<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Blog Posts From Intel vPro Expert Center Blog Tagged With setup_and_configuration</title>
    <link>http://communities.intel.com/community/vproexpert/blog</link>
    <description>Intel vPro Expert Center Blog</description>
    <pubDate>Thu, 02 Aug 2012 14:03:46 GMT</pubDate>
    <generator>Jive SBS 5.0.2.0  (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2012-08-02T14:03:46Z</dc:date>
    <item>
      <title>Intel® SCS Configurator Command Line Examples</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2012/08/02/intel-scs-configurator-command-line-examples</link>
      <description>&lt;!-- [DocumentBodyStart:21b11cee-c027-4412-b0cf-c004b5a7fecf] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;One of the great tools that comes with the Intel&amp;reg; Setup and Configuration Software is the Configurator tool.&amp;nbsp; It&amp;#8217;s a command line tool that you use to configure AMT on your Intel&amp;reg; vPro&amp;#8482; systems. It&amp;#8217;s designed with the idea of easy packaging and deployment using standard off-the-shelf tools for software deployment.&amp;nbsp; The Configurator is capable of doing quite a few different tasks that help you discover, configure and maintain AMT on your Intel&amp;reg; vPro&amp;#8482; clients.&amp;nbsp; Each of these capabilities has a number of different options you can use to meet specific needs you may have.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;In order to give you a starting point, I&amp;#8217;ve put together a list of some common example command lines that use the configurator to perform a number of common tasks along with brief explanations of what each example will do.&amp;nbsp; You can find detailed information about the command line options in the Intel&amp;reg; SCS documentation.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;You can find the command line examples here: &lt;a class="jive-link-wiki-small" data-containerId="2005" data-containerType="14" data-objectId="19537" data-objectType="102" href="http://communities.intel.com/docs/DOC-19537"&gt;http://communities.intel.com/docs/DOC-19537&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Let me know if there&amp;#8217;s a command line you&amp;#8217;d like to see added to the list.s&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:21b11cee-c027-4412-b0cf-c004b5a7fecf] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">scs</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">setup_and_configuration</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">commandline</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">command_line</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">scs_8.1</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">setup_and_configuration_software</category>
      <pubDate>Thu, 02 Aug 2012 14:03:46 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2012/08/02/intel-scs-configurator-command-line-examples</guid>
      <dc:date>2012-08-02T14:03:46Z</dc:date>
      <clearspace:dateToText>9 months, 2 weeks ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/intel-scs-configurator-command-line-examples</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=15299</wfw:commentRss>
    </item>
    <item>
      <title>NEW! The latest version of Intel® SCS (8.1) is now available!</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2012/07/16/new-the-latest-version-of-intel-scs-81-is-now-available</link>
      <description>&lt;!-- [DocumentBodyStart:bbbf3cd5-afab-4b4f-801a-c8127a736535] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;strong&gt;A new version of Intel&amp;reg; SCS is now available!&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Version 8.1 (&lt;a class="jive-link-external-small" href="http://intel.com/go/scs" target="_blank"&gt;download&lt;/a&gt;) is an update to version 8.0.&amp;nbsp; New installations of SCS do not require 8.0 to be installed first, as 8.1 is a full package.&amp;nbsp; &lt;/p&gt;&lt;p&gt;Interested to see what's new? Watch a &lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/software/scs-8-1-demo.html" target="_blank"&gt;demo of Intel&amp;reg; 8.1&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Version 8.1 Highlights&lt;/strong&gt; &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Windows 8 Professional clients (in legacy desktop mode)&lt;/li&gt;&lt;li&gt;Detection and fix for hostname FQDN mismatches&lt;/li&gt;&lt;li&gt;Discovery and&amp;nbsp; configuration of business Ultrabooks&lt;/li&gt;&lt;li&gt;Migration utilities for SCS 5.x and 8.0&lt;/li&gt;&lt;li&gt;Compatible with AMT 8.1 ME firmware&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Detailed Highlights&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Windows 8 Pro &amp;#8220;metro mode&amp;rdquo; client configuration is not supported at this time.&lt;/li&gt;&lt;li&gt;Hostname FQDN mismatches can be detected by system discovery with the /ReportToRCS parameter.&amp;nbsp; &lt;/li&gt;&lt;li&gt;Ultrabooks without a wired LAN port on their system will be configured over wireless in client control mode.&amp;nbsp; Upgrading to admin control mode requires a PKI certificate, and is supported via the &amp;#8220;movetoacm&amp;rdquo; upgrade process (introduced in SCS 7.1)&lt;/li&gt;&lt;li&gt;Migration utilities include CLI and wizard.&amp;nbsp; Systems provisioned with a management console cannot &amp;#8220;migrate&amp;rdquo; to using SCS with these utilities.&amp;nbsp; The following types of migrations are supported.&lt;/li&gt;&lt;li&gt;Unconfiguration of AMT active directory objects automatically done&lt;/li&gt;&lt;li&gt;Mandatory encryption when creating or editing XML files (non-database mode)&lt;/li&gt;&lt;li&gt;Separate power policy for wireless adapters can be defined&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Where do I download SCS?&lt;/strong&gt; &lt;/p&gt;&lt;p&gt;You can go to the &lt;a class="jive-link-external-small" href="http://intel.com/go/scs" target="_blank"&gt;SCS product page&lt;/a&gt; to obtain the latest version (and download the newly updated product brief).&amp;nbsp; Developers and ISV&amp;#8217;s can obtain the Implementation and Reference Guide and sample code from the &lt;a class="jive-link-external-small" href="http://software.intel.com/en-us/articles/download-the-latest-version-of-intel-amt-setup-and-configuration-service-scs/" target="_blank"&gt;SCS page&lt;/a&gt; on the vPro Developer Community. &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Have feedback? &lt;/strong&gt; &lt;/p&gt;&lt;p&gt;If you have any feedback on SCS, please visit our support community: &lt;a class="jive-link-community-small" data-containerId="2005" data-containerType="14" data-objectId="2387" data-objectType="14" href="http://communities.intel.com/community/vproexpert/intel_setup_and_configuration_software"&gt;Intel&amp;reg; Setup and Configuration Software&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:bbbf3cd5-afab-4b4f-801a-c8127a736535] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">scs</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">setup_and_configuration</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">scs_8.1</category>
