<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Activation Blog</title>
    <link>http://communities.intel.com/community/openportit/vproexpert/activation/blog</link>
    <description>Activation focused blog</description>
    <pubDate>Tue, 17 Nov 2009 18:11:21 GMT</pubDate>
    <generator>Clearspace 2.5.9 (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2009-11-17T18:11:21Z</dc:date>
    <item>
      <title>vPro Insights on using Altiris 7 OOB Site Service</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2009/11/17/vpro-insights-on-using-altiris-7-oob-site-service</link>
      <description>&lt;!-- [DocumentBodyStart:079c811e-a08e-4c84-acf4-61e7d848f267] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;If you are moving to an Altiris 7 environment (Symantec Management Platform or Dell Client Management platform), and already have familiarity in working with vPro in an Altiris 6 environment - &lt;a class="jive-link-external-small" href="http://bit.ly/2LL1hu"&gt;take a look at this article on Symantec Connect&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The article provides 4 quick insights:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Pre-defined TaskServer jobs for configuring and maintaining&lt;/li&gt;&lt;li&gt;Checking and fixing the OOB Site Service installation&lt;/li&gt;&lt;li&gt;Once OOB Discovery is enabled, using Filters to determine what systems have Intel AMT&lt;/li&gt;&lt;li&gt;Placement of the remote configuration certificate (different than Altiris 6 environments)&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:079c811e-a08e-4c84-acf4-61e7d848f267] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">altiris</category>
      <pubDate>Tue, 17 Nov 2009 18:11:21 GMT</pubDate>
      <author>terry.c.cutler@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2009/11/17/vpro-insights-on-using-altiris-7-oob-site-service</guid>
      <dc:date>2009-11-17T18:11:21Z</dc:date>
      <clearspace:dateToText>1 week, 4 days ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/activation/blog/comment/vpro-insights-on-using-altiris-7-oob-site-service</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/activation/blog/feeds/comments?blogPost=12854</wfw:commentRss>
    </item>
    <item>
      <title>Recording and Q&amp;As Available: Activate Today! Realize ROI with Intel® vPro Technology and Symantec Altiris</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2009/07/17/recording-and-qas-available-activate-today-realize-roi-with-intel-vpro-technology-and-symantec-altiris</link>
      <description>&lt;!-- [DocumentBodyStart:f9205385-5847-40a3-8597-d18f35a64fb6] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;&lt;em&gt;&lt;a class="jive-link-external-small" href="http://bit.ly/LcwyF"&gt;Activate Today! Realize ROI with Intel® vPro Technology and Symantec Altiris&lt;/a&gt;&lt;/em&gt; is now available for on-demand viewing!&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;We are hosting a series of ROI and activation webinars on Tech Republic; each one is focused on a specific management console - &lt;a class="jive-link-external-small" href="http://bit.ly/LcwyF"&gt;Symantec Altiris&lt;/a&gt;, &lt;a class="jive-link-external-small" href="http://bit.ly/D8MSU"&gt;Microsoft System Center Configuration Manager&lt;/a&gt;, and &lt;a class="jive-link-external-small" href="http://bit.ly/BmFhZ"&gt;LANDesk&lt;/a&gt;.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;This webcast features special guest speakers from Intel Corporation, &lt;strong&gt;Jeff Marek, Director of End User Platform Engineering, Digital Office, and Jeff Torello, Staff Architect, Digital Office and Lee Bender, Sr. Technical Manager of Strategic Alliances, Symantec&lt;/strong&gt;. They discuss the ROI possible with Intel vPro technology usage models activated, a review of the primary usage models supported by Altiris, and an overview of the activation process using Altiris.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;In addition, Kelsey captured the questions and answers from this session (Thanks Kelsey!!).&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Have questions that aren't covered here? Please post them in the &lt;a class="jive-link-community-small" href="http://communities.intel.com/community/openportit/vproexpert/ask" title="Welcome to intel.com/ITopia. A world where IT is as it should be. Ask our experts what you want to know about that latest in Intel vPro Technology."&gt;Ask An Expert forum&lt;/a&gt; and we'll get them answered for you.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" cellpadding="3" cellspacing="0" class="MsoTableGrid"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top" width="175"&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;Question&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" width="463"&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;Answer&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" width="175"&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;Q1: Are there other   vendors/products that take advantage of the vPro technology, or is Symantec   exclusively doing the management for the vPro technology?&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" width="463"&gt;&lt;p class="MsoNormal"&gt;A1: Yes, there are others. In fact, we have many ISV partners that   support vPro Technology in their client management solutions. Other than   Symantec, Microsoft supports vPro in their Configuration Manager (aka SCCM)   product in the Out-of-Band Manager component. LANDesk also support vPro   Technology, as well as others.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" width="175"&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;Q2: Cleveland Clinic: How much   do you pay to purchase desktop from HP? Any minimum purchase?&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" width="463"&gt;&lt;p class="MsoNormal"&gt;A2: We buy over 5000 new pc's a year on our lifecycle process. We   have built into this process the imaging and vpro setup. The cost is volume   based, but anyone can buy a PC from HP with VPRO enablement on a one off   basis.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" width="175"&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;Q3: How could you boot a   remote system from a network ISO if the OS is down? ie no vpn client? Thanks!&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" width="463"&gt;&lt;p class="MsoNormal"&gt;A3: With the Intel vPro technology, a boot redirection can be   initiated. This allows a bootable ISO to be presented to the system. There   are online demonstrations at Intel vPro Expert Center and Symantec Connect. This   is the power of Intel vPro technology and out-of-band management. Regardless   of the host operating system state, Intel vPro technology communications can   connect to, power on\off, present a bootable ISO, and other items over the   network. The bootable ISO can be located at any accessible UNC share. There   are online demonstrations at Intel vPro Expert Center and Symantec Connect.   Example &lt;a class="jive-link-external-small" href="http://www.symantec.com/connect/articles/combining-band-and-out-band-management"&gt;article&lt;/a&gt;.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" width="175"&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;Q4A: What specific kinds of   problems can be fixed remotely, if the OS isn't operating?&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" width="463"&gt;&lt;p class="MsoNormal"&gt;A4: Software problems. By booting to an ISO located somewhere on the   network, the technician has the ability to run diagnostic tools or repair   corrupt files on the local hard drive. So, specifically, a tech could fix OS   problems, perform hardware or low-level scans, boot into the BIOS to review   and change BIOS settings, etc. This ability to redirect the boot process   allows the tech to access common diagnostic tools, even if the OS won't boot!   But obviously, bad hardware cannot be fixed remotely and will require a   desk-side visit.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" width="175"&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;Q4B: OK, so maybe this is   obvious, but to implement this, I need all new hardware, right?&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" width="463"&gt;&lt;p class="MsoNormal"&gt;A4: You may already have systems supporting Intel Active Management   Technology, within the Intel vPro Technology platform. The technology has   been in systems for over 3 years now. There are tools and articles on Intel   vPro Expert Center and Symantec Connect explaining how to find systems. One   example is&lt;a class="jive-link-external-small" href="file:///C:/Documents%20and%20Settings/mgartner/Local%20Settings/Temporary%20Internet%20Files/Content.Outlook/MN2YUHVI/'http:/www.symantec.com/connect/articles/scanning-environment-intel-amt-capable-systems"&gt; here&lt;/a&gt;. Intel vPro Technology is a platform (analogous to Centrino) that   consist of: CPU, chipset, and network adapter(s). I am not aware of any   computer manufacturers that offer FRU (field replaceable unit) upgrades for   motherboards/systems to convert a non-vPro PC to vPro. So, yes, the short   answer is, unless you have existing PC's that support vPro, as companies   refresh their fleet, they can opt for vPro Technology in their new PC   purchases. We maintain a list of PCs featuring vPro Technology on the vPro   Expert Center &lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-2033"&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" width="175"&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;Q5: How long of a time frame   from investigation of vPro to actually having machines up and working?&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" width="463"&gt;&lt;p class="MsoNormal"&gt;A5: [Cleveland Clinic] It’s a process to start this. You really need   to engage the product your using and vPro together. We were very early   adopters in this process, and really took us about 6-7 months. Once we got   through all those initial hurdles, we were able to move very quickly. We have   a lifecycle process now and also pushed that back to our manufacturer. In   terms of new deployment, I think it would be much quicker.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" width="175"&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;Q6: Were all of your employees   behind moving to vPro? Were they all believers at first?&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" width="463"&gt;&lt;p class="MsoNormal"&gt;A6: It’s having a positive impact and is lowering the workload for   people responsible for managing these systems.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" width="175"&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;Q7: How could you boot a   remote system from a network ISO if the OS is down or maybe if you don’t have   a VPN client?&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" width="463"&gt;&lt;p class="MsoNormal"&gt;A7: Intel vPro technology is contained in the hardware, so the OS   itself is irrelevant to the functionality of vPro. The way this would   typically work is that the chipset manages the network stack and so it’s   still on the network with same IP/hostname. You can connect with the Symantec   tool and tell it to grab this network based image (ISO) of our repair utility   that we put together inside our company. That machine will reboot and load   that image across the network. Now, if there’s no VPN client, you can provide   the user a CD to cause the computer to be rebooted, or a USB image and have   that capability still be performed.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" width="175"&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;Q8: What are the typical types   of problems that customers are fixing remotely?&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" width="463"&gt;&lt;p class="MsoNormal"&gt;A8: It’s the ability to reach out and repair and recover the machine   from a variety of bad scenarios. You can go down the wire to figure out if   your inventory isn’t up to date and what kind of hardware it is. Once you   have the ability to boot to an ISO – you can jump into the BIOS you can help   the end user walk through it, low level scans, copy over possibly corrupted   files. We have seen people reboot dead hardware to do even just limited   functionality. Once you can fix something remotely you can repair things that   you usually couldn’t.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top" width="175"&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;Q9: Are there other software   tools that can be used to manage vPro PCs?&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td valign="top" width="463"&gt;&lt;p class="MsoNormal"&gt;There are about 60 different programs that support vPro capabilities.   On the vPro Expert Center there is a list of the programs that support vPro.   Some examples are Microsoft Systems Center Configuration Manager (SCCM) and   LANDesk.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:f9205385-5847-40a3-8597-d18f35a64fb6] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">webinar</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">roi</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">training</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">symantec</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">activation</category>
      <pubDate>Fri, 17 Jul 2009 22:33:29 GMT</pubDate>
      <author>michele.gartner@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2009/07/17/recording-and-qas-available-activate-today-realize-roi-with-intel-vpro-technology-and-symantec-altiris</guid>
      <dc:date>2009-07-17T22:33:29Z</dc:date>
      <clearspace:dateToText>4 months, 2 weeks ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/activation/blog/comment/recording-and-qas-available-activate-today-realize-roi-with-intel-vpro-technology-and-symantec-altiris</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/activation/blog/feeds/comments?blogPost=12351</wfw:commentRss>
    </item>
    <item>
      <title>Remote Configuration Certificate Best Practices in Out of Band Management 7 for Intel vPro Systems</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2009/04/07/remote-configuration-certificate-best-practices-in-out-of-band-management-7-for-intel-vpro-systems</link>
      <description>&lt;!-- [DocumentBodyStart:173f26e6-bb37-4d26-808f-26a800cad1c3] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;div style="border-right: medium none; padding-right: 0in; border-top: medium none; padding-left: 0in; padding-bottom: 4pt; border-left: medium none; padding-top: 0in; border-bottom: #4f81bd 1pt solid; mso-element: para-border-div;"&gt;&lt;/div&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Whether you are planning to implement a Vendor TLS Certificate in the future, or you are having trouble applying a certificate you’ve already obtained, this article walks through the best practices.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; The details include all the steps to properly install the right items and resolve issues we’ve encountered up to this point.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; This article applies to Out of Band Management Solution 7.0, included with Client Management Suite 7.0.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Since certificates introduce tight encryption security, if the right items and steps are not in place or followed, it can break the ability of AMT systems to provision with Remote Configuration.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h1 style="margin: 12pt 0in 3pt;"&gt;&lt;span style="color: #000000; font-family: Cambria;"&gt;Introduction&lt;/span&gt;&lt;/h1&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Why is Configuring a vPro capable system important?&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Without setup and configuration, the functionality provided by vPro is not accessible within your Symantec Client Management Suite environment.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Out of Band Management Solution allows setup and configuration to occur automatically using Remote Configuration.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Using Remote Configuration to setup and configure your Intel AMT vPro capable computers takes the work out of the process, after some initial setup.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; AMT systems that come preconfigured with versions 2.2, 2.6, 3.0+, 4.0+, and 5.0+ will automatically use Remote Configuration to setup and configure with a valid Provisioning Server.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Out of Band Management provides such a server.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; The hashes from vendors (AMT 3.0 includes Verisign, GoDaddy, Comodo) are already configured in the firmware, and upon connection to power and the network, will begin to send out requests for configuration.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Thus in this way the managed vPro systems are already prepared to be configured without any intervention by the IT staff.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Usually the issues we see with the Remote Configuration process originate on the server-side process of adding a certificate from the before mentioned vendors.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Obtaining and installing a vendor TLS Remote Configuration certificate needs to be done the correct way so that authentication can succeed.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Once in place, provisioning will roll forward without any further intervention as long as the certificate remains valid.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; This article focuses on applying the server-side certificate so that setup and configuration can move forward automatically.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h1 style="margin: 12pt 0in 3pt;"&gt;&lt;span style="color: #000000; font-family: Cambria;"&gt;Obtaining a Remote Configuration Certificate&lt;/span&gt;&lt;/h1&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;This subject has been covered previously.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; I wanted to lightly touch upon this as there is a &lt;strong style="mso-bidi-font-weight: normal;"&gt;&lt;em style="mso-bidi-font-style: normal;"&gt;vital&lt;/em&gt;&lt;/strong&gt; step that should be taken so that if anything goes wrong we can correct it.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; First, the following article covers how to properly obtain a certificate:&lt;/span&gt;&lt;/p&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;a class="jive-link-external-small" href="http://juice.altiris.com/article/4496/obtaining-and-applying-a-verisign-remote-configuration-certificate"&gt;&lt;span style="font-size: 12pt; font-family: Calibri;"&gt;http://juice.altiris.com/article/4496/obtaining-and-applying-a-verisign-remote-configuration-certificate&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Note that part of obtaining a Remote Configuration is submitting the request from the Server you plan to install the certificate onto.