Home > Intel Communities > Open Port IT Community > Intel® vPro™ Expert Center > Microsoft Manageability > Blog > Tags > matt_royer
1 2 3 Previous Next

Microsoft Manageability

41 Posts tagged with the matt_royer tag
0

If you want to have the Intel Manageability Tool Kit interoperate with a vPro client that has been provisioned by Microsoft System Center Configuration Manager SP1, there are two key things you need to do: Configure Manageability Commander to trust the Issuing Certificate Authority of AMT Web Certificates and to authenticate with a Kerberos user that has access to the vPro Client.

Before configuring Manageability Commander, you will need to obtain a copy of the Root Certificate Authority Certificate that the vPro Client AMT Web Server Certificate was issued from. This is the same Certificate Authority that was configured in “Microsoft System Center Configuration Manager Console” -> “Out of Band Component Configuration” -> "Site Database" -> "Site Management" -> "Site" -> "Site Settings" -> "Component Configuration" -> "Out of Band Management" -> "General Tab" -> "Certificate Template".
OOBM_Prop.JPG

If you are issuing AMT Web Server Certificates from a subordinate certificate authority, you should still use the certificate from the Root Certificate Authority the SubCA is chained up to.

Cert1.JPG

 

 

Export a copy of the Root CA

1)   To export of a copy of the Root CA Certificate, you can open your local certificate store, select “Trusted Root Certificate” -> “Certificate” and search for the proper Root CA Certificate. If you do not have the Root CA certificate in your trusted root store, your CA Administrator can obtain a copy for you from the CA by selecting the “Properties” of the Certificate Authority and selecting “View Certificate”.

2)   Once you have the certificate open, select the “Detail” tab and then select “Copy to File”.cert2.JPG

3)   When the “Certificate Export Wizard” appears, click “Next”.
export1.JPG

4)   Select “DER encoded binary X.509(.CER)” and click “Next”.
export2.JPG

5)   Select a location to export the certificate to and then click “Next”.
export3.JPG

6)   On the “Complete the Certificate Export Wizard”, click ‘Finish”.
export4.JPG

 

 

Trusting your Root Certificate Authority in Manageability Commander

Now that you have a copy of the Root CA certificate, you are able to configure Manageability Commander so that it can manage a vPro client provisioned by SCCM.

1)   If you have not already done so, you can download a copy of the Manageability Tool Kit from the following location: http://software.intel.com/en-us/articles/download-the-latest-version-of-manageability-developer-tool-kit/. Follow the onscreen instructions on how to install it.

2)   Once Manageability Tool Kit is install and Manageability Commander is open, select “File” -> “Certificate Manager”.
commander1.JPG

3)   In the “Certificate Manager” window, ensure you delete all other existing certificates by highlighting them and clicking the “Delete” button. After which, select “Import”.
commander2.JPG

4)   Browse for the Root Certificate Authority Certificate you exported (which is the Root CA Certificate that is chained up from your AMT Web Server certificates) and click “Open”.
commander3.JPG

5)   Back in the “Certificate Manager” window, click the “Refresh Displayed Certificates” button. You should now see your CA in the “Trusted Root Certificates” list. Click “Close” to exit the Certificate Manager window.
commander4.JPG

 

 

Adding a Client to Manageability Commander

Once the Root CA certificate has been trusted, you can now add the client (that is provisioned by SCCM) you want to manage via Manageability Commander.

1)   To add the vPro client, select “File” -> “Add” -> “Add Intel® AMT Computer”.
commander5.JPG

2)   When the “Add Intel® AMT Computer” window appears, enter in the full qualified domain name (FQDN) of the client you want to manage. If you want Manageability Commander to use Kerberos authentication of the local user logged, leave the Username and Password blank. If you want to specify a different Kerberos user then the local logged on user, enter in the desired Kerberos user as domain\user and the appropriate password. Click “OK” to close the “Add Intel® AMT Computer” window.
commander6.JPG

3)   Once you have added the vPro client, you should see it in the list of clients to manage. Right click on the client, and select “Connect”.
commander7.JPG

4)   Once connected, you can invoke any of the vPro / AMT use cases that the Manageability Commander Tool supports on the client provisioned and also managed by SCCM.
commander8.JPG

 

 

 

 

Debugging Connection

If you are having connection issue, you can perform some general troubleshoot by viewing the debug information.

1)   To view the debug information, select “Help” -> “Show Debug Information...”
debug1.JPG

2)   Once the “Manageability stack” window opens, you can see additional detail of any issues encountered.
debug2.JPG

 

 

 

 

--Matt Royer

0 Comments Permalink
0

 

Microsoft has just released a hotfix to address AMT 4 / AMT 5 power control within System Center Configuration Manager 2007 Service Pack 1.

 

 

 

 

 

System Center Configuration Manager 2007 (KB957469):

 

  • Description: The Out of Band Power control function does not work for clients that have the Intel AMT 4 or Intel AMT 5 chipset in System Center Configuration Manager 2007 Service Pack 1

  • http://support.microsoft.com/kb/957469

 

 

 

 

Please reference the following WIKI for a comprehensive list of required software bundles and hotfixes for SCCM SP1 and vPro/AMT Out of Band Management: http://communities.intel.com/openport/docs/DOC-1897

 

 

 

 

 

 

 

 

--Matt Royer

0 Comments Permalink
6

Microsoft SCCM 2007 SP1 Intel vPro Training Videos

We’re pleased to announce the availability of Microsoft SCCM 2007 SP1 Intel vPro Training videos. During a recent training event in Redmond, Washington, we had the cameras rolling for this detailed and robust training experience and it is now available for you to experience and utilize.

 

Below is an overview and link for each training section.

 

Introduction

 

Technical overview of Microsoft System Center Configuration Manager 2007 SP1 support of Intel vPro technology with specific focus on supported use cases, provisioning process and infrastructure prerequisites for Intel vPro Out of Band Management.

Lab Module One

 

Configuration steps of Active Directory and PKI infrastructure to support Intel vPro Out of Band Management within Microsoft System Center Configuration Manager 2007 SP1.