      <pubDate>Mon, 16 Jul 2012 15:00:15 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2012/07/16/new-the-latest-version-of-intel-scs-81-is-now-available</guid>
      <dc:date>2012-07-16T15:00:15Z</dc:date>
      <clearspace:dateToText>10 months, 1 week ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/new-the-latest-version-of-intel-scs-81-is-now-available</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=15274</wfw:commentRss>
    </item>
    <item>
      <title>Configuring PCs with Group Policy Objects using Intel® Setup and Configuration Software</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2012/06/05/configuring-pcs-with-group-policy-objects-using-setup-configuration-server</link>
      <description>&lt;!-- [DocumentBodyStart:ba0cf2cf-bc79-433f-9d3f-3d95732f25db] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;Need to configure AMT machines within your environment but don't have a Independent Software Vendor (ISV)?&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Here is another way you can configure your AMT machines without haveing a software deployment tool.&amp;nbsp; As long as your organization has Active Directory set up, you can follow the instructions for SCS to install your configuration server. Once that is configured, you can use Group Policy Object's Start Up Scripts to deploy SCS Discovery which will determine what AMT platforms you have in your environment and how they are set up.&amp;nbsp; Once that can be determined, the machines not configured can be configured with a SCS profile in admin or client control mode.&amp;nbsp; Then maintenance can be run on the clients.&amp;nbsp; By using the GPO's startup script, the account being used is the computer's system account. This helps if users in the environment do not have full administrative rights to their computer.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;To get more details on this UCRD:&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 14pt;"&gt;Download Here: &lt;a class="jive-link-external-small" href="http://downloadcenter.intel.com/Detail_Desc.aspx?agr=Y&amp;amp;DwnldID=21363" target="_blank"&gt;Setup and Configuration with Intel SCS 8 and Microsoft Active Directory&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 14pt;"&gt;&lt;br/&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;For more information on Intel&lt;span style="color: #666666; font-family: intel-neo-sans-1, intel-neo-sans-2, tahoma, helvetica, sans-serif; background-color: #ffffff;"&gt;&amp;reg;&lt;/span&gt; Setup and Configuration Software&amp;nbsp; 8.0, visit &lt;a class="jive-link-external-small" href="http://www.intel.com/go/scs" target="_blank"&gt;www.intel.com/go/scs&lt;/a&gt; or the &lt;a class="jive-link-community-small" data-containerId="2005" data-containerType="14" data-objectId="2387" data-objectType="14" href="http://communities.intel.com/community/vproexpert/intel_setup_and_configuration_software"&gt;Intel Setup and Configuration Software Community&lt;/a&gt;. You can also find more Use Case Reference Designs here: &lt;a class="jive-link-wiki-small" data-containerId="2005" data-containerType="14" data-objectId="4080" data-objectType="102" href="http://communities.intel.com/docs/DOC-4080"&gt;Use Case Reference Designs for Intel vPro Technology&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:ba0cf2cf-bc79-433f-9d3f-3d95732f25db] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">scs</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">provision</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">setup_and_configuration</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">scs_8.0</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">corevpro</category>
      <pubDate>Tue, 05 Jun 2012 13:05:59 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2012/06/05/configuring-pcs-with-group-policy-objects-using-setup-configuration-server</guid>
      <dc:date>2012-06-05T13:05:59Z</dc:date>
      <clearspace:dateToText>11 months, 2 weeks ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/configuring-pcs-with-group-policy-objects-using-setup-configuration-server</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=15216</wfw:commentRss>
    </item>
    <item>
      <title>New Troubleshooting guide for vPro integration in Symantec Management Platform 7.0 available</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2010/11/03/new-troubleshooting-guide-for-vpro-integration-in-symantec-management-platform-70-available</link>
      <description>&lt;!-- [DocumentBodyStart:4ed11137-9357-451a-9bb2-1d57d97b0b5e] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;New Troubleshooting guide for vPro integration in Symantec Management Platform 7.0 available:&lt;/p&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" data-containerId="10313" data-containerType="2020" data-objectId="5754" data-objectType="102" href="http://communities.intel.com/docs/DOC-5754"&gt;http://communities.intel.com/docs/DOC-5754&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;This guide covers the following Symantec technologies for both setup and configuration, and usage for vPro (AMT):&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Notification Server&lt;br/&gt;&lt;/li&gt;&lt;li&gt;Task Server&lt;br/&gt;&lt;/li&gt;&lt;li&gt;Out of Band Management&lt;br/&gt;&lt;/li&gt;&lt;li&gt;Credential Manager&lt;br/&gt;&lt;/li&gt;&lt;li&gt;Pluggable Protocol Architecture&lt;br/&gt;&lt;/li&gt;&lt;li&gt;Real-Time Console Infrastructure&lt;br/&gt;&lt;/li&gt;&lt;li&gt;Real-Time System Manager&lt;br/&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:4ed11137-9357-451a-9bb2-1d57d97b0b5e] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">amt</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">provisioning</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">task_server</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">symantec</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">notification_server</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">out_of_band_management</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">intelamt</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">real-time_system_manager</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">setup_and_configuration</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">intelscs</category>