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; This process creates the private key for the server-side certificate, and this item will not be available until partway through the application of the crt (or cer) file obtained from the vendor.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; The specific step that provides the full key, both private and public, is when the certificate is exported into a PFX format after the initial import, checking the option to export the private key will give you a complete backup of the full certificate in case it is needed in the future.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; If something happens, or if the application doesn’t go right, we’ll need both, so it’s essential to export this as soon as possible.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;During the steps to install the certificate emphasis will be given on the step where the export should take place.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h2 style="margin: 12pt 0in 3pt;"&gt;&lt;em&gt;&lt;span style="font-size: 18pt; color: #000000; font-family: Cambria;"&gt;Certificate Authority (CA)&lt;/span&gt;&lt;/em&gt;&lt;/h2&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;In order to use Remote Configuration with Out of Band Management the Microsoft Certificate Authority services must be installed on the Notification Server or the OOB Site Server.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Use the following steps to install if it is not installed:&lt;/span&gt;&lt;/p&gt;&lt;ol start="1" style="margin-top: 0in;" type="1"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Go to Start &amp;gt; Administrative Tools &amp;gt; and click on Add or Remove Programs.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;In the left-side button bar click the button Add/Remove Windows Components.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;Check the option labeled Certificate Services.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; See this screenshot for details:&lt;br/&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-12037-3846/CAInstall.jpg"&gt;&lt;img alt="CAInstall.jpg" class="jive-image-thumbnail jive-image" height="450" onclick="myJiveImage.start(this, 'http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/3846/CAInstall.jpg');return false;" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-12037-3846/620-450/CAInstall.jpg" width="620"/&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;/span&gt;You’ll receive the pop-up:&lt;br/&gt;&lt;em style="mso-bidi-font-style: normal;"&gt;After installation Certificate Services, the machine name and domain membership may not be changed due to the binding of the machine name to CA information stored in the Active Directory.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Changing the machine name or domain membership would invalidate the certificates issues from the CA.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Please ensure the proper machine name and domain membership are configured before installing Certificate Services. Do you want to continue?&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click Yes to continue once your system has the intended identity.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Click Next.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Choose what type of CA to create.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; If you are not installing a hierarchy of CAs you can leave the stand-alone root CA option selected.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Click Next.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Input the name the CA will be known by.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; This must match what is in the hierarchy or by what the Remote Configuration certificate name will be known by.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;The Distinguished Name is generated automatically in an AD Environment and will be the suffix of the system.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click through the rest of the options, noting where the services data files are stored.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;You will be prompted to restart IIS.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; This is required during the installation.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click Finish to complete the installation.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Done!&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; The NS or Site Server is now prepared to handle certificates in the Remote Configuration process.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h1 style="margin: 12pt 0in 3pt;"&gt;&lt;span style="color: #000000; font-family: Cambria;"&gt;Installing the Certificate&lt;/span&gt;&lt;/h1&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;The recommended application for a Remote Configuration certificate is to let the certificate dictate where to be installed.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; However this process has sometimes resulted with the certificate installed to an incorrect place.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; When this occurred we’ve had headaches trying to clean up the system to properly install the certificate.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Why this occurs is unclear.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; For reference I’m including the process of adding a certificate automatically here:&lt;/span&gt;&lt;/p&gt;&lt;ol start="1" style="margin-top: 0in;" type="1"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l5 level1 lfo4;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Save the acquired cer or crt file from the vendor onto the Notification Server or the Site Server for Out of Band Management.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l5 level1 lfo4;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Right-click on the file and choose Install Certificate.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l5 level1 lfo4;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click next on the Welcome screen.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l5 level1 lfo4;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Leave the radial option on ‘Automatically select the certificate store based on the type of certificate’ and click Next.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l5 level1 lfo4;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click Finish to complete the installation.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; You’ll receive a confirmation pop-up that the certificate installed successfully.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;While I won’t advise against using this method, the below steps uses the manual installation method to ensure the certificate is installed to the correct place.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;I’ve condensed the steps required into the following list.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; This process works for all vendors once you’ve obtained a certificate.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Note that these steps are provided to consolidate both recommended steps and documentation into one whole.&lt;/span&gt;&lt;/p&gt;&lt;ol start="1" style="margin-top: 0in;" type="1"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Go to Start &amp;gt; Run &amp;gt; type mmc &amp;gt; and click OK.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;In the resulting console click under File and choose Add/Remove Snap-ins…&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Near the bottom of the resulting window click the Add button.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;From the list that appears select Certificates and then click the Add button.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Leave the radial button selected on ‘My user account’ and click Finish.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;From the same list select Certificates again and click the Add button.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;From the resulting window change the radial select to ‘Computer account’ and click Next.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Leave the selection at ‘Local computer: (the computer this console is running on) and click Finish.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click the Close button in the window offering you the list of available snap-ins.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;At the original add/remove snap-in screen verify that you have two entries:&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style: none"&gt;&lt;ol start="1" style="margin-top: 0in;" type="a"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level2 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Certificates – Current User&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level2 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Certificates (Local Computer)&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click OK.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;Expand both trees in the left-hand pane within the console.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; You should see the full certificate stores as shown in this screenshot:&lt;br/&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-12037-3847/CertificateStores.jpg"&gt;&lt;img alt="CertificateStores.jpg" class="jive-image" height="384" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-12037-3847/576-384/CertificateStores.jpg" width="576"/&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Right-click on the Personal folder under the Current User certificate store and highlight ‘All Tasks’ and click on ‘Import’ in the pop-out menu.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click Next on the Welcome page of the Certificate Import Wizard and click the Browse button.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Browse to the cer or crt file provided by the vendor, highlight it, and click Open.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click Next, and leave the radial option on ‘Place all certificates in the following store’, which should be set to ‘Personal’.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Click Next.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Under the Completing section of the wizard, Click Finish.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; You should receive a pop-up indicating the certificate was successfully installed.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;&lt;em style="mso-bidi-font-style: normal;"&gt;NOTE!&lt;/em&gt;&lt;/strong&gt;&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; This is the vital step mentioned previously in the article.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; We will now export the certificate with both public and private keys, which will give us the full set and allow us to remove and reapply if necessary.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; In the MMC select the newly imported certificate &amp;gt; right-click &amp;gt; and choose All Tasks &amp;gt; Export…&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click Next on the Welcome screen.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; In the resulting list you should have an active option for ‘Personal Information Exchange – PKCS #12 (.PFX)’.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; If this option is not available (grayed out as shown in this screenshot), there is a problem with the certificate and the private key is not accessible:&lt;br/&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-12037-3848/ExportDial.jpg"&gt;&lt;img alt="ExportDial.jpg" class="jive-image" height="379" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-12037-3848/497-379/ExportDial.jpg" width="497"/&gt;&lt;/a&gt;&lt;br/&gt;If this occurs please note the following items:&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style: none"&gt;&lt;ol start="1" style="margin-top: 0in;" type="a"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level2 lfo2;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;The application of the public key, or cer/crt file, must be done on the server where the key was requested.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level2 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;If this is not your Provisioning Server you’ll need to contact the Vendor of the certificate to resolve the discrepancy.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level2 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;If you did request this certificate from the server you are operating on, you’ll also need to contact the vendor to explain that the private key is not found when exporting the certificate after initial application.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Follow the wizard, and ensure you select the option ‘Yes, export the private key’.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; When saving the file, it will prompt you to set a password to protect the private key (this is recommended for security reasons).&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; The export should leave you a PFX file.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Keep this in a safe place, preferably in line with your company’s encryption certificate backup policy.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Next we need to import the full key into the Computer store.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Start back in the MMC &amp;gt; under the Local Computer certificate store &amp;gt; right-click on the Personal folder &amp;gt; select All Tasks &amp;gt; Import…&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click Next on the Welcome screen and click the Browse button on the subsequent screen.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Browse to the newly exported PFX file.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Note that you will need to change the ‘Files of type’ to include the PFX format.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Click Next.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;The Password screen prompts for the password you set when you exported the key in step #20, as shown in the following screenshot.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Enter the password and click Next.&lt;br/&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-12037-3849/CertPassword.jpg"&gt;&lt;img alt="CertPassword.jpg" class="jive-image" height="378" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-12037-3849/498-378/CertPassword.jpg" width="498"/&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Choose or leave the select to ‘Place all certificates in the following store’.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; The value should be Personal.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Click Next.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click Finish on the end details page to complete the import.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Done!&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;em style="mso-bidi-font-style: normal;"&gt;NOTE: In Out of Band Management 6.x, with Intel SCS 3.x or earlier, a separate utility was required to load certificates into Intel SCS so the Provision Server was aware of them.  This is no longer required as Intel SCS 5.x possesses intelligence to automatically acquire all installed Intel vPro Remote Configuration encryption certificates.&lt;/em&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h2 style="margin: 12pt 0in 3pt;"&gt;&lt;em&gt;&lt;span style="font-size: 18pt; color: #000000; font-family: Cambria;"&gt;Reinstalling the Certificate&lt;/span&gt;&lt;/em&gt;&lt;/h2&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;If you need to reinstall the certificate and you have a PFX file, you can do so by opening both certificate stores (User and Local Computer) as outlined in the previous steps.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Browse through the certificate stores and delete any instance of the vendor certificate.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt; This will remove any associations and allow a clean application of the certificate to occur.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Look for the following:&lt;/span&gt;&lt;/p&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;The name matching the name of the cer or crt file obtained from the vendor&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;The vendor’s certificate (the entry will contain the vendor name).&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;em style="mso-bidi-font-style: normal;"&gt;NOTE: Be careful when removing vendor certificates as they may not be part of the Remote Configuration.  The best example is Verisign, which may have many entries.  If unsure, leave the certificate in place, or export it before deleting it so you can restore it if necessary.&lt;/em&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h2 style="margin: 12pt 0in 3pt;"&gt;&lt;em&gt;&lt;span style="font-size: 18pt; color: #000000; font-family: Cambria;"&gt;Enabling Remote Configuration&lt;/span&gt;&lt;/em&gt;&lt;/h2&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;To ensure that Out of Band Management is setup to use Remote Configuration as a valid setup and configuration method, follow these steps:&lt;/span&gt;&lt;/p&gt;&lt;ol start="1" style="margin-top: 0in;" type="1"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l0 level1 lfo3;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;In the Symantec Management Console browse under Home &amp;gt; Remote Management &amp;gt; and click on Out of Band Management.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l0 level1 lfo3;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;In the left-hand tree browse under Configuration &amp;gt; Configuration Service Settings &amp;gt; and select General.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l0 level1 lfo3;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;In the resulting page ensure that the option labeled Allow Remote Configuration is checked.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; If it is not, check it.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; See this screenshot for an example:&lt;br/&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-12037-3850/EnableRemoteConfig.jpg"&gt;&lt;img alt="EnableRemoteConfig.jpg" class="jive-image-thumbnail jive-image" height="522" onclick="myJiveImage.start(this, 'http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/3850/EnableRemoteConfig.jpg');return false;" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-12037-3850/620-522/EnableRemoteConfig.jpg" width="620"/&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l0 level1 lfo3;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;If you needed to check the option, be sure to click Save Changes to register the change.