedure to install and configure vPro testing environment is described below:&lt;br/&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol start="1"&gt;&lt;li&gt;We are using PKI mode so we install a Certificate Authority on Server A .&lt;br/&gt;&lt;/li&gt;&lt;li&gt;Create a certificate template and issue the client certificate template on Server A&lt;br/&gt;&lt;/li&gt;&lt;li&gt;On Server A, request a certificate. In the "Identifying Information For Offline Template, the Name:" field specifiy the fully qualified&lt;br/&gt;name of the Provisioning Server (Server A).&lt;br/&gt;&lt;/li&gt;&lt;li&gt;Install the client certificate on Server A. Export the client certificate.&lt;br/&gt;&lt;/li&gt;&lt;li&gt;Open the root certificate. On the Details tab, note down the certificate hash value in the Thumbprint field. Export the root certificate.&lt;br/&gt;&lt;/li&gt;&lt;li&gt;On Server A, create new Profile in SCS Console. Enable TLS. Create a digest user and give it PT administration right.&lt;br/&gt;&lt;/li&gt;&lt;li&gt;Start Client A, then press Ctrl+P during startup to enter the Intel MEBX. Manually&amp;nbsp; enter the matching certificate hash value which is obtained from step 5. Input other necessary fields in MEBX.&lt;br/&gt;&lt;/li&gt;&lt;li&gt;vPro Client A is provisioning automatically. The target vPro device appear in SCS console but with its provisioning status "Not Configured".&lt;br/&gt;&lt;/li&gt;&lt;li&gt;We are starting to get the above "PKI configuration failed" errors now.&lt;br/&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Please help to check if I am doing anything wrong. Attached the event log file. Thanks!&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:a9ea7e02-b9f9-485e-9eaf-06ec83a005e1] --&gt;</description>
      <pubDate>Fri, 22 Apr 2011 10:24:07 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/122132?tstart=0#122132</guid>
      <dc:date>2011-04-22T10:24:07Z</dc:date>
      <clearspace:dateToText>2 years, 1 month ago</clearspace:dateToText>
      <clearspace:replyCount>5</clearspace:replyCount>
      <clearspace:objectType>0</clearspace:objectType>
    </item>
  </channel>
</rss>