      <pubDate>Wed, 03 Nov 2010 17:16:51 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2010/11/03/new-troubleshooting-guide-for-vpro-integration-in-symantec-management-platform-70-available</guid>
      <dc:date>2010-11-03T17:16:51Z</dc:date>
      <clearspace:dateToText>2 years, 6 months ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/new-troubleshooting-guide-for-vpro-integration-in-symantec-management-platform-70-available</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=13799</wfw:commentRss>
    </item>
    <item>
      <title>Extra AMT configuration with Config Manager</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2010/06/23/extra-amt-configuration-with-config-manager</link>
      <description>&lt;!-- [DocumentBodyStart:6c7f3713-181c-47ac-b90c-6bffd3ee93a9] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;span style="font-family: arial,helvetica,sans-serif; color: #333333;"&gt;Config Manager does a great job of setting up and configuring AMT. However, there are some features that the current Config Manager doesn't configure. To name a few: KVM Remote Control, Fast Call for Help, and PET or WSMan eventing. This is not a knock on Config Manager. It configures everything it needs to perform that actions it supports on AMT. But, just because one uses Config Manager to setup &amp;amp; configure AMT doesn't mean that one can't use other AMT tools and features. The trick is figuring out how to apply the extra AMT settings needed for the desired features.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: arial,helvetica,sans-serif; color: #333333;"&gt;OK, that's a mouth full. Here's an example that might help. Let's say you want AMT 6.0 to send a WS-Man event every time it's IP address changes, for tracking purposes. First, you find a tool (or write your own, it's not to hard with WinRM) to add the appropriate settings to AMT. Then, follow this Use Case Reference Design: &lt;span style="font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;a class="jive-link-wiki-small" data-containerId="2005" data-containerType="14" data-objectId="5215" data-objectType="102" href="http://communities.intel.com/docs/DOC-5215"&gt;&lt;span style="font-size: 10pt;"&gt;http://communities.intel.com/docs/DOC-5215&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: 10pt;"&gt;. &lt;span&gt;It offers two methods you may use in conjunction with Config Manager to get the extra AMT settings applies to all your AMT systems.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: arial,helvetica,sans-serif; color: #333333; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;Here's a few ideas on other ways you might use this:&lt;/span&gt;&lt;/p&gt;&lt;ol start="1"&gt;&lt;li&gt;&lt;div&gt;&lt;span style="font-family: arial,helvetica,sans-serif; color: #333333; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;Configure KVM ahead of time so the Service Desk user's don't need AMT admin permissions to use KVM Remote Control&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;&lt;/li&gt;&lt;li&gt;&lt;div&gt;&lt;span style="font-family: arial,helvetica,sans-serif; color: #333333; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;Configure Fast Call for Help so end user's may press the "Call for Help" button to alert the Service Desk that they need help.&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;&lt;/li&gt;&lt;li&gt;&lt;div&gt;&lt;span style="font-family: arial,helvetica,sans-serif; color: #333333; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;Configure and use Agent Presence&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;&lt;/li&gt;&lt;li&gt;&lt;div&gt;&lt;span style="font-family: arial,helvetica,sans-serif; color: #333333; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;Add a special Digest account for administrative and automation purposes&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;&lt;/li&gt;&lt;li&gt;&lt;div&gt;&lt;span style="font-family: arial,helvetica,sans-serif; color: #333333; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;Turn on some of AMT 6's new features like IPv6 or Wireless Profile Sync.&lt;/span&gt;&lt;/div&gt;&lt;br/&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: arial,helvetica,sans-serif; color: #333333;"&gt;The trick is finding the tool that will perform the configuration you want. Then, using the reference design above you can automate it. For #1 above, the Service Manager plugin has support for this. For the rest, you're own for now. But stay tuned as I'm working on blogs, examples, and reference designs to help.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:6c7f3713-181c-47ac-b90c-6bffd3ee93a9] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">manageability</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">amt</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">tools</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">sccm</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">microsoft</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">reference_design</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">setup_and_configuration</category>
      <pubDate>Wed, 23 Jun 2010 16:27:25 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2010/06/23/extra-amt-configuration-with-config-manager</guid>
      <dc:date>2010-06-23T16:27:25Z</dc:date>
      <clearspace:dateToText>2 years, 11 months ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/extra-amt-configuration-with-config-manager</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=13401</wfw:commentRss>
    </item>
    <item>
      <title>Remote Configuration Certificate Best Practices in Out of Band Management 7 for Intel vPro Systems</title>
      <link>http://communities.intel.com/community/vproexpert/blog/2009/04/07/remote-configuration-certificate-best-practices-in-out-of-band-management-7-for-intel-vpro-systems</link>