Lab Module Two

 

Steps for Microsoft System Center Configuration Manager 2007 SP1 OOB Service Point installation, OOB Component Configuration and Network Discovery for Management Controllers.

Lab Module Three

 

Steps for creating a collection for housing Intel vPro clients and configuring that collection for automatic provisioning of the Out of Band Management Controllers.

Lab Module Four

 

Installation overview for the Microsoft System Center Configuration Manager 2007 SP1 client agent and initiation of Intel vPro client provisioning.

Lab Module Five

 

Technical overview of the Out of Band Management Console, Intel vPro Management Engine Interface and Intel AMT power control via Advertisements.

Lab Module Six

 

Configuration steps of the Intel WS-MAN Translator to support legacy Intel vPro clients (Intel AMT firmware versions less than 3.2.1).

Lab Module Seven

 

Provisioning legacy Intel vPro clients (Intel AMT firmware versions less than 3.2.1) through the Intel WS-MAN Translator using PSK provisioning.

Lab Module Eight

 

Overview of the Intel vPro migration process from the Intel SCS / Microsoft SMS 2003 Add-on to Microsoft System Center Configuration Manager 2007 SP1.

 

Please let us know if you have questions or comments regarding this material.

 

This resource along with other resources on the Intel vPro Expert Center can assist you in answering questions when deploying Intel vPro clients in conjunction with Microsoft System Center Configuration Manager 2007 SP1.

6 Comments Permalink
0

An updated version (release 1.1 - build 552) of the Intel WS-MAN Translator has just been released. Updated features include:

 

  • Provides support for running on 64-bit systems

  • Provides additional translation services for legacy systems such as wireless profiles, and 802.1x.

  • You can upgrade from existing builds by using this VB Script or it can be installed on its own.

 

To download the latest version, please visit: http://software.intel.com/en-us/articles/intel-ws-management-translator

 

 

 

 

 

 

 

 

Upgrading from Intel WS-MAN Translator 1.0 to Intel WS-MAN Translator 1.1 (Build 552)

 

 

To upgrade a previous version of the Intel WS-Man Translator to a newer version, download the Update Translator VBScript and run it in the same folder that the latest Translator MSI is located. This will upgrade your WS-MAN Translator version and keep your previous configuration setting.

 

 

 

Fresh install of the Intel WS-MAN Translator

 

 

 

Generate a Certificate Request on SCCM Server for Intel WS-MAN Translator

 

  1. On the SCCM Server, go to Start > All Programs > Administrative Tools > Internet Information Services (IIS)

  2. Expand Web Sites and Right Click on Default Web Site and select Properties
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1723/GenerateCert1.JPG!*

  3. In the Default Web Site Properties windows Select the Directory Security Tab. In the Secure Communications section, click the Server Certificate button
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1724/GenerateCert2.JPG!

  4. This will launch the Web Server Certificate Wizard. Click Next
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1725/GenerateCert3.JPG!*

  5. In the IIS Certificate Wizard Window, select Create a new certificate . Click Next
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1726/GenerateCert4.JPG!*

  6. Select Send the request immediately to an online certification authority. Click Next
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1727/GenerateCert5.JPG!

  7. Enter a Name for the certificate: WS-MAN Translator Server Certificate. Click Next
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1728/GenerateCert6.JPG!

  8. Enter Organization Information (Organization and Organizational Unit) and Click Next
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1729/GenerateCert7.JPG!*

  9. Enter the Common name: This is the FQDN of your server you are installing the Intel WS-MAN Translator on and should be the same as the FQDN of your SCCM Server. Click Next
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1730/GenerateCert8.JPG!

  10. Enter in your Geographical Information. Click Next
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1731/GenerateCert9.JPG!

  11. Enter 443 for the SSL Port for this web site. Click Next
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1732/GenerateCert10.JPG!

  12. In the Choose a Certification Authority Window, select your issuing Certificate Authority. Click Next
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1733/GenerateCert11.JPG!*

  13. Confirm your request and click Next
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1734/GenerateCert12.JPG!

  14. Once Wizard is complete, click Finished
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1735/GenerateCert13.JPG!*

 

Set Delegation for the SCCM Server

 

  1. On your Domain Infrastructure Image, Click Start > All Programs > Administrator Tools > Active Directory Users and Computers > vprodemo.com > Computers. Right Click on SCCM Server and select Properties.
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11434-1782/Computer.JPG!

  2. Check the box Trust Computer for Delegation and click OK
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11434-1781/delegation.JPG!*
    Note: If you do not allow this, you will need to setup the WS-MAN Translator (during configuration steps) run time account with a user that has permission to the AMT client. At that point the credentials configured in the run time account are used to manage the client for Kerberos authentication.

 

Installing the Intel WS-MAN Translator

 

  1. On the SCCM Server, run the Intel WS-MAN Translator Setup

  2. In the Intel WS-Management Translator setup window, click Next
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1736/Install1.JPG!*

  3. In the Intel WS-Management Translator setup window, click Next
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1737/Install2.JPG!*

  4. During the installation, keep all of the Default settings until installation wizard is complete and install has finished.
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1738/Install3.JPG!
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1740/Install5.JPG!

 

Configuring the Intel WS-MAN Translator

 

  1. Click Start > All Programs > Intel WS-Management Translator > wtranscfg.exe to configure the Translator

  2. In the WS-Translator Configuration Wizard Window, Set common setup accounts, Set TLS/forwarding options, & Set WinRM Options. Click Next
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11641-1935/config1.JPG!*

  3. In the Set initial setup password window, enter the password you configured within SCCM Out of Band Management Properties > Provisioning setting Section > MEBx Account. Click Next
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1719/ConfigTrans2.JPG!*

  4. In the Set Common Pre-Shared Key window, should select a more random and secure PID and PPS for security reasons. Click Next.
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1720/ConfigTrans3.JPG!

  5. In the Import Common Setup Certificate, Click Browse and select the Same Certificate you used in SCCM Out of Band Management Properties > Certificates Section > Provisioning Certificate. Click Next.
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1721/ConfigTrans4.JPG!

