Intel vPro Expert Center Blog

Previous Next
2


The following information contains the detailed steps used to order a Remote Configuration Client Certificate from GoDaddy. There are many methods that can be used, but this was tested and validated that the certificate worked for both SMS and SCCM SP1 to provide Remote Configuration Provisioning to vPro clients.

SUMMARY: You will be required to prove that you, or your company, own the rights to the domain for which you are applying for this certificate. In the following example, I first registered my lab domain before ordering my Remote Configuration Certificate. I also needed a Company representative to submit a letter of approval (Company Letterhead) to GoDaddy giving me authority to request this certificate. I also tested the certificate I received from GoDaddy did work with Remote Configuring AMT clients in SMS and SCCM SP1 environment.

Key items that are detailed in the steps below that were required to get my certificate:
○ Certificate type must be a Deluxe Assurance SSL certificate
○ Certificate request is for an Organization
○ OU = Intel(R) Client Setup Certificate
○ CN = ServerName.domain.com (this must be the FQDN of the Provisioning Server for Remote Configuration generating the CSR)
○ Organization = The legal name of your organization that can approve your certificate request
○ Required Documentation to be submitted (Driver's License, Bank Statement, and Approval Letter on Company Letterhead)

STEPS TO PURCHASE THE REMOTE CONFIGURATION CERTIFICATE
1. Go to GoDaddy Web site: www.godaddy.com
2. Select the SSL Certificate link: https://www.godaddy.com/gdshop/ssl/ssl.asp?ci=8979

http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1281/1.png

3. From the SSL Certificate page, choose the Deluxe SSL certificate and click ADD
a. select Single (your choice of 1, 2, or 3 years) for a single Domain environment
b. Unlimited Subdomains - wild cards are support for version of AMT 2.6 / 3.2 and higher
4. In the next screen, you will be prompted to customize your order. No additional items are necessary on this screen, select Continue
5. At the Checkout Now screen, you should see the Deluxe Assurance SSL certificate (other options may vary if you selected additional items to purchase)
http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1282/2.png

6. In the Billing information Window, make sure to include your valid company name. You will be required to have someone from your company submit an approval letter for this certificate request on company letterhead (more detailed steps to follow).
7. After you fill out your billing information, you will need to login to your account to configure the certificate you have just purchased.
8. After logging in to your account, select Manage SSL Certificates.
9. You will see you have an available credit in the Secure Certificates, Click Set up Certificate link and Click Activate Account
a. You may need to Login in to your account or Create a new Certificate account - this is different than your GoDaddy Account
http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1283/3.png

10. Select the Deluxe High-Assurance SSL Certificate and Click Request Certificate

http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1284/4.png

11. Select Corporate option in Step 1
Fill out Personal Information in Step 2, including your company name
Generate you CSR and paste text in the box provided in Step 3 (make sure to indicate the type of server used to produce CSR)
They provide a link in Step 3 on How to generate a CSR (follow these steps).

The CSR MUST include the following fields to be a valid vPro Remote Configuration Certificate and approved by GoDaddy:

  • OU = Intel(R) Client Setup Certificate
  • CN = ServerName.domain.com (this must be the FQDN of the Provisioning Server for Remote Configuration generating the CSR)
  • Organization = The legal name of your organization that can approve your certificate request

http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1285/5.png
12. After you paste your CSR information and click Submit, your request will be routed to GoDaddy and they will follow up via email for next steps.
13. You will be asked to send them two forms of Identification (Driver License and Bank Statement)
14. Additionally, you will be asked to have someone within your company provide an approval letter on company letterhead stating that you have the authority to request the SSL certificate for this server and domain.
15. After GoDaddy has validated the required documentation, they will send you an email stating that your SSL certificate is available.
16. You can now download your SSL certificate and apply it to your IIS Web Server on your requesting Provisioning Server.

Average User Rating
(1 rating)


Add a comment Leave a comment on this blog post.
Mar 8, 2008 4:17 AM Reply Guest Insurance Certificate

I like godaddy very much , we have 1 hosting account and almost 50 domains there.I will like to buy Certificate also from them.This tips really helps us.
Thanks

Mar 8, 2008 8:06 AM Reply Click to view wryork's profile wryork

I have found an interesting tidbit while setting up SCCM SP1 and remote configuration certificates using GoDaddy.

If you follow the help file in SCCM SP1 on how to setup Remote Configuration Provisioning in SCCM SP1, you will see the steps they document to generate the provisioning certificate server request (CSR) to send to your CA vendor (i.e. GoDaddy, VeriSign, Starfield, etc).

However, Microsoft's steps tell you to use the specific OID (Object Identifier) in this request. It does not have the steps to use the Intel(R) Client Setup Certificate for the OU, as I documented in this original posting. When I followed these steps and submitted my CSR to GoDaddy, which included this OID as outlined and not the OU field, GoDaddy issued my certificate and I found the OID was not in the issued certificate.

Therefore, this certificate will not work for provisioning.

I contacted GoDaddy and they told me they do not support modifying these attributes (OID). SO, if you are following SCCM SP1 directions and plan to submit to GoDaddy, make sure you use the OU = Intel(R) Client Setup Certificate and not the OID they mention.

Let me know if you need help with this process. It varies depnding on what ISV you are setting up and what Certificate Authority you are submitting to for this certificate.