      <description>&lt;!-- [DocumentBodyStart:d8c43535-7bc2-420f-9c77-49644f428c11] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;div style="border-right: medium none; padding-right: 0in; border-top: medium none; padding-left: 0in; padding-bottom: 4pt; border-left: medium none; padding-top: 0in; border-bottom: #4f81bd 1pt solid; mso-element: para-border-div;"&gt; &lt;/div&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Whether you are planning to implement a Vendor TLS Certificate in the future, or you are having trouble applying a certificate you&amp;#8217;ve already obtained, this article walks through the best practices.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; The details include all the steps to properly install the right items and resolve issues we&amp;#8217;ve encountered up to this point.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; This article applies to Out of Band Management Solution 7.0, included with Client Management Suite 7.0.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Since certificates introduce tight encryption security, if the right items and steps are not in place or followed, it can break the ability of AMT systems to provision with Remote Configuration.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h1 style="margin: 12pt 0in 3pt;"&gt;&lt;span style="color: #000000; font-family: Cambria;"&gt;Introduction&lt;/span&gt;&lt;/h1&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Why is Configuring a vPro capable system important?&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Without setup and configuration, the functionality provided by vPro is not accessible within your Symantec Client Management Suite environment.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Out of Band Management Solution allows setup and configuration to occur automatically using Remote Configuration.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Using Remote Configuration to setup and configure your Intel AMT vPro capable computers takes the work out of the process, after some initial setup.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; AMT systems that come preconfigured with versions 2.2, 2.6, 3.0+, 4.0+, and 5.0+ will automatically use Remote Configuration to setup and configure with a valid Provisioning Server.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Out of Band Management provides such a server.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; The hashes from vendors (AMT 3.0 includes Verisign, GoDaddy, Comodo) are already configured in the firmware, and upon connection to power and the network, will begin to send out requests for configuration.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Thus in this way the managed vPro systems are already prepared to be configured without any intervention by the IT staff.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Usually the issues we see with the Remote Configuration process originate on the server-side process of adding a certificate from the before mentioned vendors.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Obtaining and installing a vendor TLS Remote Configuration certificate needs to be done the correct way so that authentication can succeed.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Once in place, provisioning will roll forward without any further intervention as long as the certificate remains valid.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; This article focuses on applying the server-side certificate so that setup and configuration can move forward automatically.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h1 style="margin: 12pt 0in 3pt;"&gt;&lt;span style="color: #000000; font-family: Cambria;"&gt;Obtaining a Remote Configuration Certificate&lt;/span&gt;&lt;/h1&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;This subject has been covered previously.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; I wanted to lightly touch upon this as there is a &lt;strong style="mso-bidi-font-weight: normal;"&gt;&lt;em style="mso-bidi-font-style: normal;"&gt;vital&lt;/em&gt;&lt;/strong&gt; step that should be taken so that if anything goes wrong we can correct it.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; First, the following article covers how to properly obtain a certificate:&lt;/span&gt;&lt;/p&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;a class="jive-link-external-small" href="http://juice.altiris.com/article/4496/obtaining-and-applying-a-verisign-remote-configuration-certificate" target="_blank"&gt;&lt;span style="font-size: 12pt; font-family: Calibri;"&gt;http://juice.altiris.com/article/4496/obtaining-and-applying-a-verisign-remote-configuration-certificate&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Note that part of obtaining a Remote Configuration is submitting the request from the Server you plan to install the certificate onto.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; This process creates the private key for the server-side certificate, and this item will not be available until partway through the application of the crt (or cer) file obtained from the vendor.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; The specific step that provides the full key, both private and public, is when the certificate is exported into a PFX format after the initial import, checking the option to export the private key will give you a complete backup of the full certificate in case it is needed in the future.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; If something happens, or if the application doesn&amp;#8217;t go right, we&amp;#8217;ll need both, so it&amp;#8217;s essential to export this as soon as possible.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;During the steps to install the certificate emphasis will be given on the step where the export should take place.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h2 style="margin: 12pt 0in 3pt;"&gt;&lt;em&gt;&lt;span style="font-size: 18pt; color: #000000; font-family: Cambria;"&gt;Certificate Authority (CA)&lt;/span&gt;&lt;/em&gt;&lt;/h2&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;In order to use Remote Configuration with Out of Band Management the Microsoft Certificate Authority services must be installed on the Notification Server or the OOB Site Server.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Use the following steps to install if it is not installed:&lt;/span&gt;&lt;/p&gt;&lt;ol start="1" style="margin-top: 0in;" type="1"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Go to Start &amp;gt; Administrative Tools &amp;gt; and click on Add or Remove Programs.