  6. In the Select TLS/forwarding options windows, select (default Options): Listening Port: 443 & Forwarding Port: 16993. For the Server Certificate: select the WS-Man Translator certificate created in previous step.
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1722/ConfigTrans5.JPG!

  7. Select Allow Basic Authoziation and Click Finished. Click OK to Restart the Translator Service.
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11641-1936/config2.JPG!

 

Configuring SCCM SP1 to use the Intel WS-MAN Translator

 

  1. Within System Center Configuration Manager Out of Band Management Properties > Provisioning setting Section > AMT Settings. Check the option for Enable support for Intel WS-MAN Translator. Once selected, click Apply.
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1717/ConfigSCCM1.JPG!*

 

--Matt Royer

0 Comments Permalink
0

 

For those that are not aware, our friends at Microsoft maintain a great blog on System Center Configuration Manager. The blog is used by the SMS Writing team to keep you informed about the content they are writing, the availability of new documents, updates to documents, and other news. The blog is also intended to collect feedback from you, their customers, about existing content and what you'd like to see in the future.

 

 

 

 

 

If you haven't already subscribed to the feed, I would highly recommend it. http://blogs.technet.com/wemd_ua_-_sms_writing_team/

 

 

 

 

 

This week they have a great article on "[Quiz Questions for Out of Band Management (AMT)|http://blogs.technet.com/wemd_ua_-_sms_writing_team/archive/2008/10/03/overflow-additional-quiz-questions-for-out-of-band-management-amt.aspx]"; take a couple minutes and check it out.

 

 

 

 

 

--Matt Royer

0 Comments Permalink
2

If you are using SCCM SP1 with AMT 3.2.1 machines (ex: HP7800P) and you see the following error.. this post is for you.

 

 

Here is what MEinfo read back during this state of detection

 

 

If you do, no need to be frustrated, just need to run a couple of steps to get back on the road. You can utilize Matt Royer's blog at Intel AMT 3.2.1 Self-signed certificate issue and working around it for Microsoft System Configuration Manager SP1

 

For me I had to give it a go myself, so Nick & I did the following:

  • secured our SCCM environment

  • borrowed 2 new HP boxes in the box

  • downloaded the vbscript file, wsman translator.

 

After 3 trial runs at it, we captured the video today and here it is. Here are the top things I wish I knew prior to installing:

#1. OOB settings is under component configuration (Under site settings) in SCCM

#2. Having your cert (*.pfx) file downloaded and handy is important (and it's in the dictionary)

#3. Make sure you run the following: winrm set winrm/config/client/auth @{Basic="true"} on the console your running the box on

#4. Be patient - this was the single hardest thing during this process for me..

 

Here's the video.

 

 

My recommendation, if your stuck in this state on your machines, follow Matt's blog, check out my video and then ask if any questions..

2 Comments Permalink
0

 

Microsoft has just released two additional hotfixes that address issues with System Center Configuration Manager SP1 and vPro/AMT Out of Band Management. Please reference the following WIKI for a comprehensive list of required software bundles and hotfixes for SCCM SP1 and vPro/AMT Out of Band Management: http://communities.intel.com/openport/docs/DOC-1897

 

 

 

 

 

System Center Configuration Manager 2007 (KB955355):

 

  • Description: A distinguished name that contains more than 100 characters and that is discovered from Active Directory for an AMT host causes the SMS_EXECUTIVE service to crash in System Center Configuration Manager 2007

  • URL: http://support.microsoft.com/kb/955355

 

 

 

 

System Center Configuration Manager 2007 (KB956337):

 

  • Description: System Center Configuration Manager 2007 Service Pack 1 is unable to remove AMT user ACLs during the provisioning process for AMT 2.x computers

  • URL: http://support.microsoft.com/KB/956337

 

 

 

 

 

 

 

--Matt Royer

0 Comments Permalink
2

Microsoft has just released 2 hotfixes that address issues with System Center Configuration Manager SP1 and vPro/AMT Out of Band Management. Please reference the following WIKI for a comprehensive list of required software bundles and hotfixes for SCCM SP1 and vPro/AMT Out of Band Management: http://communities.intel.com/openport/docs/DOC-1897

 

 

 

 

 

System Center Configuration Manager 2007 (KB954718):

 

 

  • Description: You cannot use the Out of Band Management console in Configuration Manager 2007 to connect to computers that use versions of Intel AMT that are earlier than version 3.2.1

  • URL: http://support.microsoft.com/kb/954718

 

 

 

 

System Center Configuration Manager 2007 (KB955126):

 

 

  • Description: The SMS_Executive service process (Smsexec.exe) in System Center Configuration Manager 2007 may crash if you have Intel AMT-related software installed

  • URL: http://support.microsoft.com/KB/955126

 

 

 

 

 

 

 

 

--Matt Royer

2 Comments Permalink
0

When you install the Intel WS-MAN Translator, by default it will provide a PSK PID/PPS of 4444-4444 0000-0000-0000-0000-0000-0000-0000-00000. Although easy to remember, it not necessarily the most secure. If you do not have a unique PID/PPS generated for your environment, you can leverage the USBFILE utility availible in the AMT Software Development Kit (SDK) to generate a secure and unique PID/PPS. USBFile.exe is located in the .\Windows\Intel AMT SDK\Bin\Configuration\ConfigScripts directory of the AMT Software Development Kit download file.

 

 

 

 

 

Consideration: The Intel WS-MAN 1.0 only supports the use of 1 PID/PPS pair. So that you can provision AMT clients using PSK after a partial un-provision, it is recommended that you use the same PID/PPS pair throughout your Environment.

 

 

 

 

 

Generating an unique PID/PPS with USBFile for the Intel WS-MAN Translator

 

  1. Execute usbfile -create setup.bin admin <new MEBx Password> -gen 1 -xml pidpps.txt
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1743/1.JPG!*
    Note: <new MEBx Password> is what you want the MEBx password to be. If you using the Intel WS-MAN Translator with SCCM, this should be the same password you configured within SCCM Out of Band Management Properties > Provisioning setting Section > MEBx Account.
    Note: Running the USBFILE command will generate a setup.bin file; however, this setup.bin is set to consumable and can only be used once. Please reference the instructions below on how to create a non-consumable setup.bin with your unique PID/PPS

  2. After the command has been executed, you can view the generated PSK PID/PPS pair in the pidpps.txt file.
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1744/2.JPG!