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;That should do it for the certificates.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; You’ve now completed the steps required to install and enable Remote Configuration in the Out of Band Management Environment.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; However you are not done yet!&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Certain infrastructure components are required to make this process seamless.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Proceed to the next section for details.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h1 style="margin: 12pt 0in 3pt;"&gt;&lt;span style="color: #000000; font-family: Cambria;"&gt;Other Setup Requirements&lt;/span&gt;&lt;/h1&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;The following items will be used to automate the setup and configuration process.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Remote Configuration will use these to locate and communicate with the Provisioning Server (Out of Band Management).&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h2 style="margin: 12pt 0in 3pt;"&gt;&lt;em&gt;&lt;span style="font-size: 18pt; color: #000000; font-family: Cambria;"&gt;ProvisionServer&lt;/span&gt;&lt;/em&gt;&lt;/h2&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Each zone within DNS should have a ProvisionServer entry to ensure that Remote Configuration requests are properly routed to the Server.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; This will also help properly resolve names during the authentication process.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Use the following steps to add ProvisionServer to DNS:&lt;/span&gt;&lt;/p&gt;&lt;ol start="1" style="margin-top: 0in;" type="1"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Go to Start &amp;gt; Run &amp;gt; type mmc &amp;gt; and click OK.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;In the resulting console click under File and choose Add/Remove Snap-ins…&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Near the bottom of the resulting window click the Add button.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;From the list that appears select DNS and click Add and click Close.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click OK in the next Window.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Browse in the tree to the Forward Lookup Zones.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Right-click the entry for the Notification Server computer and choose New Alias.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Type ProvisionServer as the Alias name, in this manner:&lt;br/&gt;ProvisionServer&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;Done!&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Though simple, this is the key to directing the automatic Remote Configuration hello packets from enabled vPro systems to the Notification Server or Site Server.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Without this step no setup and configuration of vPro systems will occur.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;To test, log onto a system on the subnet you’re trying to conduct Remote Configuration from.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Run a command prompt and use the following command:&lt;/span&gt;&lt;/p&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;ping ProvisionServer&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;We should see the responding IP Address by the IP Address of the Notification Server, or, if you’ve set it up this way, the Intel SCS Server conducting provisioning.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Another test you can try is to run the following command:&lt;/span&gt;&lt;/p&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;nslookup ProvisionServer&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;We should get the data on the Notification Server’s Fully Qualified Domain Name (FQDN).&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h2 style="margin: 12pt 0in 3pt;"&gt;&lt;em&gt;&lt;span style="font-size: 18pt; color: #000000; font-family: Cambria;"&gt;DNS Zones&lt;/span&gt;&lt;/em&gt;&lt;/h2&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;In a multiple domain structure this is especially important, but all environments need to have the right data in DNS to properly pass and authenticate in a TLS environment.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; The DNS Primary Zone should be set to the Domain path contained within the certificate.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; For example, if the certificate name is MyNSServer_My1Domain_local, the DNS Primary Zone should be My1Domain.local.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Without this, authentication can fail as the FQDN is used during authentication, and if the name being transmitted across the wire doesn’t match what’s in the certificate, authentication will fail.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Here is another example:&lt;/span&gt;&lt;/p&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Certificate: MyNSServer_My1Domain_local.crt&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;DNS Primary lookup Zone: My1Domain.local&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h2 style="margin: 12pt 0in 3pt;"&gt;&lt;em&gt;&lt;span style="font-size: 18pt; color: #000000; font-family: Cambria;"&gt;DHCP Option&lt;/span&gt;&lt;/em&gt;&lt;/h2&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Another Network related requirement may be DHCP Option 15.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; While I’m not sure why this has proven to be required in some environments and not others, creating this option has resolved failed authentication issues within Remote Configuration.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;In DNS, create an entry for Option 15, with the value of the domain path.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; This will often be the same as what is located in the DNS Primary Zone.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; The following details are an example:&lt;/span&gt;&lt;/p&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Certificate: MyNSServer_My1Domain_local.crt&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;DNS Primary lookup Zone: My1Domain.local&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;DHCP Option 15: My1Domain.local&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h1 style="margin: 12pt 0in 3pt;"&gt;&lt;span style="color: #000000; font-family: Cambria;"&gt;Conclusion&lt;/span&gt;&lt;/h1&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Following the above procedure should allow remote configuration to occur without problems.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Once in place, the configuration will move forward with automatic setup and configuration for all vPro enabled systems that support Remote Configuration.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:173f26e6-bb37-4d26-808f-26a800cad1c3] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">amt</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">out_of_band_management</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">symantec</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">activation</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">setup_and_configuration</category>
      <pubDate>Tue, 07 Apr 2009 20:32:09 GMT</pubDate>
      <author>joel_smith1@symantec.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2009/04/07/remote-configuration-certificate-best-practices-in-out-of-band-management-7-for-intel-vpro-systems</guid>
      <dc:date>2009-04-07T20:32:09Z</dc:date>
      <clearspace:dateToText>7 months, 3 weeks ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/activation/blog/comment/remote-configuration-certificate-best-practices-in-out-of-band-management-7-for-intel-vpro-systems</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/activation/blog/feeds/comments?blogPost=12037</wfw:commentRss>
    </item>
    <item>
      <title>Remote Configuration Certificate Application Best Practices for Intel vPro Systems</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/11/07/remote-configuration-certificate-application-best-practices-for-intel-vpro-systems</link>
      <description>&lt;!-- [DocumentBodyStart:0e21f3b8-bd73-45f8-8569-a9de69148000] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Whether you are planning to implement a Vendor TLS Certificate in the future, or you are having trouble applying a certificate you've already obtained, this article walks through the best practices. The details include all the steps to properly install the right items and resolve issues we've encountered up until this point. This article applies to Out of Band Management Solution 6.2. Since certificates introduce tight encryption security, if the right items and steps are not in place or followed, it can break the ability of AMT systems to provision with Remote Configuration.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Introduction&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;Using Remote Configuration to Provision your Intel AMT vPro capable computers takes the work out of the progress. All 2.6, 3.0+ AMT systems come preconfigured to automatically use Remote Configuration to provision with a valid Provisioning Server. The hashes from vendors (AMT 3.0 includes Verisign, GoDaddy, Comodo) are already configured in the firmware, and upon connection to power and the network, will begin to send out requests for provisioning. Thus in this way the managed vPro systems are already prepared to be provisioned without any needed intervention by the IT staff.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The issues we see then arise from the server-side application of a certificate that matches the hashes already loaded. Obtaining and installing a vendor TLS Remote Configuration certificate needs to be done the right way so that authentication can succeed. Once in place, provisioning will roll forward without any further intervention. This article focuses on applying the server-side certificate so that provisioning can move forward automatically.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Obtaining a Remote Configuration Certificate&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;This subject has been covered previously. I wanted to lightly touch upon this as there is a &lt;strong&gt;&lt;em&gt;vital&lt;/em&gt;&lt;/strong&gt; step that should be taken so that if anything goes wrong we can correct it. First, the following article covers how to properly obtain a certificate:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-external-small" href="http://juice.altiris.com/article/4496/obtaining-and-applying-a-verisign-remote-configuration-certificate"&gt;http://juice.altiris.com/article/4496/obtaining-and-applying-a-verisign-remote-configuration-certificate&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Note that part of obtaining a Remote Configuration is submitting the request from the Server you plan to install the certificate onto. This process creates the private key for the server-side certificate, and this piece will not be available until partway through the application of the crt (or cer) file obtained from the vendor. The specific step that provides the full key, both private and public, is when the certificate is exported after the initial import into a PFX format, checking the option to export the private key will give you a complete backup of the full certificate. If something happens, or if the application didn't go right, we'll need both, so it's essential to export this as soon as possible.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;During the steps to install the certificate emphasis will be given on the step where the export should take place.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Installing the Certificate&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;I've condensed the steps required into the following list. This process works for all vendors once you've obtained a certificate. Note that these steps are provided to consolidate both recommended steps and documentation into one whole.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Go to Start &amp;amp;gt; Run &amp;amp;gt; type mmc &amp;amp;gt; and click OK.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;In the resulting console click under File and choose Add/Remove Snap-in...&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Near the bottom of the resulting window click the Add button.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;From the list that appears select Certificates and then click the Add button.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Leave the radial button selected on ‘My user account' and click Finish.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;From the same list select Certificates again and click the Add button.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;From the resulting window change the radial select to ‘Computer account' and click Next.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Leave the selection at ‘Local computer: (the computer this console is running on) and click Finish.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Click the Close button in the window offering you the list of available snap-ins.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;At the original add/remove snap-in screen verify that you have two entries:&lt;/p&gt;&lt;/li&gt;&lt;ol&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;Certificates - Current User&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;Certificates (Local Computer)&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Click OK.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Expand both trees in the left-hand pane within the console. You should see the full certificate stores.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Right-click on the Personal folder under the Current User certificate store and highlight ‘All Tasks' and click on ‘Import' in the pop-out menu.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Click Next on the Welcome page of the Certificate Import Wizard and click the Browse button.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Browse to the cer or crt file provided by the vendor, highlight it, and click Open.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Click Next, and leave the radial option on ‘Place all certificates in the following store', which should be set to ‘Personal'. Click Next.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Under the Completing section of the wizard, Click Finish. You should receive a pop-up .&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;&lt;strong&gt;&lt;em&gt;NOTE!&lt;/em&gt;&lt;/strong&gt; This is the vital step mentioned previously in the article. We will now export the certificate with both public and private keys, which will give us the full set and allow us to remove and reapply if necessary. In the MMC select the newly imported certificate &amp;amp;gt; right-click &amp;amp;gt; and choose All Tasks &amp;amp;gt; Export...&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Click Next on the Welcome screen. In the resulting list you should have an active option for ‘Personal Information Exchange - PKCS #12 (.PFX)'. If this option is not available there is a problem with the certificate and the private key is not accessible.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Follow the wizard, and ensure you select the option ‘Yes, export the private key'. When saving the file, it will prompt you to set a password to protect the private key (this is recommended for security reasons). The export should leave you a PFX file. Keep this in a safe place, and back it up just in case.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Next we need to import the full key into the Computer store. Start back in the MMC, under the Local Computer certificate store, right-click on the Personal folder, select All Tasks &amp;amp;gt; Import...&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Click Next on the Welcome screen and click the Browse button on the subsequent screen.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Browse to the newly exported PFX file. Note that you will need to change the ‘Files of type' to include the PFX format. Click Next.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;The Password screen prompts for the password you set when you exported the key in step #20. Enter the password and click Next.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Choose or leave the select to ‘Place all certificates in the following store'. The value should be Personal. Click Next.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Click Finish on the end details page to complete the import.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Next, we need to load the certificate into Intel SCS so it can properly authenticate with the AMT systems requesting Remote Configuration. Browse to the following location: \Program Files\Intel\AMTConfServer\Tools.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Execute the file loadcert.exe.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Press Y and Enter.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;A ‘Select Certificate' popup will appear. Select the name of the cer or crt file you received from the vendor and click OK. The window will disappear.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Now both Personal certificate stores and Intel SCS should have all the needed certificates to successfully work with Remote Configuration. However, we are not done as other steps may be needed.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Reinstalling the Certificate&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;If you need to reinstall the certificate and have a PFX file, you can do so by opening both certificate stores (User and Local Computer) as outlined in the previous steps. Browse through the certificate stores and delete any instance of the vendor certificate. This will remove any associations and allow a clean application of the certificate to occur. Look for the following:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;The name matching the name of the cer or crt file obtained from the vendor&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;The vendor's certificate (the entry will contain the vendor name).