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;In the left-side button bar click the button Add/Remove Windows Components.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;Check the option labeled Certificate Services.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; See this screenshot for details:&lt;br/&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-12037-3846/CAInstall.jpg"&gt;&lt;img alt="CAInstall.jpg" class="jive-image-thumbnail jive-image" height="450" onclick="" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-12037-3846/620-450/CAInstall.jpg" width="620"/&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;/span&gt;You&amp;#8217;ll receive the pop-up:&lt;br/&gt;&lt;em style="mso-bidi-font-style: normal;"&gt;After installation Certificate Services, the machine name and domain membership may not be changed due to the binding of the machine name to CA information stored in the Active Directory.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Changing the machine name or domain membership would invalidate the certificates issues from the CA.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Please ensure the proper machine name and domain membership are configured before installing Certificate Services. Do you want to continue?&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click Yes to continue once your system has the intended identity.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Click Next.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Choose what type of CA to create.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; If you are not installing a hierarchy of CAs you can leave the stand-alone root CA option selected.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Click Next.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Input the name the CA will be known by.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; This must match what is in the hierarchy or by what the Remote Configuration certificate name will be known by.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;The Distinguished Name is generated automatically in an AD Environment and will be the suffix of the system.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click through the rest of the options, noting where the services data files are stored.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;You will be prompted to restart IIS.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; This is required during the installation.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click Finish to complete the installation.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l1 level1 lfo5;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Done!&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; The NS or Site Server is now prepared to handle certificates in the Remote Configuration process.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h1 style="margin: 12pt 0in 3pt;"&gt;&lt;span style="color: #000000; font-family: Cambria;"&gt;Installing the Certificate&lt;/span&gt;&lt;/h1&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;The recommended application for a Remote Configuration certificate is to let the certificate dictate where to be installed.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; However this process has sometimes resulted with the certificate installed to an incorrect place.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; When this occurred we&amp;#8217;ve had headaches trying to clean up the system to properly install the certificate.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Why this occurs is unclear.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; For reference I&amp;#8217;m including the process of adding a certificate automatically here:&lt;/span&gt;&lt;/p&gt;&lt;ol start="1" style="margin-top: 0in;" type="1"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l5 level1 lfo4;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Save the acquired cer or crt file from the vendor onto the Notification Server or the Site Server for Out of Band Management.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l5 level1 lfo4;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Right-click on the file and choose Install Certificate.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l5 level1 lfo4;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click next on the Welcome screen.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l5 level1 lfo4;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Leave the radial option on &amp;lsquo;Automatically select the certificate store based on the type of certificate&amp;#8217; and click Next.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l5 level1 lfo4;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click Finish to complete the installation.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; You&amp;#8217;ll receive a confirmation pop-up that the certificate installed successfully.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;While I won&amp;#8217;t advise against using this method, the below steps uses the manual installation method to ensure the certificate is installed to the correct place.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;I&amp;#8217;ve condensed the steps required into the following list.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; This process works for all vendors once you&amp;#8217;ve obtained a certificate.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Note that these steps are provided to consolidate both recommended steps and documentation into one whole.&lt;/span&gt;&lt;/p&gt;&lt;ol start="1" style="margin-top: 0in;" type="1"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Go to Start &amp;gt; Run &amp;gt; type mmc &amp;gt; and click OK.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;In the resulting console click under File and choose Add/Remove Snap-ins&amp;hellip;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Near the bottom of the resulting window click the Add button.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;From the list that appears select Certificates and then click the Add button.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Leave the radial button selected on &amp;lsquo;My user account&amp;#8217; and click Finish.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;From the same list select Certificates again and click the Add button.