  3. This PID/PPS pair can then be configured in the Intel WS-MAN Translator by running Start > All Programs > Intel WS-Management Translator > wtranscfg.exe. Navigate to the Set Common Pre-Shared Key screen and enter in the PID/PPS that you generated. Click Finished and then OK to Restart the Translator Service.
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1745/3.JPG!

 

 

 

 

 

 

 

Generating a non-consuming setup.bin for One Touch Provisioning

 

  1. Execute usbfile -create setup.bin admin <new MEBx Password> -pid <PID> -pps <PPS> where PID and PPS are the unique ones you generated for your environment.
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1746/4.JPG!*
    This will create a file called setup.bin in the working directly that you ran usbfile.exe
    Note: <new MEBx Password> is what you want the MEBx password to be. If you using the Intel WS-MAN Translator with SCCM, this should be the same password you configured within SCCM Out of Band Management Properties -> Provisioning setting Section -> MEBx Account.

  2. Using the USB Key Provisioning Utility, you can create a properly formatted USB Key loaded with the setup.bin file that can be used for One Touch Provisioning.
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1742/5.JPG!

 

 

 

 

--Matt Royer

0 Comments Permalink
5

Note:  The Self Signed Certificate issue was corrected with AMT firmware 3.2.2.  Please work with your OEM to secure the 3.2.2 firmware update.  -- Matt Royer

 

Summary

An issue has been identified that may cause the remote configuration provisioning process to fail when using Microsoft System Center Configuration Manager (SCCM) on systems that have been upgraded from Intel AMT 3.x firmware to 3.2.1 firmware. The Self-signed certificate used to establish the initial PKI provisioning (Remote Configuration) connection is being read as invalid, which causes this failure.

 

The recommended resolution is to perform a provision and un-provision of the system to regenerate the Self-signed certificate. This resolves the certificate being read as invalid and prepares the PC to be provisioned successfully by SCCM. This can be accomplished locally at the PC or remotely from the console. Both scenarios are documented in detail below but local provision/un-provision will require entering the Management Engine BIOS Extension (MEBx) screen at the local machine. To perform this action remotely, the community has developed a software-based script to execute a remote provision/un-provision. The script should be run for vPro clients experiencing this issue prior to SCCM provision. Once the script is executed, the vPro clients can then be natively provisioned by SCCM.

 

 

 

 

 

Background
vPro Clients that are experiencing the issue will show up as AMT Status "Detected" within the Collection View after a Management Controller discovery and will exhibit with the following error in the amtopmgr.log:

 

During SCCM Management Controller Discovery
Error 0x80090308 returned by InitializeSecurityContext during follow up TLS handshaking with server.
Error 0x6fcb970 returned by ApplyControlToken
*During a SCCM Provisioning attempt*
Error 0x80090308 returned by InitializeSecurityContext during follow up TLS handshaking with server.
Error 0x261b948 returned by ApplyControlToken

Note: An AMT Status of "Detected" can occur for a variety of reasons; in general it means that the SCCM Out of Band Service Point is unable to establish an initial connection with the AMT client. This scenario can also occur when the computer has been previously provisioned for AMT outside Configuration Manager and the password for the AMT Remote Admin Account or the MEBx Account has been changed and is unknown.

When trying to provision a vPro Client that has a firmware version less than 3.2.1 that is impacted with the Self-signed Certificate issue, SCCM will forward the request to the Intel WS-MAN Translator (which is required for provisioning and management of a vPro Client less than 3.2.1.) The Intel WS-MAN Translator will handle provisioning the vPro client despite the invalid Self-signed Certificate. The steps listed below should not be required for firmware versions less than 3.2.1 if you have the Intel WS-MAN Translator installed and properly configured.

 

As an interim workaround for vPro Clients 3.2.1 experiencing the issue, you can either locally (through the MEBx) or remotely provision and un-provision the AMT client. The un-provisioning process will regenerate a new Self-signed Certificate within the AMT Management Engine, after which, SCCM can natively use this newly generated certificate to establish the initial secure connection during the provisioning process.

 

Provisioning via Pre-Shared Key (PSK) is not impacted by the Self-signed Certificate issue; however, to leverage PSK provisioning you will need to install / configure the Intel WS-MAN Translator and load the PID/PPS pair into the vPro client. PID/PPS configuration within the vPro client requires either manual configuration via Management Engine BIOS Extension (MEBx) or One Touch Provisioning through USB key import.

 

 

 

 

 

 

 

Local Provision / Un-provision

To performing a Provision / Un-provision locally on the vPro Client

 

  1. Log into the MEBx by pressing Ctrl-P during POST

  2. If you have not changed the default admin password already, login in with "admin" as the password. If you have already changed the MEBx password, log in with the password you changed it to

  3. Within the MEBx Menu, select "Change Intel(R) ME Password".

    1. When presented with "Intel (R) New ME Password", Enter in the same password you configured in SCCM Component Configuration -> Out Of Band Management -> General Tab -> MEBx Account.

    2. When presented with "Verify Password", re-enter the password.

  4. From the MEBx Menu, select "Intel(R) AMT Configuration"

  5. Within the Intel(R) AMT Configuration Menu, select "Provision Model"

    1. When presented with "Change to Intel(R) AMT 1.0 Mode: (Y/N)", enter "N"

    2. When presented with "Change to Small Business : (Y/N), enter "Y"

  6. When returned to the Intel(R) AMT Configuration Menu, select "Unprovision"

    1. When presented with "Reset Intel(R) AMT Provisioning: (Y/N), enter "Y"

    2. When presented, ensure you select "Full Unprovision" and press enter

  7. When returned to the Intel(R) AMT Configuration Menu, select "Return to Previous Menu"

  8. When returned to the MEBx Menu, select "Exit"

    1. When presented with "Are you sure you want to exit: (Y/N)", enter "Y"

  9. Allow vPro Client to reboot fully

 

After performing the local Provision / Un-provision, you should be able to do a rediscovery of the Management Controller within SCCM and see that the AMT Status is now reflected as "Not Provision". With the vPro Client in a "Not Provision" state, SCCM will be able to natively provision the client without issues. Although fairly simplistic, one of key disadvantages of locally provisioning and un-provisioning the vPro Client is that you will need to have physical (touch) access.

