<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Intel Communities: Message List - AMT Provisioning hell</title>
    <link>http://communities.intel.com/community/openportit/vproexpert?view=discussions</link>
    <description>Most recent forum messages</description>
    <language>en</language>
    <pubDate>Thu, 02 Jul 2009 04:40:17 GMT</pubDate>
    <generator>Clearspace 2.5.9 (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2009-07-02T04:40:17Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Re: AMT Provisioning hell</title>
      <link>http://communities.intel.com/message/36055?tstart=0#36055</link>
      <description>&lt;!-- [DocumentBodyStart:8ac07839-f88a-48d0-89a8-ce4e6c73a23f] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Well, assuming you've checked all your network configuration (DHCP, DNS), done a factory reset on the problem unit(s), applied Microsoft hotfix KB960804, and triple-checked your root CA's certificate hash, I'm probably going to have to defer to Microsoft Premiere Support on this one.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;By the way, have you opened the AMT Provisioning certificate from your site server, and validated the certificate chain up to your root CA? An invalid certificate chain caused a problem for me a while back. See this blog post for more details:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a class="jive-link-blog-small" href="http://communities.intel.com/community/openportit/vproexpert/blog/2008/11/18/intel-amt-provisioning-issues-with-configmgr-sp1"&gt;http://communities.intel.com/community/openportit/vproexpert/blog/2008/11/18/intel-amt-provisioning-issues-with-configmgr-sp1&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="color: #ff0000;"&gt;Edit: Fixed URL&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Trevor Sullivan&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Systems Engineer&lt;/em&gt;&lt;/p&gt;&lt;p&gt;OfficeMax Corporation&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:8ac07839-f88a-48d0-89a8-ce4e6c73a23f] --&gt;</description>
      <pubDate>Wed, 01 Jul 2009 11:20:56 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/36055?tstart=0#36055</guid>
      <dc:date>2009-07-01T11:20:56Z</dc:date>
      <clearspace:dateToText>4 months, 4 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
    </item>
    <item>
      <title>Re: AMT Provisioning hell</title>
      <link>http://communities.intel.com/message/36611?tstart=0#36611</link>
      <description>&lt;!-- [DocumentBodyStart:06c25deb-c616-452c-97e6-03228452a894] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;OK, thanks for your help, I'll post the solution once I find it.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Bob&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:06c25deb-c616-452c-97e6-03228452a894] --&gt;</description>
      <pubDate>Thu, 02 Jul 2009 04:02:39 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/36611?tstart=0#36611</guid>
      <dc:date>2009-07-02T04:02:39Z</dc:date>
      <clearspace:dateToText>4 months, 4 weeks ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: AMT Provisioning hell</title>
      <link>http://communities.intel.com/message/36031?tstart=0#36031</link>
      <description>&lt;!-- [DocumentBodyStart:bdf8c1cc-2bcf-4d8a-9f4b-da883dccc8c6] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Yes, still seeing that error. I have completely rebuilt the CA and performed a full unprovision on the clients. Still no change, the M10 client provisions fine, but the other one do not. I have checked DNS and the records are correct,&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:bdf8c1cc-2bcf-4d8a-9f4b-da883dccc8c6] --&gt;</description>
      <pubDate>Wed, 01 Jul 2009 00:24:52 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/36031?tstart=0#36031</guid>
      <dc:date>2009-07-01T00:24:52Z</dc:date>
      <clearspace:dateToText>5 months, 22 hours ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
    </item>
    <item>
      <title>Re: AMT Provisioning hell</title>
      <link>http://communities.intel.com/message/34502?tstart=0#34502</link>
      <description>&lt;!-- [DocumentBodyStart:fe85f9dd-6405-459c-8382-3ba9f4a7c838] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Bob,&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Are you still seeing the &lt;em&gt;ApplyControlToken&lt;/em&gt; error? If so, can you double-check your DNS records (A and PTR) for these clients?&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Trevor Sullivan&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Systems Engineer&lt;/em&gt;&lt;/p&gt;&lt;p&gt;OfficeMax Corporation&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:fe85f9dd-6405-459c-8382-3ba9f4a7c838] --&gt;</description>
      <pubDate>Mon, 29 Jun 2009 13:04:25 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/34502?tstart=0#34502</guid>
      <dc:date>2009-06-29T13:04:25Z</dc:date>
      <clearspace:dateToText>5 months, 2 days ago</clearspace:dateToText>
      <clearspace:replyCount>3</clearspace:replyCount>
    </item>
    <item>
      <title>Re: AMT Provisioning hell</title>
      <link>http://communities.intel.com/message/33237?tstart=0#33237</link>
      <description>&lt;!-- [DocumentBodyStart:272aa6c4-1387-4dec-ad2b-a24b4b16b643] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;OK, I've done a full un-provision, from the BIOS and removed the object from AD. Then the M10 client could provision again fine (other clients still fail). I have removed the third party certificate from the certificate store on the oob management point server and deleted, then re-added the OOB service point role. I'm not sure how much 'cleaning' this does, as it still retained the settings I had. I did re-enter all the information anyway, just in case. No change.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The certificate is an internally provisioned one, and the correct certificate hash is in the BIOS of the client PCs. There is no difference in the BIOS settings between the client that does provision, and the ones that don't.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:272aa6c4-1387-4dec-ad2b-a24b4b16b643] --&gt;</description>
      <pubDate>Fri, 26 Jun 2009 03:45:06 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/33237?tstart=0#33237</guid>