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;From the resulting window change the radial select to &amp;lsquo;Computer account&amp;#8217; and click Next.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Leave the selection at &amp;lsquo;Local computer: (the computer this console is running on) and click Finish.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click the Close button in the window offering you the list of available snap-ins.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;At the original add/remove snap-in screen verify that you have two entries:&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style: none;"&gt;&lt;ol start="1" style="margin-top: 0in;" type="a"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level2 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Certificates &amp;#8211; Current User&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level2 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Certificates (Local Computer)&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click OK.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;Expand both trees in the left-hand pane within the console.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; You should see the full certificate stores as shown in this screenshot:&lt;br/&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-12037-3847/CertificateStores.jpg"&gt;&lt;img alt="CertificateStores.jpg" class="jive-image" height="384" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-12037-3847/576-384/CertificateStores.jpg" width="576"/&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Right-click on the Personal folder under the Current User certificate store and highlight &amp;lsquo;All Tasks&amp;#8217; and click on &amp;lsquo;Import&amp;#8217; in the pop-out menu.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click Next on the Welcome page of the Certificate Import Wizard and click the Browse button.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Browse to the cer or crt file provided by the vendor, highlight it, and click Open.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click Next, and leave the radial option on &amp;lsquo;Place all certificates in the following store&amp;#8217;, which should be set to &amp;lsquo;Personal&amp;#8217;.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Click Next.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Under the Completing section of the wizard, Click Finish.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; You should receive a pop-up indicating the certificate was successfully installed.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;&lt;em style="mso-bidi-font-style: normal;"&gt;NOTE!&lt;/em&gt;&lt;/strong&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; This is the vital step mentioned previously in the article.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; We will now export the certificate with both public and private keys, which will give us the full set and allow us to remove and reapply if necessary.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; In the MMC select the newly imported certificate &amp;gt; right-click &amp;gt; and choose All Tasks &amp;gt; Export&amp;hellip;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click Next on the Welcome screen.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; In the resulting list you should have an active option for &amp;lsquo;Personal Information Exchange &amp;#8211; PKCS #12 (.PFX)&amp;#8217;.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; If this option is not available (grayed out as shown in this screenshot), there is a problem with the certificate and the private key is not accessible:&lt;br/&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-12037-3848/ExportDial.jpg"&gt;&lt;img alt="ExportDial.jpg" class="jive-image" height="379" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-12037-3848/497-379/ExportDial.jpg" width="497"/&gt;&lt;/a&gt;&lt;br/&gt;If this occurs please note the following items:&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style: none;"&gt;&lt;ol start="1" style="margin-top: 0in;" type="a"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level2 lfo2;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;The application of the public key, or cer/crt file, must be done on the server where the key was requested.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level2 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;If this is not your Provisioning Server you&amp;#8217;ll need to contact the Vendor of the certificate to resolve the discrepancy.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level2 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;If you did request this certificate from the server you are operating on, you&amp;#8217;ll also need to contact the vendor to explain that the private key is not found when exporting the certificate after initial application.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Follow the wizard, and ensure you select the option &amp;lsquo;Yes, export the private key&amp;#8217;.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; When saving the file, it will prompt you to set a password to protect the private key (this is recommended for security reasons).&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; The export should leave you a PFX file.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Keep this in a safe place, preferably in line with your company&amp;#8217;s encryption certificate backup policy.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Next we need to import the full key into the Computer store.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Start back in the MMC &amp;gt; under the Local Computer certificate store &amp;gt; right-click on the Personal folder &amp;gt; select All Tasks &amp;gt; Import&amp;hellip;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click Next on the Welcome screen and click the Browse button on the subsequent screen.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Browse to the newly exported PFX file.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Note that you will need to change the &amp;lsquo;Files of type&amp;#8217; to include the PFX format.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Click Next.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;The Password screen prompts for the password you set when you exported the key in step #20, as shown in the following screenshot.