 

 

 

 

 

 

 

Remote Provision / Un-provision

To perform a Provision / Un-provision remotely on the vPro Client, the community has created a visual basic script that will perform the function remotely. In an attempt to reduce the complexity, the VBScript leverages the Intel WS-MAN Translator to provide the authentication and remote configuration connection. To leverage this remote Provision/Un-provision capability, you must have the Intel WS-MAN Translator installed and configured prior to executing the VBScript. Please visit the following Blog to learn how to install and configure the Intel WS-MAN Translator.

 

The VBScript and guide can be download from the following location (http://communities.intel.com/docs/DOC-1850) and contents can be decompressed to a folder on either your SCCM server or on workstation that you want to run the script from. Please note that you must have WINRM basic authentication switched to "true" on the computer you are planning to run the VBscript from; WINRM Basic Authentication is required for connections to the Intel WS-MAN Translator to work properly. To turn WINRM Basic Authentication to true, run the following command from the command line:

 

winrm set winrm/config/client/auth @{Basic="true"}



 

 

 

With the archive file decompressed, you will see two VBScripts in the folder: SelfSignedFix.vbs and ExecFromCollection.vbs. SelfSignedFix.vbs is the VBScript that will perform the remote Provision / Un-provision. To use the SelfSignedFix.vbs, there are several parameters you must supply for it to work properly:

 

  • Intel WS-MAN Translator URL: This is the secure URL on which the Intel WS-MAN Translator is listening

  • The Hostname, FQDN, or IP Address of the vPro Client: This is the vPro Client that is having the issue with the Self-signed Certificate and needs to be Provisioned / Un-provisioned

  • Log File Location: This is the folder or share where the results of the provision / un-provision will be logged for the client. Note that SelfSignedFix.vbs script will automatically create a new log with the filename of the hostname, FQDN, or IP Address you used as the previous parameter.

  • Screen Output: Whether (Y) or not (N) to display the Provisioning / Un-provisioning output on the console screen.

 

Critical Note: Prior to executing the SelfSignedFix.vbs, it is imperative that you change the MEBx password in the SelfSignedFix.vbs VBScript to match what is configured in SCCM Component Configuration -> Out Of Band Management -> General Tab -> MEBx Account.



 

As a general reference, you can only change the MEBx password remotely once and only if the vPro Client is in a factory default state (never been provisioned). Since this VBScript remotely provisions and un-provisions the vPro client, we must set the MEBx password during this provisioning process. To Change the MEBx password, open SelfSignedFix.vbs with any text editor and modify (line 19) with your environment specific information:

 

 

Const SCCMMEBxPassword = "P@ssw0rd" to Const SCCMMEBxPassword = "<your SCCM MEBx password>"



 

 

 

Note: If you have already changed the MEBx password, the MEBx password will not changed; however, you should still change the SCCMMEBxPassword in SelfSignedFix.vbs VBScript to match your SCCM Configuration in case you run into a vPro Client where you have not changed the MEBx password yet.

 

 

 

With the MEBx Password modified, here are some examples of how the SelfSignedFix.vbs can be run from the command line:

 

 

After running SelfSignedFix.vbs, you should be able to do a rediscovery of the Management Controller within SCCM and see that the AMT Status is now reflected as "Not Provision". With the vPro Client in a "Not Provision" state, SCCM will be able to natively provision the client without issues.

 

 

 

 

Provision / Un-provision Log

Similar to what is displayed in the previous screen shots, a successful remote Provision / Un-provision log will look like the following:

 

**Begin Execution 8/11/2008 8:22:22 PM*************************
Connecting to https://sccmsp1.vprodemo.com/wstrans/setup/eoi20/192.168.0.101/wsman
Setting AMT Clock
Setting HostName
Setting TLS settings
Setting new MEBx Password
CommitChanges
CommitChanges_OUTPUT
ReturnValue = 2057

Unprovision
PartialUnprovision_OUTPUT
ReturnValue = 0
**End Execution 8/11/2008 8:22:30 PM*************************

In an event that vPro Client is inaccessible to be remotely provisioned / un-provisioned, the error log will look like the following:

 

**Begin Execution 8/11/2008 8:22:12 PM*************************
Connecting to https://sccmsp1.vprodemo.com/wstrans/setup/eoi20/192.168.0.100/wsman
Unable to connect to AMT Device: 192.168.0.100
**End Execution 8/11/2008 8:22:12 PM*************************

This error can occur for a variety of reasons. Some common causes of this error are:

 

 

In either case, you will need to root cause why the vPro Client was not remotely accessible to be provisioned / un-provisioned. You can then run SelfSignedFix.vbs at a later time to retry and remotely provision / un-provision.

 

 

 

 

 

 

 

Automating the execution of SelfSignedFix.vbs within SCCM

To avoid having to run SelfSignedFix.vbs on each impacted system individually, there are a couple of automated procedures you can perform depending on what is right for your environment. To identify and isolate the vPro Clients that are impacted by the invalided Self-signed Certificate, you can create a SCCM Collection using the following criteria "Select * from sms_r_system where AMTStatus=1"; this will automatically bucket all the vPro Clients listed as AMTStatus Detected in a single collection for easy identification.

 

 

For step by step instructions on how to create the collection for vPro Clients with the AMT Status of Detected, please reference the guide included with the scripts.

 

 

Once you have the impacted vPro Clients in a single collection, you can either use SCCM Advertisements to push and execute SelfSignedFix.vbs from the client or you can use the included ExecFromCollection.vbs to connect directly to collection and execute SelfSignedFix.vbs on an enumerated list of members in that collection.