&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;NOTE: Be careful when removing vendor certificates as they may not be part of the Remote Configuration. The best example is Verisign, which may have many entries. If unsure, leave the certificate in place, or export it before deleting it so you can restore it if necessary.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Other Setup Requirements&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;The following items may be required, depending on the environment.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;ProvisionServer&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;Each zone within DNS should have a ProvisionServer entry to ensure that Remote Configuration requests are properly routed. This will also help properly resolve names during the authentication process. To test, log onto a system on the subnet you're trying to conduct Remote Configuration from. Run a command prompt and use the following command:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;ping ProvisionServer&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;We should see the responding IP Address by the IP Address of the Notification Server, or, if you've set it up this way, the Intel SCS Server conducting provisioning. Another test you can try is to run the following command:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;nslookup ProvisionServer&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;We should get the data on the Notification Server's name.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;DNS Zones&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;In a multiple domain structure this is especially important, but all environments need to have the right data in DNS to properly pass and authenticate in a TLS environment. The DNS Primary Zone should be set to the Domain path contained within the certificate. For example, if the certificate name is MyNSServer_My1Domain_local, the DNS Primary Zone should be My1Domain.local. Without this, authentication can fail as the FQDN is used during authentication, and if the name being transmitted across the wire doesn't match what's in the certificate, authentication will fail. Here is another example:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Certificate: MyNSServer_My1Domain_local.crt&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;DNS Primary lookup Zone: My1Domain.local&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;DHCP Option&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;Another Network related requirement may be DHCP Option 15. While I'm not sure why this has proven to be required in some environments and not others, creating this option has resolved failed authentication issues within Remote Configuration.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;In DNS, create an entry for Option 15, with the value of the domain path. This will often be the same as what is located in the DNS Primary Zone. The following details are an example:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Certificate: MyNSServer_My1Domain_local.crt&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;DNS Primary lookup Zone: My1Domain.local&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;DHCP Option 15: My1Domain.local&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Conclusion&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;Following the above procedure should allow remote configuration to occur without problems. Once in place, the configuration will move forward with automatically provisioning systems that support Remote Configuration.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:0e21f3b8-bd73-45f8-8569-a9de69148000] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">activation</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">amt</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">intel_amt</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">intel_scs</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">symantec</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">out_of_band_management</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">provisioning</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">setup</category>
      <pubDate>Fri, 07 Nov 2008 22:35:26 GMT</pubDate>
      <author>joel_smith1@symantec.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/11/07/remote-configuration-certificate-application-best-practices-for-intel-vpro-systems</guid>
      <dc:date>2008-11-07T22:35:26Z</dc:date>
      <clearspace:dateToText>1 year, 3 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/activation/blog/comment/remote-configuration-certificate-application-best-practices-for-intel-vpro-systems</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/activation/blog/feeds/comments?blogPost=11691</wfw:commentRss>
    </item>
    <item>
      <title>Implementing network filtering with Symantec Altiris</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/09/05/implementing-network-filtering-with-symantec-altiris</link>
      <description>&lt;!-- [DocumentBodyStart:6378b671-bc48-4861-b919-bc1bb2b9bd49] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;If you are using Altiris as your management console, then check out this new use case document for implementing network filters!&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1927"&gt;Altiris Use Case: Network Filtering and System Defense&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:6378b671-bc48-4861-b919-bc1bb2b9bd49] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">symantec</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">use_cases</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">system_defense</category>
      <pubDate>Fri, 05 Sep 2008 20:16:05 GMT</pubDate>
      <author>michele.gartner@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/09/05/implementing-network-filtering-with-symantec-altiris</guid>
      <dc:date>2008-09-05T20:16:05Z</dc:date>
      <clearspace:dateToText>1 year, 2 months ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/activation/blog/comment/implementing-network-filtering-with-symantec-altiris</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/activation/blog/feeds/comments?blogPost=11501</wfw:commentRss>
    </item>
    <item>
      <title>The Mechanics of Provisioning with Out of Band Management 6.3</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/08/11/the-mechanics-of-provisioning-with-out-of-band-management-63</link>
      <description>&lt;!-- [DocumentBodyStart:ec25c22e-4f60-4bfc-adae-967e6d458196] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;For those who have Provisioned Intel AMT Systems, you may wonder what takes place in the background. This article is for you! The process has often been covered at a high level, but here the technical details are provided. Hopefully this helps you understand the inner workings, and provide you information when troubleshooting Provisioning issues. And for those of you who are technically minded, it's also neat to know! This information was compiled working on issues and running through provisioning processes from Symantec Support.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Introduction&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;Often the Provisioning process for Intel vPro systems has been described as complex. This comes from the fact that the Provisioning process was designed with high security in mind. Since the initial release we have improved success rates by working with Intel to make the process more user friendly without compromising the high level of security. To this end this document will explain the process of Provisioning from a technical level, providing an unfiltered view of the process, also without compromising its security.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Provisioning Flow&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;The following process assumes that Altiris Out of Band Management and Intel SCS are install, configured, and ready to go. This process follows the flow of Provisioning and what data points, technologies, and methods are used. The level of details is meant to be a resource when working with Provisioning or troubleshooting Provisioning issues, so not all details are available for this process. Note the following points before moving through the process:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;The console items in the Altiris Console under View &amp;amp;gt; Solutions &amp;amp;gt; Out of Band Management &amp;amp;gt; Provisioning are not tied to the Altiris database like most of the rest of the Altiris Console. They connect through a virtual Website (AMTSCS under the Default Website of the SCS Server) to the IntelAMT database.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Data from two databases (IntelAMT and Altiris) are used during the Provisioning process.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The following articles can assist if you need information on these:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-external-small" href="http://juice.altiris.com/article/1314/altiris-and-intel-reg-vpro-copy-technology-evaluators-guide"&gt;http://juice.altiris.com/article/1314/altiris-and-intel-reg-vpro-copy-technology-evaluators-guide&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Administrator's and Reference Guides: &lt;a class="jive-link-external-small" href="http://www.altiris.com/support/documentation"&gt;http://www.altiris.com/support/documentation&lt;/a&gt; look under Out of Band Management&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;The server is loaded with a security key or certificate. See the following two items for how these keys are loaded:&lt;/p&gt;&lt;/li&gt;&lt;ol&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;For a PID PPS, either keys are randomly generated or imported into the IntelAMT database. Specifically they reside in the table csti_pid_map. Once created/imported, they are available for verifying authentication from an incoming provisioning request from AMT.&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;For TLS-PKI (certificate-based Remote Configuration) a certificate is loaded onto the server. See this article for details: &lt;a class="jive-link-external-small" href="http://juice.altiris.com/article/4496/obtaining-and-applying-a-verisign-remote-configuration-certificate"&gt;http://juice.altiris.com/article/4496/obtaining-and-applying-a-verisign-remote-configuration-certificate&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;The clients need the matching keys loaded onto them. This is done differently depending on the type:&lt;/p&gt;&lt;/li&gt;&lt;ol&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;For PID PPS the keys are set by one of the following methods: the OEM sets it, it's entered manually into the Intel ME, or inputted via a one-touch USB flash drive. The PID and PPS are written into the firmware to be used as the authentication credentials when it looks for a provisioning server.&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;For Remote Configuration (TLS-PKI) at the factory predefined hashes are burned into the firmware for the following certificate vendors (more to come in subsequent versions of AMT). This means AMT already has authentication keys to begin the provisioning process direct from the factory.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/ol&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;VeriSign&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Komodo&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;GoDaddy&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;The client machine, once it has it's keys and has been connected to the network and power, uses one of two methods to find the Provisioning Server:&lt;/p&gt;&lt;/li&gt;&lt;ol&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;The IP address of the server can be manually put into the Intel ME, including what port the SCS listener is configured for (default 9971). When this is done, the AMT client will transmit its Hello message directly to the IP Address and port.&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;The client will transmit its message on port 9971 to the name of ‘ProvisionServer'. If Out of Band Management, Intel SCS, and DNS have been properly setup DNS will route the packet to the Notification Server.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;The Notification Server is set to listen for AMT Provisioning traffic on port 9971, but can be configured to use a different port if so desired in the Altiris Console under View &amp;amp;gt; Solutions &amp;amp;gt; Out of Band Management &amp;amp;gt; Configuration &amp;amp;gt; Provisioning &amp;amp;gt; Configuration Service Settings &amp;amp;gt; General. The top options labeled: ‘Listen port:".| &lt;br/&gt;!ListenPort.jpg!&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;When SCS, via the service AMTConfig (process AMTConfigWinService.exe) receives the incoming "hello" packet, it initiates an authentication request with the client to complete the authentication process, the beginning of which was stored in the packet. Once authentication completes successfully, the process moves on.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;The service, AMTConfig, catches the incoming packet and logs the data in the IntelAMT database, in the table csti_amts. This table contains all the relevant data for this system's identity. &lt;br/&gt;!csti_amts.jpg!&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Once the system has been logged into the IntelAMT database, Intel SCS uses the database entries under csti_configuration to initiate what's known as the props script. This script is what will assist in the provisioning process. In Altiris case, it is oobprov.exe, located by default at C:\Program Files\Altiris\OOBSC\oobprov.exe. For an example of how Intel SCS knows about this, see this data snippet from the csti_configuration table: &lt;br/&gt;!csti_configuration.jpg!&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;On a busy SCS server you can look at Task Manager and see multiple instances of oobprov.exe running. The default settings allow 10 threads to work on provisioning requests at any given time. These threads will interface with the Altiris Database via the Altiris Agent on the local server system. In a standard setup the local system is also the Notification Server.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;OOBPROV runs a SQL query to fetch the Fully Qualified Domain Name (FQDN) for the system it is to provision. The query is based off the following data points:&lt;/p&gt;&lt;/li&gt;&lt;ol&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;UUID passed to it via Intel SCS, Source is as follows: Database: IntelAMT, Table: csti_amts, Data Source: "Hello" packet from AMT system, Values used: uuid&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;Database: Altiris, Data-class: OOB Capability, Table: Inv_OOB_Capability, Data Source: Out of Band Discovery Task, Values used: _ResourceGuid - UUID&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;Database: Altiris, Data-class: AeX AC Location, Table: Inv_AeX_AC_Location, Data Source: Basic Inventory Agent, whether from Basic Inventory function or Hardware Inventory from Inventory Solution, Values used: _ResourceGuid - Fully Qualified Domain Name&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;The Query accomplishes the following: It takes the UUID from csti_amts, uuid and looks for a match in Inv OOB Capability, uuid. If a match is made, it takes the _ResourceGuid from the same table and makes a match of the same columns name to AeX AC Location. With the match it then reads the values stored under Fully Qualified Domain Name (I'm not sure why they didn't just label this column FQDN...).&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Next, oobprov.exe hands back the FQDN it's read from AeX AC Location, Fully Qualified Domain Name and passes it to SCS. SCS takes this value and inserts it into the IntelAMT database at csti_amts, fqdn for the matching resource.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Next, oobprov.exe fetches the automatic profile set within Out of Band Management Solution. This is done in the Altiris Console under View &amp;amp;gt; Solutions &amp;amp;gt; Out of Band Management &amp;amp;gt; Configuration &amp;amp;gt; Provisioning &amp;amp;gt; Intel AMT Systems &amp;amp;gt; Resource Synchronization. This policy needs to be enabled for this step to work, and a default profile configured and selected under the dropdown labeled ‘Intel AMT 2.0+ to profile:'.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;The profile provides the operational data for management of the AMT system. After AMT accepts the profile, the Provisioning process is now complete. Before this step, AMT functionality is not available on this system, and after this step only properly authenticated functions will be able to use Intel vPro on the target provisioned systems.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Troubleshooting&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;The following items can be considered break points for this process. If you've done provisioning you may have run into the symptoms produced by the following items. These are compiled as common areas of trouble in this process.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;The "Hello" packets only transmit for 24 hours, on a back-off schedule, before stopping altogether. If the Server is unable to provision in that time, with IP refreshes becoming more frequent, the system can be in a limbo state. See this article for steps to rectify: &lt;a class="jive-link-external-small" href="http://juice.altiris.com/article/3612/using-intels-rct-tool-restart-amt-hello-packets-enterprise-provisioning"&gt;http://juice.altiris.com/article/3612/using-intels-rct-tool-restart-amt-hello-packets-enterprise-provisioning&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;IP Address changes, refreshes within DHCP during a system's build process can leave SCS with an out of date IP Address for a system that needs provisioning. Coupled with the preceding issue this can leave the system in an unprovisioned state, leaving no ability of the SCS to contact the system to finish the process.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Remote Configuration certificate is not properly installed on the server, producing authentication failure messages in the AMT logs.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Oobprov.exe is unable to fetch the FQDN. The AMT system needs the Altiris Agent installed, have sent Basic Inventory when it had a valid FQDN (for example a system in the process of being built might not have a valid FQDN yet), OOB Discovery Task downloaded and executed, and data populated into the OOB Capability data class from the task in order for oobprov.exe to be able to fetch the FQDN. Conversely you can use the option in Resource Synchronization labeled, ‘Use DNS IP resolution to find FQDN when assigning profiles'.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;A good resource for troubleshooting issues can be found here:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-external-small" href="http://juice.altiris.com/book/3699/troubleshooting-altiris-manageability-toolkit-vpro-technology"&gt;http://juice.altiris.com/book/3699/troubleshooting-altiris-manageability-toolkit-vpro-technology&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Conclusion&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;Knowing the underline mechanisms can help when troubleshooting or even when planning your environment. While not all details are provided here, the most essential are.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:ec25c22e-4f60-4bfc-adae-967e6d458196] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">activation</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">amt</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">out_of_band_management</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">symantec</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">provisioning</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">notification_server</category>