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Enter the password and click Next.&lt;br/&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-12037-3849/CertPassword.jpg"&gt;&lt;img alt="CertPassword.jpg" class="jive-image" height="378" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-12037-3849/498-378/CertPassword.jpg" width="498"/&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Choose or leave the select to &amp;lsquo;Place all certificates in the following store&amp;#8217;.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; The value should be Personal.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Click Next.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click Finish on the end details page to complete the import.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo2;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Done!&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;em style="mso-bidi-font-style: normal;"&gt;NOTE: In Out of Band Management 6.x, with Intel SCS 3.x or earlier, a separate utility was required to load certificates into Intel SCS so the Provision Server was aware of them.&amp;nbsp; This is no longer required as Intel SCS 5.x possesses intelligence to automatically acquire all installed Intel vPro Remote Configuration encryption certificates.&lt;/em&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h2 style="margin: 12pt 0in 3pt;"&gt;&lt;em&gt;&lt;span style="font-size: 18pt; color: #000000; font-family: Cambria;"&gt;Reinstalling the Certificate&lt;/span&gt;&lt;/em&gt;&lt;/h2&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;If you need to reinstall the certificate and you have a PFX file, you can do so by opening both certificate stores (User and Local Computer) as outlined in the previous steps.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Browse through the certificate stores and delete any instance of the vendor certificate.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt; This will remove any associations and allow a clean application of the certificate to occur.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Look for the following:&lt;/span&gt;&lt;/p&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;The name matching the name of the cer or crt file obtained from the vendor&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;The vendor&amp;#8217;s certificate (the entry will contain the vendor name).&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;em style="mso-bidi-font-style: normal;"&gt;NOTE: Be careful when removing vendor certificates as they may not be part of the Remote Configuration.&amp;nbsp; The best example is Verisign, which may have many entries.&amp;nbsp; If unsure, leave the certificate in place, or export it before deleting it so you can restore it if necessary.&lt;/em&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h2 style="margin: 12pt 0in 3pt;"&gt;&lt;em&gt;&lt;span style="font-size: 18pt; color: #000000; font-family: Cambria;"&gt;Enabling Remote Configuration&lt;/span&gt;&lt;/em&gt;&lt;/h2&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;To ensure that Out of Band Management is setup to use Remote Configuration as a valid setup and configuration method, follow these steps:&lt;/span&gt;&lt;/p&gt;&lt;ol start="1" style="margin-top: 0in;" type="1"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l0 level1 lfo3;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;In the Symantec Management Console browse under Home &amp;gt; Remote Management &amp;gt; and click on Out of Band Management.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l0 level1 lfo3;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;In the left-hand tree browse under Configuration &amp;gt; Configuration Service Settings &amp;gt; and select General.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l0 level1 lfo3;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;In the resulting page ensure that the option labeled Allow Remote Configuration is checked.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; If it is not, check it.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; See this screenshot for an example:&lt;br/&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-12037-3850/EnableRemoteConfig.jpg"&gt;&lt;img alt="EnableRemoteConfig.jpg" class="jive-image-thumbnail jive-image" height="522" onclick="" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-12037-3850/620-522/EnableRemoteConfig.jpg" width="620"/&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l0 level1 lfo3;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;If you needed to check the option, be sure to click Save Changes to register the change.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;That should do it for the certificates.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; You&amp;#8217;ve now completed the steps required to install and enable Remote Configuration in the Out of Band Management Environment.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; However you are not done yet!&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Certain infrastructure components are required to make this process seamless.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Proceed to the next section for details.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h1 style="margin: 12pt 0in 3pt;"&gt;&lt;span style="color: #000000; font-family: Cambria;"&gt;Other Setup Requirements&lt;/span&gt;&lt;/h1&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;The following items will be used to automate the setup and configuration process.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Remote Configuration will use these to locate and communicate with the Provisioning Server (Out of Band Management).&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h2 style="margin: 12pt 0in 3pt;"&gt;&lt;em&gt;&lt;span style="font-size: 18pt; color: #000000; font-family: Cambria;"&gt;ProvisionServer&lt;/span&gt;&lt;/em&gt;&lt;/h2&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Each zone within DNS should have a ProvisionServer entry to ensure that Remote Configuration requests are properly routed to the Server.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; This will also help properly resolve names during the authentication process.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Use the following steps to add ProvisionServer to DNS:&lt;/span&gt;&lt;/p&gt;&lt;ol start="1" style="margin-top: 0in;" type="1"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Go to Start &amp;gt; Run &amp;gt; type mmc &amp;gt; and click OK.