 

 

Critical Note: Before proceeding to use one of these large execution methods, it is recommended that you test your configuration (both SelfSignedFix.vbs and Intel WS-MAN Translator) by testing on a few impacted system individually first. Once you run SelfSignedFix.vbs steps above on these select impacted vPro Clients, you need to ensure you are able to natively provision the client within SCCM before you move onto a more automated implementation.



 

 

 

 

 

Using ExecFromCollection.vbs

ExecFromCollection.vbs is a VBscript that will connect to a desired collection, enumerate the list of members in the collection, and execute SelfSignedFix.vbs VBScript against each member in the collection. Prior to using ExecFromCollection.vbs, you must first change the SMSSiteCode, SMSServer, SMSCOLLECTION, and WSTransURL constants. To modify the required constants, open up ExecFromCollection.vbs with any text editor and change the following values with entries specific to your environment (Make sure you save your changes).

 

  • SMSSITECODE : This is your SMS Site Code

  • SMSSERVER : This is the FQDN of you SMS Site Server

  • SMSCollection : This is the SMS Collection ID that you want to enumerate the list of vPro Clients from. You can find the Collection ID of a particular collection by right clicking on the collection and select "Properties"; the Collection ID will be at the bottom of the General Tab
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11443-1774/9.JPG!

  • WSTransURL : This is the secure URL in which the Intel WS-MAN Translator is listening on

 

 

Once the constants have been modified within ExecFromCollection.vbs, you can execute the VBscript by running the following Command Line:

 

cscript ExecFromCollection.vbs



ExecFromCollection.vbs will cycle through each enumerate member in the collection and execute SelfSignedFix.vbs VBScript against it. Prior to running ExecFromCollection.vbs, you need to ensure that the SelfSignedFix.vbs VBscript and ExecFromCollection.vbs VBscript are located in the same folder.

 

After running ExecFromCollection.vbs VBscript, you should be able to do a rediscovery of the Management Controller within SCCM and see that the AMT Status is now reflected as "Not Provision". With the vPro Client in a "Not Provision" state, SCCM will be able to natively provision the client without issues. For any vPro Clients that remain in a Detected state, review the log files to help isolate the root of their issue. For step- by-step instructions on using ExecFromCollection.vbs, please reference the Guide included in the download package.

 

 

 

 

Using SCCM Advertisement to Execution SelfSignedFix.vbs

In terms of leveraging SCCM Advertisements to push the SelfSignedFix.vbs down to the client and execute it, there are several different ways this could be done. This example simply pulls the SelfSignedFix.vbs off a remote share which is then executed by a SCCM Task Sequence. When the advertisement is picked up by the SCCM Client Agent, the task sequence is executed and SelfSignedFix.vbs is run on the vPro Client machine. Depending on your environment, you may want to leverage alternative methods of deploying and executing this with a SCCM Advertisement. Please note, that the SelfSignedFix.vbs is not performing any provision / un-provision commands locally on the client; although it is running on the local client, the provision / un-provision commands are being routed to the Intel WS-MAN Translator and then the commands are sent back down to the vPro client from the Intel WS-MAN Translator.

 

  1. In preparation of creating a task sequence, create a remote share on a server where the SelfSignedFix.vbs will be run from and the log files generated from SelfSignedFix.vbs will be stored. Ensure sufficient permissions are granted to the account running the advertisement.

  2. Create a New Task Sequence and give it a name that is easily recognizable. Make sure you create the Task Sequence with the option of "Create a new custom task sequence".

  3. When you edit your task sequence, add a new "General"-> "Run Command Line" task.

  4. Give the task an appropriate name and in the Command Line field enter in:
    cscript
    server\share\SelfSignedFix.vbs %COMPUTERNAME% "
    server\share" N
    ... where
    server\share is the remote share that you created and https://wsmantransurl/ is the secure URL of your Intel WS-MAN Translator. %COMPUTERNAME% is an OS environment variable that will give you the hostname of the client.
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11443-1766/12.JPG!

  5. Once the task sequence is created, you can advertise the task sequence on a Collection you created for just the AMT Detected vPro Clients.

  6. Depending on your advertisement mandate, the next time the client's SCCM agent pulls down an updated policy it will execute the task sequence.

After running SelfSignedFix.vbs VBscript via the advertisement, you should be able to do a rediscovery of the Management Controller within SCCM and see that the AMT Status is now reflected as "Not Provision". With the vPro Client in a "Not Provision" state, SCCM will be able to natively provision the client without issues. For any vPro Clients that remain in a Detected state, review the log file and isolate the root of their issue.

 

Note: Depending on your Client OS configuration, it may be necessary to set WINRM basic authentication to "true" prior to execution SelfSignedFix.vbs; this can be accomplished by add winrm set winrm/config/client/auth @{Basic="true"} command line task prior to the execution of SelfSignedFix.vbs.

 

This blog was intended to give you a general understanding of the issue and the work arounds that are in place. For a comprehensive step-by-step guide, please refer to the documentation included with Remote Provision / Un-provision Script archive file. To download the Scripts and the Guide, please visit the following URL: http://communities.intel.com/docs/DOC-1850

 

--Matt Royer

5 Comments Permalink
10

As explained in the SCCM SP1 & WS-MAN Translator: How vPro firmware versions less than 3.2.1 are supported blog, The Intel WS-MAN Translator is crucial component to providing support for vPro Client with firmware versions less than 3.2.1 with Microsoft System Center Configuration Manager.

 

Intel has just posted the production release of the Intel WS-MAN Translator 1.0 and is available for download at the following location: http://softwarecommunity.intel.com/articles/eng/3840.htm. At that location you will find the install binaries and documentation on how to install the translator. However, here is a high level overview of how to install and configure the Intel WS-MAN Translator.

 

Pre-installation Steps

 

Generate a Certificate Request on SCCM Server for Intel WS-MAN Translator

 

  1. On the SCCM Server, go to Start > All Programs > Administrative Tools > Internet Information Services (IIS)

  2. Expand Web Sites and Right Click on Default Web Site and select Properties
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1723/GenerateCert1.JPG!*

  3. In the Default Web Site Properties windows Select the Directory Security Tab. In the Secure Communications section, click the Server Certificate button
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1724/GenerateCert2.JPG!