      <pubDate>Mon, 11 Aug 2008 16:05:04 GMT</pubDate>
      <author>joel_smith1@symantec.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/08/11/the-mechanics-of-provisioning-with-out-of-band-management-63</guid>
      <dc:date>2008-08-11T16:05:04Z</dc:date>
      <clearspace:dateToText>1 year, 3 months ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/activation/blog/comment/the-mechanics-of-provisioning-with-out-of-band-management-63</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/activation/blog/feeds/comments?blogPost=11416</wfw:commentRss>
    </item>
    <item>
      <title>Using Altiris? Check out new docs on best practices, wireless, and remote diagnostics</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/06/05/using-altiris-check-out-new-docs-on-best-practices-wireless-and-remote-diagnostics</link>
      <description>&lt;!-- [DocumentBodyStart:a7eaa1b3-e8b1-4a3c-b588-2e22e7d0c605] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;New documents for Altiris were just posted - Check them out!&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1670"&gt;Best Practices and Troubleshooting of Intel® vPro™ Technology with the Altiris® Agent&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1669"&gt;Altiris use case: Remote Diagnostics and Repair&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1668"&gt;Altiris and Intel(R) vPro(TM) Technology over Wireless&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;More are coming soon - come back for Altiris docs on provisioning, asset tracking, and network filters.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:a7eaa1b3-e8b1-4a3c-b588-2e22e7d0c605] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">use_cases</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">best_practice</category>
      <pubDate>Thu, 05 Jun 2008 22:47:02 GMT</pubDate>
      <author>michele.gartner@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/06/05/using-altiris-check-out-new-docs-on-best-practices-wireless-and-remote-diagnostics</guid>
      <dc:date>2008-06-05T22:47:02Z</dc:date>
      <clearspace:dateToText>1 year, 5 months ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/activation/blog/comment/using-altiris-check-out-new-docs-on-best-practices-wireless-and-remote-diagnostics</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/activation/blog/feeds/comments?blogPost=11258</wfw:commentRss>
    </item>
    <item>
      <title>Optimal situation for provisioning in an Altiris environment</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/04/30/optimal-situation-for-provisioning-in-an-altiris-environment</link>
      <description>&lt;!-- [DocumentBodyStart:80cebd9f-ee75-4864-ad88-820467d51b4a] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Have you ever wondered what the optimal provisioning conditions, and if there is anyway to script the event to occur?  The linked article refers to batch files, VBscripts, key learning, and supporting materials for provisioning Intel vPro in an Altiris environment.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a class="jive-link-external-small" href="http://juice.altiris.com/node/4082"&gt;http://juice.altiris.com/node/4082&lt;/a&gt;&lt;span&gt; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Take a look, add you insights\comments, and so forth.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:80cebd9f-ee75-4864-ad88-820467d51b4a] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">provisioning</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">vpro</category>
      <pubDate>Wed, 30 Apr 2008 18:17:44 GMT</pubDate>
      <author>terry.c.cutler@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/04/30/optimal-situation-for-provisioning-in-an-altiris-environment</guid>
      <dc:date>2008-04-30T18:17:44Z</dc:date>
      <clearspace:dateToText>1 year, 7 months ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/activation/blog/comment/optimal-situation-for-provisioning-in-an-altiris-environment</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/activation/blog/feeds/comments?blogPost=11116</wfw:commentRss>
    </item>
    <item>
      <title>Remote Configuration and Altiris</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/04/04/remote-configuration-and-altiris</link>
      <description>&lt;!-- [DocumentBodyStart:6998921c-ddca-4998-a9f7-a8dfb8bdca39] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;&lt;span&gt;For those pursuing remote configuration in an Altiris environment, take a look at the article posted at &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://juice.altiris.com/article/3866/frequently-asked-questions-about-remote-configuration"&gt;http://juice.altiris.com/article/3866/frequently-asked-questions-about-remote-configuration&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Some parts of the article are applicable even outside an Altiris environment&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:6998921c-ddca-4998-a9f7-a8dfb8bdca39] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">remote_configuration</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">vpro</category>
      <pubDate>Fri, 04 Apr 2008 17:47:55 GMT</pubDate>
      <author>terry.c.cutler@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/04/04/remote-configuration-and-altiris</guid>
      <dc:date>2008-04-04T17:47:55Z</dc:date>
      <clearspace:dateToText>1 year, 7 months ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/activation/blog/comment/remote-configuration-and-altiris</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/activation/blog/feeds/comments?blogPost=11021</wfw:commentRss>
    </item>
    <item>
      <title>Altiris and Remote Configuration - ManageFusion lab</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/03/21/altiris-and-remote-configuration-managefusion-lab</link>
      <description>&lt;!-- [DocumentBodyStart:544eae2a-563f-460c-a74f-ce4094b64b3c] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;If you are planning to be at the Symantec\Altiris ManageFusion event in Las Vegas this year (April 8-10), be sure to sign up for the vPro labs.  On Tuesday afternoon there will be an operations focused lab.  On Wednesday afternoon there will be an Enterprise Provisioning using Remote Configuration.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;On the enterprise provisioning side, there are mainly three items to keep in mind&lt;/p&gt;&lt;!--[CodeBlockStart:2c1f4660-03c0-44e0-a741-659170e0d8df]--&gt;&lt;span&gt;&lt;ul&gt;&lt;li&gt;Authenticate the Intel vPro firmware to the provisioning service&lt;/li&gt;&lt;li&gt;Obtain the Configuration parameters - provision profile, Active Directory OU, etc&lt;/li&gt;&lt;li&gt;Map the Clients FQDN and UUID&lt;/li&gt;&lt;/ul&gt;&lt;/span&gt;&lt;!--[CodeBlockEnd:2c1f4660-03c0-44e0-a741-659170e0d8df]--&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The enterprise provisioning lab will discussion and step through each.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:544eae2a-563f-460c-a74f-ce4094b64b3c] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">remote_configuration</category>
      <pubDate>Sat, 22 Mar 2008 02:27:41 GMT</pubDate>
      <author>terry.c.cutler@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/03/21/altiris-and-remote-configuration-managefusion-lab</guid>
      <dc:date>2008-03-22T02:27:41Z</dc:date>
      <clearspace:dateToText>1 year, 8 months ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/activation/blog/comment/altiris-and-remote-configuration-managefusion-lab</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/activation/blog/feeds/comments?blogPost=10993</wfw:commentRss>
    </item>
    <item>
      <title>Troubleshooting the Altiris Manageability Toolkit for vPro Technology - Part 4 - Provisioning Server Troubleshooting</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/03/19/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-4-provisioning-server-troubleshooting</link>
      <description>&lt;!-- [DocumentBodyStart:cb34e205-ee43-4c63-b8e3-21ac168684f9] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;In part 3 we covered troubleshooting common Provisioning Console issues. In part 4 we now focus on those components operating in the background during provisioning. With a functioning install and console, and when the issue appears to be server-related (In part 1 we covered troubleshooting the locale AMT system) now any issues seen must be evaluated on the server side. This article covers this process in a Problem - Cause - Solution format.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Introduction&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;The server components constitute a lot of ‘background' processes that support what is only seen as Altiris Console points. Much of what goes on in the background is invisible to the user save as a change in status. If setup correctly, machines simply provision. It's when they do not provision that a user should understand the server components so that proper troubleshooting can be accomplished. Note that this covers the symptoms of server-component problems. Some of the symptoms do overlap client-side issues, but in this process we are assuming we've confirmed that the client systems is functioning as expected. If you are unsure, see Part 1 of this article series.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Symptoms&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;The following symptoms are seen on the Server. Please note that some of the symptoms may appear to be both client and server related making it difficult to know where the issue lies. Use Part 1 in conjunction with this article if necessary in troubleshooting these issues.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;No update to Intel AMT Systems Node - At times this node can abruptly appear stagnant with no new systems coming in and no provisioning taking place&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;No Systems Appearing - The Intel AMT Systems node may stay blank even after connecting systems in Setup Mode onto the Network.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;FQDN Not Acquired - Once the SCS receives a hello message, it needs to acquire the FQDN, and if this fails the machine will remain in an unprovisioned state&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;No systems Provisioning - This can occur where systems show up in the system, but none of them provision&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Properties Script Failed - This is a common error to be covered separately, though many of the above symptoms end up throwing this particular error&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;In addition to the symptoms, the following tools were used to troubleshoot the issues to find out which particular issue afflicted the Server:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;AMT Logs&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;OOB Trace Loggging&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Wireshark&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;See Part 1 in this article series on how to use these. These will be referenced in the below items.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;No update to Intel AMT Systems Node&lt;/span&gt;&lt;/h1&gt;&lt;h2&gt;&lt;span&gt;Problem&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;The typical symptom is an abrupt stop to updates on this node. For example if you have a number of provisioned systems, with systems added as systems are brought up on the network, and abruptly they stop updating or being added, this is indicative of this issue.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tools:&lt;/strong&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;AMT Logs - No updates to this log occur.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Cause&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;AMTConfig Service - The AMTConfig service has stopped, crashed, or is in a hung state. This isn't common in version 3.0 of SCS or higher.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Resolution&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;Check that the AMTConfig Service is running.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;1. Go to Services Manager under Administrative Tools.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;2. Check the Service named AMTConfig to make sure it is running.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;3. If the service is not running, start it. If the service is running, try restarting it just in case it's in an hung state.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;4. Once the service is up and running again (if this is the issue) provisioning should start occurring.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;No Systems Appearing&lt;/span&gt;&lt;/h1&gt;&lt;h2&gt;&lt;span&gt;Problem&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;The symptom is that no machines appear in the Intel AMT Systems list when the page is refreshed over a period of time when new systems are expected. The page ties directly into the IntelAMT database to populate the systems, so if the list isn't updating on the page, the list is also not updating in the database.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-10990-1310/IntelAMTSystems.jpg"&gt;&lt;img height="335" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-10990-1310/620-335/IntelAMTSystems.jpg" width="620"/&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tools:&lt;/strong&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;AMT Logs - I. No entries found&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;II. No entries found&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;III. Invalid PID Map error&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Wireshark - II. On the client the "Hello" packet is sent, but on the server it never arrives.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Cause&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;The causes vary. See below for known causes for this issue:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;I. AMTConfig Service - The AMTConfig service has stopped, crashed, or is in a hung state. This isn't common in version 3.0 of SCS or higher.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;II. "Hello" packets - The routing of "hello" packets is not configured correctly, so clients can't reach the Provision Server.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;III. PID rejected - The PID provided in the "Hello" packet is not contained as a valid security key in the IntelAMT database. This is only seen in the AMT Log found in the Provisioning Console under Logs, selecting the ‘Log' icon.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Resolution&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;See the steps to follow for the above causes.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;I. AMTConfig Service&lt;/p&gt;&lt;/li&gt;&lt;ul&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;1. See the resolution to the section No update to Intel AMT Systems Node.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;II. "Hello" Packets&lt;/p&gt;&lt;/li&gt;&lt;ul&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;1. In the Provisioning console go to the DNS Configuration node. Does the ‘Test' button allow Provisionserver to resolve back to the IP of the Notification Server?&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;2. If yes, go to the segment of the network the client is on and try to ping the name ‘Provisionserver'. Does the IP resolve?&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;3. If answer to either question above is NO, a CNAME record needs to be created on each DNS Server to route to the IP address of the Notification Server.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;III. PID rejected&lt;/p&gt;&lt;/li&gt;&lt;ul&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;1. In the Provisioning Console go to the Security Keys node under the Configuration Service Settings. The list of unused PID and PPS combinations are listed.&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;2. In the IntelAMT database, within the csti_pid_map table all used and unused security keys are listed. The ones with a value ‘True' in the ‘Used' column will not show up in the console.&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;3. Either import the keys if the OEM placed the AMT systems in TLS-PSK Setup Mode through the import button in the Security Keys page, or manually enter the PID PPS.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;FQDN Not Acquired&lt;/span&gt;&lt;/h1&gt;&lt;h2&gt;&lt;span&gt;Problem&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;One or more Intel AMT Systems are registering in Intel SCS, but they never show an FQDN and never move out of the ‘Unprovisioned' status. In the AMT Log often these systems show the error ‘Properties Script Failed' (note that the cause of this error can be many, and this issue is but one of them). &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;NOTE!&lt;/strong&gt; If no system is provisioning the issue may not be FQDN related. See No Systems Provisioning in this article for more information.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tools:&lt;/strong&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;AMT Logs - Properties Script Failed messages&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;OOB Trace - Unable to locate FQDN (Fully Qualified Domain Name) entries&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Cause&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;Intel SCS calls the Out of Band Provisioning or Properties script oobprov.exe to do a number of things. The first thing it does is obtain an FQDN for the machine needing provisioning. If it fails to obtain an FQDN Provisioning will fail and the computer will remain in an unprovisioned state until oobprov.exe can successfully locate the FQDN.