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;In the resulting console click under File and choose Add/Remove Snap-ins&amp;hellip;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Near the bottom of the resulting window click the Add button.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;From the list that appears select DNS and click Add and click Close.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Click OK in the next Window.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Browse in the tree to the Forward Lookup Zones.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Right-click the entry for the Notification Server computer and choose New Alias.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Type ProvisionServer as the Alias name, in this manner:&lt;br/&gt;ProvisionServer&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l2 level1 lfo6;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;Done!&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Though simple, this is the key to directing the automatic Remote Configuration hello packets from enabled vPro systems to the Notification Server or Site Server.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Without this step no setup and configuration of vPro systems will occur.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;To test, log onto a system on the subnet you&amp;#8217;re trying to conduct Remote Configuration from.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Run a command prompt and use the following command:&lt;/span&gt;&lt;/p&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;ping ProvisionServer&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;We should see the responding IP Address by the IP Address of the Notification Server, or, if you&amp;#8217;ve set it up this way, the Intel SCS Server conducting provisioning.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Another test you can try is to run the following command:&lt;/span&gt;&lt;/p&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;nslookup ProvisionServer&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;We should get the data on the Notification Server&amp;#8217;s Fully Qualified Domain Name (FQDN).&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h2 style="margin: 12pt 0in 3pt;"&gt;&lt;em&gt;&lt;span style="font-size: 18pt; color: #000000; font-family: Cambria;"&gt;DNS Zones&lt;/span&gt;&lt;/em&gt;&lt;/h2&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;In a multiple domain structure this is especially important, but all environments need to have the right data in DNS to properly pass and authenticate in a TLS environment.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; The DNS Primary Zone should be set to the Domain path contained within the certificate.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; For example, if the certificate name is MyNSServer_My1Domain_local, the DNS Primary Zone should be My1Domain.local.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Without this, authentication can fail as the FQDN is used during authentication, and if the name being transmitted across the wire doesn&amp;#8217;t match what&amp;#8217;s in the certificate, authentication will fail.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Here is another example:&lt;/span&gt;&lt;/p&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Certificate: MyNSServer_My1Domain_local.crt&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;DNS Primary lookup Zone: My1Domain.local&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h2 style="margin: 12pt 0in 3pt;"&gt;&lt;em&gt;&lt;span style="font-size: 18pt; color: #000000; font-family: Cambria;"&gt;DHCP Option&lt;/span&gt;&lt;/em&gt;&lt;/h2&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Another Network related requirement may be DHCP Option 15.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; While I&amp;#8217;m not sure why this has proven to be required in some environments and not others, creating this option has resolved failed authentication issues within Remote Configuration.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;In DNS, create an entry for Option 15, with the value of the domain path.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; This will often be the same as what is located in the DNS Primary Zone.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; The following details are an example:&lt;/span&gt;&lt;/p&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Certificate: MyNSServer_My1Domain_local.crt&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;DNS Primary lookup Zone: My1Domain.local&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l3 level1 lfo1;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;DHCP Option 15: My1Domain.local&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;h1 style="margin: 12pt 0in 3pt;"&gt;&lt;span style="color: #000000; font-family: Cambria;"&gt;Conclusion&lt;/span&gt;&lt;/h1&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Following the above procedure should allow remote configuration to occur without problems.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt; Once in place, the configuration will move forward with automatic setup and configuration for all vPro enabled systems that support Remote Configuration.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:d8c43535-7bc2-420f-9c77-49644f428c11] --&gt;</description>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">amt</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">activation</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">symantec</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">out_of_band_management</category>
      <category domain="http://communities.intel.com/community/vproexpert/blog/tags">setup_and_configuration</category>
      <pubDate>Tue, 07 Apr 2009 20:32:09 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/vproexpert/blog/2009/04/07/remote-configuration-certificate-best-practices-in-out-of-band-management-7-for-intel-vpro-systems</guid>
      <dc:date>2009-04-07T20:32:09Z</dc:date>
      <clearspace:dateToText>4 years, 1 month ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/vproexpert/blog/comment/remote-configuration-certificate-best-practices-in-out-of-band-management-7-for-intel-vpro-systems</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/vproexpert/blog/feeds/comments?blogPost=12037</wfw:commentRss>
    </item>
  </channel>
</rss>