  4. This will launch the Web Server Certificate Wizard. Click Next
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1725/GenerateCert3.JPG!*

  5. In the IIS Certificate Wizard Window, select Create a new certificate . Click Next
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1726/GenerateCert4.JPG!*

  6. Select Send the request immediately to an online certification authority. Click Next
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1727/GenerateCert5.JPG!

  7. Enter a Name for the certificate: WS-MAN Translator Server Certificate. Click Next
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1728/GenerateCert6.JPG!

  8. Enter Organization Information (Organization and Organizational Unit) and Click Next
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1729/GenerateCert7.JPG!*

  9. Enter the Common name: This is the FQDN of your server you are installing the Intel WS-MAN Translator on and should be the same as the FQDN of your SCCM Server. Click Next
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1730/GenerateCert8.JPG!

  10. Enter in your Geographical Information. Click Next
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1731/GenerateCert9.JPG!

  11. Enter 443 for the SSL Port for this web site. Click Next
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1732/GenerateCert10.JPG!

  12. In the Choose a Certification Authority Window, select your issuing Certificate Authority. Click Next
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1733/GenerateCert11.JPG!*

  13. Confirm your request and click Next
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1734/GenerateCert12.JPG!

  14. Once Wizard is complete, click Finished
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1735/GenerateCert13.JPG!*

 

Modifying Windows Remote Management (WinRM) to support Basic Authentication

 

  1. On the SCCM Server, open a command prompt and run the following command: winrm set winrm/config/client/auth @{Basic="true"} (command line is case sensitive)
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1716/WINRM1.JPG!

  2. You should see Basic = True returned

 

Set Delegation for the SCCM Server

 

  1. On your Domain Infrastructure Image, Click Start > All Programs > Administrator Tools > Active Directory Users and Computers > vprodemo.com > Computers. Right Click on SCCM Server and select Properties.
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11434-1782/Computer.JPG!

  2. Check the box Trust Computer for Delegation and click OK
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11434-1781/delegation.JPG!*
    Note: If you do not allow this, you will need to setup the WS-MAN Translator (during configuration steps) run time account with a user that has permission to the AMT client. At that point the credentials configured in the run time account are used to manage the client for Kerberos authentication.

 

 

 

 

Installing the Intel WS-MAN Translator

 

 

 

 

  1. On the SCCM Server, run the Intel WS-MAN Translator Setup

  2. In the Intel WS-Management Translator setup window, click Next
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1736/Install1.JPG!*

  3. In the Intel WS-Management Translator setup window, click Next
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1737/Install2.JPG!*

  4. During the installation, keep all of the Default settings until installation wizard is complete and install has finished.
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1738/Install3.JPG!
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1740/Install5.JPG!

 

Configuring the Intel WS-MAN Translator

 

  1. Click Start > All Programs > Intel WS-Management Translator > wtranscfg.exe to configure the Translator

  2. In the WS-Translator Configuration Wizard Window, Set common setup accounts & Set TLS/forwarding options. Click Next
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1718/ConfigTrans1.JPG!*

  3. In the Set initial setup password window, enter the password you configured within SCCM Out of Band Management Properties > Provisioning setting Section > MEBx Account. Click Next
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1719/ConfigTrans2.JPG!*

  4. In the Set Common Pre-Shared Key window, should select a more random and secure PID and PPS for security reasons. Click Next.
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1720/ConfigTrans3.JPG!

  5. In the Import Common Setup Certificate, Click Browse and select the Same Certificate you used in SCCM Out of Band Management Properties > Certificates Section > Provisioning Certificate. Click Next.
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1721/ConfigTrans4.JPG!

  6. In the Select TLS/forwarding options windows, select (default Options): Listening Port: 443 & Forwarding Port: 16993. For the Server Certificate: select the WS-Man Translator certificate created in previous step. Click Finished. Click OK to Restart the Translator Service.
    !http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1722/ConfigTrans5.JPG!

 

Configuring SCCM SP1 to use the Intel WS-MAN Translator

 

  1. Within System Center Configuration Manager Out of Band Management Properties > Provisioning setting Section > AMT Settings. Check the option for Enable support for Intel WS-MAN Translator. Once selected, click Apply.
    *!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1717/ConfigSCCM1.JPG!*

 

--Matt Royer

10 Comments Permalink
0

 

For those that are not aware, Microsoft has a System Center Configuration Manager 2007 Toolkit that provides some excellent tools to help with troubleshooting, security hardening, and easier log viewing within SCCM.

 

 

 

 

 

To download System Center Configuration Manager 2007 Toolkit, please visit http://www.microsoft.com/downloads/details.aspx?FamilyID=948e477e-fd3b-4a09-9015-141683c7ad5f&DisplayLang=en

 

 

 

 

 

Here are the tools that are included (as documented on Microsoft's Website)

 

  • Client Spy - A tool to help troubleshoot issues related to software distribution, inventory, and software metering on Configuration Manager 2007 clients.

  • Policy Spy - A policy viewer to help review and troubleshoot the policy system on Configuration Manager 2007 clients.

  • Trace32 - A log viewer that provides a way to easily view and monitor log files created and updated by Configuration Manager 2007 clients and servers.

  • Security Configuration Wizard Template for Configuration Manager 2007 - An attack-surface reduction tool for the Microsoft Windows Server 2003 operating system with Service Pack 1 and Service Pack 2 (SP1 and SP2) that determines the minimum functionality required for a server's role or roles, and disables functionality that is not required.

  • DCM Model Verification - A tool used by desired configuration management content administrators for the validation and testing of configuration items and baselines authored externally from the Configuration Manager console.

  • DCM Digest Conversion - A tool used by desired configuration management content administrators to convert existing SMS 2003 Desired Configuration Management Solution templates to Desired Configuration Management 2007 configuration items.