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Resolution&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;To find the FQDN, oobprov.exe runs through a number of checks. The suggested method is to have the Altiris Agent installed and have run the OOB Discovery Task (located in the Altiris Console under View &amp;amp;gt; Solutions &amp;amp;gt; Out of Band Management &amp;amp;gt; Configuration &amp;amp;gt; Out of Band Discovery &amp;amp;gt; Out of Band Discovery). This populates the Altiris database so it has both an FQDN in the AeX AC Location data class and the UUID in the Inv_OOB_Capability data class. If this data is not available, another option is to check DNS resolution as a method. In the Altiris Console look under the Resource Synchronization node, within the Intel AMT Systems folder. As shown below, this option enables oobprov.exe to use DNS IP resolution as a method. &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-10990-1311/DNSReverseLookup.jpg"&gt;&lt;img height="320" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-10990-1311/620-320/DNSReverseLookup.jpg" width="620"/&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;NOTE the warning found directly below the checkbox: Warning! Using DNS for IP to FQDN resolution might lead to incorrect profile mapping. Make sure your DHCP server is configured correctly to give update the DNS server for dynamic addresses.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;No systems Provisioning&lt;/span&gt;&lt;/h1&gt;&lt;h2&gt;&lt;span&gt;Problem&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;Systems are added regularly to the Intel AMT Systems node, but they never provision. This includes never getting an FQDN (see the above section for more information), though the cause may not be the inability of oobprove.exe to obtain the FQDN.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tools:&lt;/strong&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;AMT Logs - Provisioning Script Failed messages&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;OOB Trace - No references to oobprov.exe&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Cause&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;If not an FQDN mapping issue, this issue stems from a timeout value in the IntelAMT database being set to 0. In the IntelAMT database, in the table csti_configuration, under the column Props_script_timeout if the value is 0 IntelSCS will timeout before it even has a chance to call oobprov.exe.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Resolution&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;Normally only one row exists in this table. The following SQL query will properly update this value to the default level. The default is 180 and should be set.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;USE IntelAMT&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;UPDATE csti_configuration&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;SET props_script_timeout = 180&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;WHERE use_props_script = 'True'&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Execute the script within SQL Query Analyzer or SQL Enterprise Studio to update the value.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Properties Script Failed&lt;/span&gt;&lt;/h1&gt;&lt;h2&gt;&lt;span&gt;Problem&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;This message can mean a number of things, including the symptoms described in the preceding two section. This message can continually appear into the AMT logs as provisioning is attempted over and over.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Cause&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;The causes of this issue vary. The basic explanation is that when oobprov.exe is called, if it returns anything other than success, the resulting error message in the AMT logs is ‘Properties Script Failed'.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Resolution&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;See the above two sections for the symptoms No Systems Provisioning and FQDN Not Acquired, but for additional information see the following article:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-external-small" href="http://juice.altiris.com/article/2982/troubleshooting-properties-script-failed-out-band-management-solution"&gt;http://juice.altiris.com/article/2982/troubleshooting-properties-script-failed-out-band-management-solution&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Conclusion&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;This concludes the troubleshooting section for the Provisioning process. For the most common issues, the resolutions and steps presented in the first four parts of this series will resolve them. I also hope the methodology here helps explain how the background processes are working. In the next parts of this series we'll cover troubleshooting issues with the management components after systems have been successfully provisioned.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:cb34e205-ee43-4c63-b8e3-21ac168684f9] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">symantec</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">activation</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">amt</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">intel_amt</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">intel_scs</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">out_of_band_management</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">provisioning</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">server</category>
      <pubDate>Wed, 19 Mar 2008 20:51:48 GMT</pubDate>
      <author>joel_smith1@symantec.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/03/19/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-4-provisioning-server-troubleshooting</guid>
      <dc:date>2008-03-19T20:51:48Z</dc:date>
      <clearspace:dateToText>1 year, 8 months ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/activation/blog/comment/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-4-provisioning-server-troubleshooting</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/activation/blog/feeds/comments?blogPost=10990</wfw:commentRss>
    </item>
    <item>
      <title>Troubleshooting the Altiris Manageability Toolkit for vPro Technology - Part 3 - Provisioning Console Troubleshooting</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/03/18/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-3-provisioning-console-troubleshooting</link>
      <description>&lt;!-- [DocumentBodyStart:66593fb6-eedd-4c37-8a57-0a31f853e68f] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;In part 2 we introduced the Server components used in Provisioning, including some key items to be aware of.  In this installment we'll cover troubleshooting the server components in a symptom - cause - resolution format.  The methodology should also allow help you understand how these components work for further troubleshooting efforts, or for simply understanding how the data is moving through the Provisioning process.  This specific article covers the Console and the common errors that can appear. &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Introduction&lt;/span&gt;&lt;/h1&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Once the server components are installed, and the AMT systems are in a correct Setup Mode, one must access the Provisioning Console to manage the Provisioning process.  This console is located in the Altiris Console under View &amp;amp;gt; Solutions &amp;amp;gt; Out of Band Management &amp;amp;gt; Configuration &amp;amp;gt; Provisioning.  This part of the series covers errors in the console, specifically to common errors scene after the installation has taken place.  These errors can also surface due to environmental changes in the infrastructure.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Symptoms&lt;/span&gt;&lt;/h1&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;This section lists all the symptoms covered in this article.  Use this list to guide you if you are working on a specific issue.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Provisioning Console Access Forbidden - Generally this is a 403 error on most of the Altiris Console Provisioning Nodes&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Provisioning Console Connection Closed - All the Provisioning Nodes show an error that the underlining connection was closed&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Provisioning Console User Not Authorized - This error relates to the access rights to the actual Provision Nodes, and can happen even if a user is an Altiris Administrator&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Provisioning Console Timeouts - We've seen timeouts occur in the console, when accessing the Intel AMT Systems list&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h1&gt;&lt;span&gt;Provisioning Console Access Forbidden&lt;/span&gt;&lt;/h1&gt;&lt;h2&gt;&lt;span&gt;Problem&lt;/span&gt;&lt;/h2&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;When accessing the Provisioning Console, the following error is thrown:&lt;/p&gt;&lt;p&gt;The request failed with HTTP status 403: Forbidden&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-10985-1308/OOBProvCommonError.jpg"&gt;&lt;img height="340" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-10985-1308/620-340/OOBProvCommonError.jpg" width="620"/&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Cause&lt;/span&gt;&lt;/h2&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;When installing Intel SCS, the manual install defaults to HTTPS, using TLS for secure communication.  If the environment is not setup for TLS/HTTPS, the Altiris Provisioning Console will be unable to authenticate to Intel SCS, throwing this error.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Resolution&lt;/span&gt;&lt;/h2&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;On the Notification Server where Intel SCS is installed, open up IIS Manager.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Browse down into the Default Web Site and select AMTSCS.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Right-click on AMTSCS and choose Properties.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Select the Directory Security tab.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Click the Edit button under the Secure communications section.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Uncheck the box labeled ‘Require secure channel (SSL).&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Click OK.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Click Apply and then OK.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h1&gt;&lt;span&gt;Provisioning Console Connection Closed&lt;/span&gt;&lt;/h1&gt;&lt;h2&gt;&lt;span&gt;Problem&lt;/span&gt;&lt;/h2&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The error ‘The Host Name cannot be resolved', or ‘ the remote connection was closed' appear when accessing the Provisioning Console.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-10985-1306/SCSNameNotResolved.jpg"&gt;&lt;img height="319" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-10985-1306/620-319/SCSNameNotResolved.jpg" width="620"/&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The problem can also be seen when using the Test functionality on the DNS Configuration node.  It may show a failed to obtain IP message.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-10985-1307/DNSSCSfailed.jpg"&gt;&lt;img height="310" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-10985-1307/620-310/DNSSCSfailed.jpg" width="620"/&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Cause&lt;/span&gt;&lt;/h2&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;When our Console tries to resolve the name to the Intel SCS Server (even when Altiris and SCS are on the same server) it fails and one of these errors are thrown.  The difference can be in the perceived FQDN for the Server.  Altiris is attempting to acquire the right IP address so it can communicate with SCS.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Resolution&lt;/span&gt;&lt;/h2&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;There are two ways to fix this if a reinstallation does not correctly set the SCS identity within Altiris.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;LMHOSTS or HOSTS files - We can update one or both of these files to contain the FQDN we're using to try and translate the IP Address.  The difficult part is finding out what Altiris is attempting to connect to.  Use the process below to find out what it is looking for:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;See Part 1 concerning the use of OOB trace logging and Debug View.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Enable trace logging in OOB and launch dbgview.exe.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Try to access the console and produce the error.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Stop trace logging.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;This is the difficult part.  Normally I scan through the log looking for the host name of the server.  Usually this shows up as part of an FQDN.  One example of this is Altiris called Servername.domain, which did not respond, but Servername.domain.com was a valid name.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Do a Search for the Host Name of the system (Not FQDN as it may not be using the valid one).  For example, MyServer.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Once complete, access the file named lmhosts (no extension).  Place a line in the file with the Server IP Address and invalid name:&lt;/p&gt;&lt;/li&gt;&lt;ul&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;10.10.10.1     Servername.domain&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Whatever invalid name was located in step 5, the above sequence can be used to give the computer the correct IP Address resolution.  This resolves the issue.  However there may be other steps needed.  If this doesn't resolve the issue, continue to step 8.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Access the Service Location node in the Provisioning Console.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Change the option to ‘Alternate URL:'.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Specify a new location changing the name to one that resolves, for example:&lt;/p&gt;&lt;/li&gt;&lt;ul&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;&lt;span&gt;Previous URL: &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://Servername.domain:80/AMTSCS"&gt;http://Servername.domain:80/AMTSCS&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;&lt;span&gt;Fixed URL: &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://Servername.domain.com:80/AMTSCS"&gt;http://Servername.domain.com:80/AMTSCS&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Click Apply to save the changes.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The difficult part in this process is locating what Altiris believe the name of the Intel SCS Server is.  Since Altiris and SCS are not integrated, they do not have a mechanism that shows if they are on the same server or not.  This is why this issue surfaced.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Provisioning Console User Not Authorized&lt;/span&gt;&lt;/h1&gt;&lt;h2&gt;&lt;span&gt;Problem&lt;/span&gt;&lt;/h2&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;After installation or after credential changes the typical error structure appears with the message: &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Current User can't view this page.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Current user can't change settings on this page.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Note that the error does not have the Red error typically associated with other console errors.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-10985-1309/ProvConsoleRights.jpg"&gt;&lt;img height="375" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-10985-1309/620-375/ProvConsoleRights.jpg" width="620"/&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Cause&lt;/span&gt;&lt;/h2&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;After installation only the user who conducted the Intel SCS install has rights to the console nodes.  Until other users are added, only this user (usually the Notification Server Application identity) has rights to these nodes.  Notification Server role and scope security does not apply to the populating of the data to the right of these nodes (although it does control access to actually showing the nodes themselves in the left-hand tree).&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Resolution&lt;/span&gt;&lt;/h2&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Follow these steps to give the necessary users rights to the Provision Console nodes:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Log into the Altiris Console as the Notification Server Application Identity, or the user used to manually install Intel SCS (one of these will usually be the authorized user).&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Access the Altiris Console under View &amp;amp;gt; Solutions &amp;amp;gt; Out of Band Management &amp;amp;gt; Configuration &amp;amp;gt; Provisioning &amp;amp;gt; Configuration Service Settings &amp;amp;gt; Users.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Note the users who already have rights.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Click the blue + icon to add a user.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Click the ... browse icon to see a typical Notification Server Domain user and groups search window.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Add a group or user and click OK.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Under the Role: give Enterprise Administrator rights unless you want to limit which nodes are operable.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Click OK to complete adding the user.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;If no user can access these nodes, the Intel SCS installation needs to be run again under the correct user.  Run through these steps to complete this:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Log onto the Notification Server directly (or with the /console switch if you're using Remote Desktop) with the NS Application Identity.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;In Add/Remove Programs, locate ‘Intel® Active Management Technology Setup and Configuration Service and remove it.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;On the Notification Server, browse to &lt;em&gt;install_path&lt;/em&gt;\Program Files\Altiris\Notification Server\NSCap\Bin\Win32\X86\OOB\IntelSCS\.