      <dc:date>2009-06-26T03:45:06Z</dc:date>
      <clearspace:dateToText>5 months, 5 days ago</clearspace:dateToText>
      <clearspace:replyCount>4</clearspace:replyCount>
    </item>
    <item>
      <title>Re: AMT Provisioning hell</title>
      <link>http://communities.intel.com/message/33234?tstart=0#33234</link>
      <description>&lt;!-- [DocumentBodyStart:894d3e71-0a6f-44e1-aa79-b573a45922c1] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Actually, in addition to what Bill York just mentioned, it might be worth going to the extent of removing and re-installing the OOB service point role on your site server, just to make sure things are "cleaned out." &lt;img height="16px" src="http://communities.intel.com/images/emoticons/happy.gif" width="16px"/&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Trevor Sullivan&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Systems Engineer&lt;/em&gt;&lt;/p&gt;&lt;p&gt;OfficeMax Corporation&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:894d3e71-0a6f-44e1-aa79-b573a45922c1] --&gt;</description>
      <pubDate>Fri, 26 Jun 2009 03:09:24 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/33234?tstart=0#33234</guid>
      <dc:date>2009-06-26T03:09:24Z</dc:date>
      <clearspace:dateToText>5 months, 5 days ago</clearspace:dateToText>
      <clearspace:replyCount>5</clearspace:replyCount>
    </item>
    <item>
      <title>Re: AMT Provisioning hell</title>
      <link>http://communities.intel.com/message/32883?tstart=0#32883</link>
      <description>&lt;!-- [DocumentBodyStart:d846c12d-e5ab-425d-b149-306cde79f0dc] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Did you do a full unprovision or partial unprovision?  And did you perform it from SCCM OOB console or did you perform it manually within the MEBx?&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:d846c12d-e5ab-425d-b149-306cde79f0dc] --&gt;</description>
      <pubDate>Thu, 25 Jun 2009 14:13:29 GMT</pubDate>
      <author>william.york@intel.com</author>
      <guid>http://communities.intel.com/message/32883?tstart=0#32883</guid>
      <dc:date>2009-06-25T14:13:29Z</dc:date>
      <clearspace:dateToText>5 months, 6 days ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: AMT Provisioning hell</title>
      <link>http://communities.intel.com/message/32881?tstart=0#32881</link>
      <description>&lt;!-- [DocumentBodyStart:99d8f01e-ebe9-4751-a683-3d993bcda51e] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Bob, what provisioning certificate did you load into SCCM?  Is it your self generated SCCM cert that was produced from your internal CA?  And did you load that internal Root CA hash into the MEBx before the provisioning process started?  If you want to use your own internally developed cert, I would make sure all references to the VeriSign cert is removed from the CA (personal store and any other store possibly located) and remove it from SCCM (both in the OOB service point and the certificate stores on this site server.  Than make sure your self generated cert is loaded on your SCCM service point (in the OOB config and personal store on SCCM with appropriate private keys).  And make sure you load your internal Root CA hash (top level CA that produced your provisioning cert) into the MEBx.  And see what happens when provisioning.  From your thread below, it seems as you have multiple certs getting confussed and this is hard to diagnose.  I hope this might clean it up a bit...&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:99d8f01e-ebe9-4751-a683-3d993bcda51e] --&gt;</description>
      <pubDate>Thu, 25 Jun 2009 14:11:48 GMT</pubDate>
      <author>william.york@intel.com</author>
      <guid>http://communities.intel.com/message/32881?tstart=0#32881</guid>
      <dc:date>2009-06-25T14:11:48Z</dc:date>
      <clearspace:dateToText>5 months, 6 days ago</clearspace:dateToText>
      <clearspace:replyCount>6</clearspace:replyCount>
    </item>
    <item>
      <title>Re: AMT Provisioning hell</title>
      <link>http://communities.intel.com/message/32658?tstart=0#32658</link>
      <description>&lt;!-- [DocumentBodyStart:58344122-ac6d-43ae-be50-da615e2d40bc] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Also, just to see what would happen, I did an un-provision on the client which is working and was able to again provision this client without any errors.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:58344122-ac6d-43ae-be50-da615e2d40bc] --&gt;</description>
      <pubDate>Thu, 25 Jun 2009 05:27:44 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/32658?tstart=0#32658</guid>
      <dc:date>2009-06-25T05:27:44Z</dc:date>
      <clearspace:dateToText>5 months, 6 days ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
    </item>
    <item>
      <title>Re: AMT Provisioning hell</title>
      <link>http://communities.intel.com/message/32611?tstart=0#32611</link>
      <description>&lt;!-- [DocumentBodyStart:e7e2ca38-4287-4b8c-bc54-75eae42c0c5b] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;OK, so I tried factory reset and remove the record from SCCM. No change. The system actually shows up as 'Detected' in SCCM now (I did a re-install of the AMT driver).&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I had a look at the provisioning record in the bios, and the weird thing is the certificate hash is that of the Verisign one. Now, I am using an internally provisioned certificate, so I did not expect to see this. I had a look on the CA and the verisign certificate is there (from some other project I don't know about).&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;So I tried disabling the verisign cert in the BIOS and did a full un-provision. Then again attempted to provision the client, and again the verisign hash appears in the provisioing record in the machine BIOS. Not sure now if this is the root cause or not.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:e7e2ca38-4287-4b8c-bc54-75eae42c0c5b] --&gt;</description>
      <pubDate>Thu, 25 Jun 2009 00:50:10 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/message/32611?tstart=0#32611</guid>
      <dc:date>2009-06-25T00:50:10Z</dc:date>
      <clearspace:dateToText>5 months, 6 days ago</clearspace:dateToText>
      <clearspace:replyCount>9</clearspace:replyCount>
    </item>
  </channel>
</rss>