  • DCM Substitution Variables - A tool used by desired configuration management content administrators for authoring desired configuration management configuration items that use chained setting and object discovery.

 

 

 

 

--Matt Royer

0 Comments Permalink
1

 

For those that don't know, you can use the Intel AMT Web console as an alternative to running the out of band management console in Configuration Manager 2007 SP1 to manage vPro computers.

 

 

 

 

On more than a few occasions, people have been experiencing problems with connecting to the vPro AMT Web console after the vPro Client has been provisioned by SCCM. In every case that I have been involved in, it simply comes down to one or two of the following:

 

  • Not having the required HotFix (KB908209) for IE 6 installed and registry entry for both IE6 & IE 7 added

  • Connecting to the wrong URL of the vPro Client

  • Not having the "Enable Web Interface" checked within SCCM "Out of Band Management Properties"

  • Not connecting with a user that has appropriate access

 

 

 

 

 

 

 

Making sure you have KB908209 installed and having the registry key added for Internet Explore

 

 

There is a hotfix released for Internet Explorer 6 that addresses connecting to a web site with Kerberos authentication protocol that uses a non-standard port. Since you are trying to authenticate with Kerberos on a non-standard port when you connect to a vPro AMT Web console, you need this hot fix: http://support.microsoft.com/default.aspx/kb/908209. Keep in mind, besides the hotfix you also need to add a registry entry to allow the hotfix to be active (steps listed in the KB article). Here is the registry entry you need to add.

 

  • For 32 Bit: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INCLUDE_PORT_IN_SPN_KB908209\"iexplore.exe"=dword:00000001

  • For 64 Bit: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INCLUDE_PORT_IN_SPN_KB908209\"iexplore.exe"=dword:00000001

 

Although Microsoft included the hotfix into Internet Explorer 7, you still need to add the registry entry to get the authentication to work. Forgetting to add this registry entry tends to be the number 1 reason why people are having the problem!!!!

 

 

 

 

 

 

 

 

Connecting to the correct URL

 

 

When connecting to vPro AMT Web console, you must connect to the vPro Client with the following URL https://FQDN:16993 where the FQDN is the full qualified domain name of the vPro client (ie. https://vpro-client.vprodemo.com:16993). Using the IP address will not work (or at least you will get a warning about an invalid certificate) because SCCM has configured the vPro client to use TLS and the URL needs to match the certificate that was issued during the provisioning process. As a general reference, 16993 is the port that the TLS web services is listening on and you need connect with https since it's a secure connection

 

 

 

 

 

 

 

 

Ensuring you have "Enable Web Interface" check

 

 

To enable vPro AMT Web console support on the vPro Client, you need to verify that "Enable Web Interface" is checked within the SCCM "Out of Band Management Properties" - "AMT Settings" Tab. With this checked, SCCM (during the provisioning process) will configure the vPro Client to allow vPro AMT Web console access.

 

 

!http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1712/Webui+checked.JPG!

 

 

 

 

 

Make sure you have permission

 

 

Since SCCM only supports Kerberos authentication (with exception of the Remote Admin account, who's password is only known by SCCM), you need to authentication with a Kerberos users that has been granted access to the vPro Client. If you are having problems authenticating, make sure the user you are trying to authenticate with is listed in the AMT User Accounts in the "Out of Band Management Properties" - "AMT Settings" tab.

 

 

 

 

--Matt Royer

1 Comments Permalink
1

As referenced in the Overview of SMS/Intel SCS migration to SCCM SP1 blog post, Intel has developed a utility to easy the migration of vPro Client that have been activated on SMS/SCS to SCCM SP1.

 

The Production version of the Intel SCS to SCCM Migration Utility has been released and will be available for downloaded from the following location shortly: http://softwarecommunity.intel.com/articles/eng/3898.htm

 

A User Guide on how to use the migration utility has been included in the download.

 

--Matt Royer

 

 

1 Comments Permalink
1

Within SCCM there are two primary ways to provision a vPro Client: Using the Import Out of Band Computers Wizard and the In-band provisioning with the Configuration Manager client Agent. Because of the ease and automated provision, it is typically recommended that you leverage the In-band provisioning with the Configuration Manager client agent; however, there may be cases where this method may not work based on your environment or business process. This may leaves you with the only option of using the Import Out of Band Computers Wizard for vPro Client provisioning.

 

To provision clients with Import Out of Band Computer Wizard, you are required to supply at a minimum the Computer Name, FQDN, and UUID for the vPro client you are trying to provision. Hand retrieving and entering this data for a few vPro clients may be fairly straight forward; however, if you are in a scenario where you are trying to provision a large number of vPro clients it may become very time consuming. As part of the Import Out of Band Computer Wizard, you are able to specific a comma-separated values (CSV) formatted file that has these required attributes listed. With this capability available, you can technically mass import a large number of vPro clients to be provisioned; the challenge then becomes automating the retrieval of this Computer Name, FQDN, and UUID.

 

Example CSV File

 

 

 

 

 

 

 

Select Source - Choose Mapping

 

 

Select Source - Data Preview

 

 

Select Source - Summary

 

 

There can be a variety of sources such as the Active Directory, Local Computer Operating System, alternate software inventory agent, etc (your imagination is the limitation) where you could potentially pull this information.

 

 

For example, this UUID Resolver is an example utility that will query your Active Directory for computers, determine if they are vPro Capable, connects to the OS, and Exports the Computer Name, FQDN, and UUID to a CSV files that can be imported through Import Out of Band Computer Wizard; once the hello packet is received, SCCM will provision the vPro Client (Special Thanks to Ariel Toporovsky for developing this example).

 

 

Another example may be to use a Software Agent or other remote execution capability to run a localized VBS, Perl Script, exe, etc that grabs the Computer Name, FQDN, and UUID locally from the client and copies the contents to a remote share to be consolidated; once there it can be imported through the SCCM Import Out of Band Computer Wizard.

 

 

What else can you think of? If you have any thoughts or tricks on how to automate this, please post your idea / exampls in the comments. Thanks.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

--Matt Royer

 

 

1 Comments Permalink
1 2 3 Previous Next