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Launch the file AMTConfServer.exe and walk through the install.  Be sure to use the Application Identity as the credentials for SCS.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;When prompted for the database credentials, if permissible use the Application Identity.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Once completed log into the Altiris Console with the Notification Server Application Identity, then move back to step 1 of the previous sequence to add other users as necessary.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h1&gt;&lt;span&gt;Provisioning Console Timeouts&lt;/span&gt;&lt;/h1&gt;&lt;h2&gt;&lt;span&gt;Problem&lt;/span&gt;&lt;/h2&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Even in small environments we've seen timeouts on the Intel AMT Systems node, and much less frequently on the other nodes.  The timeout throws a .NET error and the page is replaced by a timeout error.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Cause&lt;/span&gt;&lt;/h2&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The cause is not known at this time.  The timeouts do not seem to occur always at particularly busy times for the Notification Server, so it is difficult to know what causes them.  When there are plenty of resources available the timeouts generally do not occur, though if the server is extremely busy it doesn't always occur.  It appears to be caused by varying factors.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;A refresh after the timeout error often loads the page just fine.  This suggests the loading the page gets into a loop or hung state, instead of a true processing timeout issue.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Resolution&lt;/span&gt;&lt;/h2&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;No full resolution is known at this time, but a few items can help minimize the impact of the issue.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Remote Consoles - We've seen remote consoles perform better than having the console loaded directly on the Notification Server&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Refresh - Normally the timeouts occur without loading any of the frames within the page.  If you click on the link or hit the refresh for the Intel AMT Systems page and no frames load within a minute, refresh the page.  Often when the page is refreshed it then loads correctly, even quickly.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h1&gt;&lt;span&gt;Conclusion&lt;/span&gt;&lt;/h1&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Once the console has been restored, the Provisioning process can be configured and initiated.  Because of the all or nothing nature of most of these issues, they must be overcome before even being able to properly setup and configure Intel SCS for the Provisioning process.  The above resolutions cover the methods used to resolve these issues at multiple sites.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:66593fb6-eedd-4c37-8a57-0a31f853e68f] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">activation</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">amt</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">intel_amt</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">intel_scs</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">out_of_band_management</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">provisioning</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">server</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">vpro</category>
      <pubDate>Tue, 18 Mar 2008 16:05:26 GMT</pubDate>
      <author>joel_smith1@symantec.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/03/18/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-3-provisioning-console-troubleshooting</guid>
      <dc:date>2008-03-18T16:05:26Z</dc:date>
      <clearspace:dateToText>1 year, 8 months ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/activation/blog/comment/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-3-provisioning-console-troubleshooting</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/activation/blog/feeds/comments?blogPost=10985</wfw:commentRss>
    </item>
    <item>
      <title>Troubleshooting the Altiris Manageability Toolkit for vPro Technology - Part 2 - Provisioning - Intro to Server Components</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/03/14/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-2-provisioning-intro-to-server-components</link>
      <description>&lt;!-- [DocumentBodyStart:4279cad2-da0a-4ffd-a2bd-6df2f33d44ef] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;In part 1 of this series we covered troubleshooting the local AMT client system. In this part we'll discuss the server components as part of the provisioning process. Learn how the symptoms pinpoint each components, and what methods reveal the source of the problem. Learn how Out of Band Management handles the Hello Packets in conjunction with the Intel SCS Component.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Introduction&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;Provisioning isn't a single road. There are two primary paths to reaching a provisioned state, not counting the simple ‘Small Business Mode'. Pre-shared Keys (TLS-PSK) and Remote Configuration (certificate-based TLS) provide two methods for authenticating with the Provision Server and receiving a Profile to set it into a Provisioned state. Understanding the server components is essential to properly diagnosing and troubleshooting problems with the process. Part 3 of this series will cover the symptoms and their likely causes, including troubleshooting details.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The following components integrate in the following manner:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-10980-1301/oobcomponentintegration.jpg"&gt;&lt;img height="495" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-10980-1301/620-495/oobcomponentintegration.jpg" width="620"/&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Out of Band Management&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;Out of Band Management contains 3 main components, with further components broken down as shown here:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Out of Band Management Solution - This is the main NS installer&lt;/p&gt;&lt;/li&gt;&lt;ul&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;NS-based Tasks and Agents&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;Provisioning Console Nodes&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Out of Band Setup and Configuration - This is a wrapper for the Intel SCS install&lt;/p&gt;&lt;/li&gt;&lt;ul&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;Creates the files used for the Intel SCS installation&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Intel SCS Component - This is Intel code for interacting with AMT systems&lt;/p&gt;&lt;/li&gt;&lt;ul&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;AMTConfig Service&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;IntelAMT database&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;h1&gt;&lt;span&gt;Out of Band Management Solution&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;The installer for this Solution creates the Altiris Console pages and underlining code that intersect directly with the Intel SCS component. Consider those pages as hooks into Intel SCS. Intel SCS can install without Out of Band Management. Everything located in the Altiris Console at View &amp;amp;gt; Solutions &amp;amp;gt; Out of Band Management &amp;amp;gt; Configuration &amp;amp;gt; Provisioning ties directly through the AMTSCS web service to access the IntelAMT database (with the exception of DNS Configuration, Service Location, and Delayed Provisioning).&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;This installer also creates the Tasks, Packages, and Agents used for Out of Band Management, including:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Out of Band Discovery - This is an EXE that uses the standard NS Software Delivery to detect the presence of AMT and pull certain data out, including the UUID. This is used heavily for FQDN mapping and is an important part of the best provisioning method.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Out of Band Task Agent - This agent installs like any other Altiris Agent subagent. It's used to function with ASF, or to restart the Hello Packet sequence with Delayed Provisioning in Remote Configuration.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Delayed Provisioning Task - This restarts the Hello Packet sequence, and requires the Out of Band Task Agent.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Collections and Packages - Collections and Packages for the above items.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Oobprov.exe - This is the Provisioning agent that assists the SCS in provisioning AMT client systems.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Important points:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Out of Band Management NS items will work without IntelSCS, but the Provisioning nodes require Intel SCS to be installed and properly configured. &lt;br/&gt;&lt;br/&gt;&lt;span&gt;!&lt;/span&gt;&lt;a class="jive-link-external-small" href="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1300/ProvisioningTree.jpg"&gt;http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1300/ProvisioningTree.jpg&lt;/a&gt;&lt;span&gt;!&lt;/span&gt;&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Installed Alone most of the above nodes will not function. The default error shown here will show with ANY problem:&lt;/p&gt;&lt;/li&gt;&lt;ul&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;Error connecting to the Intel® AMT Setup and Configuration Server. Verify that Intel® AMT Setup and Configuration Service security settings are configured and AMTConfig service is running. See documentation for details on troubleshooting the Intel® Setup and Configuration Server Installation.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;The error always has a second bullet point, with another warning box containing additional bullets. These usually give a more specific message concerning the problem. I've rarely found that the message above accurately points to the source of the problem. See this screenshot for an example:&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-10980-1304/OOBProvCommonError.jpg"&gt;&lt;img height="340" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-10980-1304/620-340/OOBProvCommonError.jpg" width="620"/&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Out of Band Setup and Configuration&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;This installer is truly just a wrapper for the Intel SCS installation. It does provide a crucial function. It lays down the following folder structure where the Intel SCS Component is installed from:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;em&gt;Install_path&lt;/em&gt;\Program Files\Altiris\Notification Server\NSCap\Bin\Win32\X86\OOB\IntelSCS&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The installer does make an automatic attempt to install Intel SCS using the script located at the above location named InstallWithDefaultSettings.cmd. This install makes the following assumptions:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;The SQL database server and instance is the same one the Notification Server is using&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;The AMTConfig service account will run under the Altiris Application Identity credentials&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;The Database install and user will be the Altiris Application Identity Account&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;The Default Web Site is available for install of the AMTSCS virtual directory&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h1&gt;&lt;span&gt;Intel SCS Component&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;The Intel Setup and Configuration Service component is provided by Intel and supported by Altiris\Symantec. This includes the following components:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;IntelAMT database - Like the Altiris database, the IntelAMT database is the backbone of the SCS component. The following items are included in the database:&lt;/p&gt;&lt;/li&gt;&lt;ol&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;Hello packet data&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;Queues for Provisioning and Maintenance actions&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;Settings for SCS&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;Security keys&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;AMT machine data&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;AMT Profiles&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;AMTConfig Service - This service is the piece that talks to the AMT systems and processes items in the database queues. It also calls oobprov.exe to assist in provisioning, primary to obtain the FQDN for the system.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;AMTSCS Virtual Directory - In IIS SCS creates a virtual directory that contains the interfaces Out of Band Management Console uses to connect to the IntelAMT database. It's simple structure belies the importance of this interface.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Keep in mind the following:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Failures to install are almost always security related. See the below ‘Install' section for more information.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;The IntelAMT and Altiris databases are required to be installed to the same SQL instance for Resource Synchronization to work (Resource Synch is the process of importing AMT systems from SCS to NS. In cases where a system is already managed by NS, the data will be merged in the existing NS record)&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;&lt;span&gt;Install&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;Often when you install Out of Band Management Solution or the Altiris Manageability Toolkit for vPro Technology the assumptions cause the OOBSC component to fail, and a message is thrown giving basic instructions on how to install it manually. In some ways I prefer the manual installation so each setting can be directly controlled. When this happens, it's important to follow these steps to avoid issues:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Log onto the Notification Server with the Application Identity, or if not allowed, log on as the user that has rights to the Notification Server and the SQL Server.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Stop IIS on the Notification Server, shut down all Altiris Consoles, stop the AMTConfig service, and shut down any SQL consoles (SQL Enterprise Studio, Query Analyzer, etc). While this can be difficult to arrange, it ensures all necessary accesses and resources are available.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Launch the installer directly from &lt;em&gt;install_path&lt;/em&gt;\Program Files\Altiris\Notification Server\NSCap\Bin\Win32\X86\OOB\IntelSCS\AMTConfServer.exe&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Follow the onscreen prompts. In the next part we'll discuss a scripted install should this install fail. The scripted install allows greater visibility to the process and shows any errors as they occur.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;&lt;span&gt;Oobprov.exe&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;This component is what is known as the Provisioning Script, or Properties Script. Intel SCS requires a provisioning script in order to conduct Provisioning, and as mentioned earlier this is provided as part of Out of Band Management.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;When the AMTConfig Service receives an incoming hello message, it logs it in, places the provisioning request in the queue, and then calls oobprov.exe. Any message stating ‘Properties Script Failed' means that oobprov.exe did not successfully provision the AMT system.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;AMTSCS Virtual Web-site&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;The web-site is generally invisible to the admin running the Console. It must exist, but otherwise the mechanism is pretty solid. The only exception to this rule is when TLS, or Transport Level Security, is involved or not.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Keep in mind the following:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If you will be using TLS for AMT management, this virtual directory much be set with https for any functionality.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If you will not be using TLS, https cannot be enabled on this virtual directory.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If TLS is not implemented but https is enabled on the virtual directory, the Altiris Console will fail.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If TLS is enabled but https is disabled on the virtual directory, the Altiris Console will fail.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;The default is https enabled when running the SCS install manually.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h1&gt;&lt;span&gt;IntelAMT database&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;Much like the Altiris database is to NS, the IntelAMT database is the backbone of Intel SCS. While all functions in the console are automatically interconnected in the database, understanding some of the important tables can help in the troubleshooting process.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Important tables&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;The following is a list of some of the core tables used by Intel SCS:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;csti_amts - This is the data on the actual AMT system. When looking in the Intel AMT Systems node in the Altiris Console, it is reflecting data from this table.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;csti_configuration - This table holds the core configuration between Out of Band Management and Intel SCS.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;csti_uuid_maps - This maps the UUID (Primary AMT ID) to the FQDN. &lt;br/&gt;&lt;br/&gt;!csti_uuid_maps.jpg!&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;csti_pid_map - This table contains the security key information so that Intel SCS can authenticate to the AMT client systems, and the client systems can initially authenticate with Intel SCS.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;csto_queue_entries - This is the queue wherein Intel SCS processes Provisioning and Maintenance requests.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;csto_delayed_entries - For Provisioning requests that have failed for whatever reason, this queue is used.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h1&gt;&lt;span&gt;Conclusion&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;This introduction to the Server Components will help provide understanding for the moving pieces, and will be heavily referred to in Part 3. Knowing how each component functions will greatly help when walking through the troubleshooting steps, especially on how to identify where the problem is originating from.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:4279cad2-da0a-4ffd-a2bd-6df2f33d44ef] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">intel_amt</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">intel_scs</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">symantec</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">activation</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">out_of_band_management</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">intelamt</category>
      <pubDate>Fri, 14 Mar 2008 17:35:45 GMT</pubDate>
      <author>joel_smith1@symantec.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/03/14/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-2-provisioning-intro-to-server-components</guid>
      <dc:date>2008-03-14T17:35:45Z</dc:date>
      <clearspace:dateToText>1 year, 8 months ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/activation/blog/comment/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-2-provisioning-intro-to-server-components</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/activation/blog/feeds/comments?blogPost=10980</wfw:commentRss>
    </item>
    <item>
      <title>Troubleshooting the Altiris Manageability Toolkit for vPro Technology – Part 1 – Provisioning Client Systems</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/03/12/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-1-provisioning-client-systems</link>
      <description>&lt;!-- [DocumentBodyStart:1a8c8d81-0f6d-44ec-b928-e5478d9b5336] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;*&lt;strong&gt;This is a repost of this article to the Activation section of the Site&lt;/strong&gt;*&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Troubleshooting issues with the Intel® AMT Provisioning process can be a daunting prospect. This series walks through the troubleshooting methods to pinpoint where problems originate and how to fix them. Use Part 1 to troubleshoot the AMT systems when provisioning is not occurring. If the issue is on the client side, this document should provide the tools to diagnose and fix the issue.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Introduction&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;There are several modes a vPro capable system can be in when it arrives at the customer site. The modes are:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;AMT disabled&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;AMT enabled, not in Setup Mode (factory default)&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;AMT enabled, not in Setup Mode (Password has been changed in the MEBx)&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;AMT enabled, in Setup Mode for TLS-PSK&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;AMT enabled, in Setup Mode for Remote Configuration&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;4 and 5 in ‘Hello' Packet Mode disabled&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Each of the modes have their own quirks, and understanding the modes will help determine what state a system is in, and how to change a system from one state to another.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Versioning&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;It is important to understand the different versions of not only the local AMT build, but of Altiris' Out of Band Management with the Intel SCS Component. See the following table:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;table&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;OOBM&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;Intel SCS&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;AMT&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;6.1&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;1.2&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;2.0&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;2.1&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;1.3&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;2.0&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;2.1&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;6.2&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;3.0&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;2.0&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;2.1&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;2.5&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;3.0&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;3.2.1&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;2.0&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;2.1&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;2.2&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;2.5&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;2.6&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;3.0&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Note the following points when working with the different versions:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Versions 2.0, 2.1, 2.5 do not support Remote Configuration&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Versions 2.5 and 2.6 are notebooks&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Versions 2.2 and 2.6 are upgrades to versions 2.0, 2.1 and 2.5 respectively and provide the additional functionality of using Remote Configuration for Provisioning&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Intel SCS version 1.2 was unstable. It's recommended to upgrade to 1.3 or upgrade OOB to 6.2.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Versions 2.2 and 2.6 are not supported for Remote Configuration unless Intel SCS is upgraded to version 3.2.1. Check the following KB articles for more information:&lt;/p&gt;&lt;/li&gt;&lt;ul&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-community-small" href="http://communities.intel.com/index.jspa" title="Gain access, share ideas, and discuss topics with leaders in the technology community."&gt;Intel Communities&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-community-small" href="http://communities.intel.com/index.jspa" title="Gain access, share ideas, and discuss topics with leaders in the technology community."&gt;Intel Communities&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;h1&gt;&lt;span&gt;AMT Setup&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;Each mode for AMT sets the system in a specific state. See the brief descriptions below of how AMT acts in each state:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;AMT disabled - In this situation AMT must be enabled either manually by looking into the Intel MEBx (Ctrl+P at startup) or by using the RCT Tool. The following article covers the use of this tool, including data on the command-line switch that can be used to enable AMT:&lt;/p&gt;&lt;/li&gt;&lt;ul&gt;&lt;li level="2" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-external-small" href="http://juice.altiris.com/article/3612/using-intels-rct-tool-restart-amt-hello-packets-enterprise-provisioning"&gt;http://juice.altiris.com/article/3612/using-intels-rct-tool-restart-amt-hello-packets-enterprise-provisioning&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;AMT enabled, not in Setup Mode (factory default) - This is the required mode to use USB One-Touch for provisioning. If a user or the OEM has logged into the MEBx and changed the password, the system is no longer in factory default and the One Touch method will not work.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;AMT enabled, not in Setup Mode (Password has been changed in the MEBx) - One Touch will not work, but manually entering the PSK or setting into Remote Configuration mode will allow the system to enter Setup Mode.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;AMT enabled, in Setup Mode for TLS-PSK - All Provisioning is encrypted using TLS, however the inner security workings can differ. For Pre-shared Key (known as PID PPS) a public and private key are used. The manufacturer can set a specific PID PPS on the system or a user can auto-generate them. The key is that both the client and server have to have the key in order for authentication to work.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;AMT enabled, in Setup Mode for Remote Configuration - All 2.2, 2.6, and 3.0 version AMT systems come in this mode unless the OEM is explicitly instructed to set it differently. The point of Remote Configuration is to avoid visiting the AMT system in order to get it provisioned for manageability use.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Modes 4 and 5 in ‘Hello' Packet Mode disabled - This is common if the system is not immediately hooked up to the production network. All systems will fall into this state if they transmit the ‘hello' packet for 24 hours.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h1&gt;&lt;span&gt;Troubleshooting Tools&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;Before we get into the actual symptoms, we'll cover the tools used to determine where the problem is coming from. While not easy to use, the logging capabilities allow us to verify if the correct processes are functioning on the local system.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;AMT Logs&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;The Altiris Console has direct ties into the AMT Logs captured in the IntelAMT database as a normal part of operation. The Logging level is set in the Altiris Console under View &amp;amp;gt; Solutions &amp;amp;gt; Out of Band Management &amp;amp;gt; Configuration &amp;amp;gt; Provisioning &amp;amp;gt; Configuration Service Settings &amp;amp;gt; and select General. Debug Warning is recommended so you get both Errors and Warnings.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The logs are accessed from Provisioning &amp;amp;gt; Logs &amp;amp;gt; and select ‘Log'. Entries here will reveal problems during the provisioning process and other Intel SCS functions.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-10974-1292/AMTLogs.jpg"&gt;&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-10974-1292/AMTLogs.jpg"/&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;OOB Trace Logging&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;Out of Band Management has the ability to log trace details to a debugging program. See the following KB article on details on how to set this up:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-community-small" href="http://communities.intel.com/index.jspa" title="Gain access, share ideas, and discuss topics with leaders in the technology community."&gt;Intel Communities&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Trace logging will log everything from console accesses, to oobprov.exe calls from IntelSCS. When oobprov.exe is called, all actions are logged to trace, which can capture problems with the provisioning process.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Wireshark&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;While the two above tools are distinctly for Out of Band Provisioning, Wireshark tells the whole story of what is coming and going across the wire. It's important to know what the AMT clients are sending, especially in the ‘Hello' packet, and what the server is responding with.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Wireshark can be obtained from: &lt;a class="jive-link-external-small" href="http://www.wireshark.org/"&gt;http://www.wireshark.org/&lt;/a&gt;. While this is the recommended tool, any network trace capture program can be used to examine the network traffic between the AMT client and the Provisioning Server.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Altiris Knowledgebase&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;All know errors and issues we've run across have been documented in the Altiris Knowledgebase. If you have a specific error, search in the KB and see if we have a documented fix for it. Access it directly here:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-external-small" href="https://kb.altiris.com/"&gt;https://kb.altiris.com/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Symptoms&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;The following symptoms point to problems with the local AMT system or its ability to communicate to the Provisioning Server so that Provisioning can occur.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;System Missing&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;A common symptom for new AMT client systems is that the system, even if believed to be in Setup Mode, doesn't show up in the Altiris Console under Intel® AMT Systems. The causes vary, but the following methodology should help pinpoint where the problem originates.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Is the system sending ‘Hello' packets? Walk through this procedure to determine if it is or not:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Does the AMT Log contain entries for the system requesting Provisioning? The identifier in the logs is the UUID. One example of an error that would prevent a system from showing up is ‘failed to find PID mapping', meaning the requesting system is trying to authenticate with a PID that the Server does not have. Either import any keys provided by the OEM or other provider, or manually enter in the PID PPS under the ‘Security Keys' section of the Provisioning Altiris Console.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If no entry appears for the system, place Wireshark on both the AMT client and the Server. Now initiate a restart of the ‘Hello' packet sequence by turning the AMT client off and unplugging it from power. Drain the capacitors by pressing the power button while unplugged. Generally the power LED will light for a moment before fading dark. Plug the system back in. Does the Server show hello packets (sending on port 16994, with destination port 9971) coming in from the system?&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If the server doesn't show any incoming ‘Hello' requests, fire up Wireshark on the local system to see if we see any ‘Hello' packets heading out. If they are actively leaving, something is blocking the traffic from reaching the Notification Server. These ports are standard TCP calls. See the next section labeled ‘Provision Server'.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If no ‘Hello' packets are being sent, the system may be in a non-Setup State. At the AMT system access the Intel MEBx by pressing Ctrl+P at startup. Is the password what was setup during Setup Mode, or will it only accept Admin? If none of the valid passwords work, this machine may be in an unworkable state. Unplug the CMOS battery for 15 seconds to put the machine back in Factory Default Mode, and Setup as necessary.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;&lt;span&gt;Provision Server&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;With Wireshark we can prove a system is sending ‘Hello' packets out on the wire. The destination is an important distinction as usually this will be simply the name ProvisionServer. By default, Remove Configuration and TLS-PSK will target the simple name ProvisionServer. It's up to the administrator to properly direct that Hello packet to the Notification Server.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If you ping ProvisionServer from a command-prompt, do you get the IP Address of the Notification Server? A CNAME record needs to be created in DNS to correctly direct the hello packets. Check page 21 of the Admin guide located at this KB article: &lt;a class="jive-link-community-small" href="http://communities.intel.com/index.jspa" title="Gain access, share ideas, and discuss topics with leaders in the technology community."&gt;Intel Communities&lt;/a&gt; for more information.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Another place you can test the DNS functionality is under Provisioning in the Altiris Console. Select the ‘DNS Configuration' node. Click the ‘Test' button to initiate the test. A correct IP Address signifies that DNS is working correctly &lt;em&gt;from the Notification Server&lt;/em&gt;. The ping test is still important to signify that the client can also resolve the name.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-10974-1293/DNSTestError.jpg"&gt;&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-10974-1293/DNSTestError.jpg"/&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If the network cannot support this CNAME, only two methods remain. You can set the Provision Server IP in the MEBx directly. You can also use the RCT tool to simulate the Hello packet and send it to the NS directly (see the previous link to the article on RCT usage).&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h1&gt;&lt;span&gt;Conclusion&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;Part 2 of this series covers the Server components for Provisioning. If you've read all the symptoms and suggestions, you'll note that there is crossover when troubleshooting between the client and the server, regardless of where the problem lies. See Part 2 for the continuation of Provisioning Troubleshooting.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:1a8c8d81-0f6d-44ec-b928-e5478d9b5336] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">provisioning</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">out_of_band_management</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">intel_scs</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">activation</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">setup</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">intel_amt</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/activation/blog/tags">symantec</category>
      <pubDate>Wed, 12 Mar 2008 21:29:44 GMT</pubDate>
      <author>joel_smith1@symantec.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/activation/blog/2008/03/12/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-1-provisioning-client-systems</guid>
      <dc:date>2008-03-12T21:29:44Z</dc:date>
      <clearspace:dateToText>1 year, 8 months ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/activation/blog/comment/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-1-provisioning-client-systems</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/activation/blog/feeds/comments?blogPost=10975</wfw:commentRss>
    </item>
  </channel>
</rss>

