<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Intel vPro Expert Center Blog</title>
    <link>http://communities.intel.com/openport/blogs/proexpert</link>
    <description>Intel vPro Expert Center Blog</description>
    <pubDate>Wed, 28 May 2008 22:50:21 GMT</pubDate>
    <generator>Clearspace 1.7.0 (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2008-05-28T22:50:21Z</dc:date>
    <item>
      <title>IT administrators compete at MMS 2008 in the Intel vPro technology Challenge</title>
      <link>http://communities.intel.com/openport/blogs/proexpert/2008/05/28/it-administrators-compete-at-mms-2008-in-the-intel-vpro-technology-challenge</link>
      <description>We had the Intel vPro technology Challenge at MMS 2008 - a competition where teams of two competed to fix a troubled PC using Microsoft System Center Configuration Manager 2007 with PCs with Intel vPro technology. Check out how much fun this Challenge was at MMS 2008 this year:&lt;br /&gt;
&lt;p /&gt;
&lt;center&gt;
&lt;object width="425" height="355"&gt;&lt;param name="movie" value="http://www.youtube.com/v/ae9269D4DvQ&amp;hl=en"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/ae9269D4DvQ&amp;hl=en" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;
&lt;/center&gt;
&lt;line&gt;
&lt;br /&gt;
&lt;/line&gt;
&lt;br /&gt;
To see more videos from MMS 2008, go to: &lt;a class="jive-link-external" href="http://www.intel.com/go/mms/"&gt;http://www.intel.com/go/mms/&lt;/a&gt;</description>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">centrino_pro</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">vpro</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">challenge</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">microsoft</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">system</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">center</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">configuration</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">manager</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">mms</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">sccm</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">sccm_sp1</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">sms</category>
      <pubDate>Wed, 28 May 2008 22:54:21 GMT</pubDate>
      <author>jlvb</author>
      <guid>http://communities.intel.com/openport/blogs/proexpert/2008/05/28/it-administrators-compete-at-mms-2008-in-the-intel-vpro-technology-challenge</guid>
      <dc:date>2008-05-28T22:54:21Z</dc:date>
      <clearspace:dateToText>4 months, 1 week ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/openport/blogs/proexpert/comment/it-administrators-compete-at-mms-2008-in-the-intel-vpro-technology-challenge</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/proexpert/feeds/comments?blogPostID=11228</wfw:commentRss>
    </item>
    <item>
      <title>What Acronym best describes Intel® vPro Technology? (MMS 08)</title>
      <link>http://communities.intel.com/openport/blogs/proexpert/2008/05/19/what-acronym-best-describes-intel-vpro-technology-mms-08</link>
      <description>Sometimes within Intel Marketing, we're told that our description of Intel Centrino with vPro technology or Intel Core 2 with vPro technology is a bit lengthy. Therefore, while at MMS 08, we asked Intel customers as well as technical experts from Intel and Microsoft to give us their best, most concise acronym that best describes Intel vPro Technology. Listen to their responses below. &lt;br /&gt;
&lt;br /&gt;
&lt;center&gt;
&lt;object width="425" height="355"&gt;&lt;param name="movie" value="http://www.youtube.com/v/2EaQujes0OU&amp;hl=en"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/2EaQujes0OU&amp;hl=en" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;
&lt;/center&gt;
&lt;br /&gt;
&lt;line&gt;
&lt;br /&gt;
&lt;/line&gt;
&lt;br /&gt;
To see more videos from MMS 08, go to &lt;a class="jive-link-external" href="http://www.intel.com/go/mms/"&gt;http://www.intel.com/go/mms/&lt;/a&gt;</description>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">intel</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">microsoft</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">vpro</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">technology</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">mms</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">08</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">justin_van_buren</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">acronym</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">system</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">center</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">configuration</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">manager</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">sms</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">management</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">summit</category>
      <pubDate>Tue, 20 May 2008 00:10:44 GMT</pubDate>
      <author>jlvb</author>
      <guid>http://communities.intel.com/openport/blogs/proexpert/2008/05/19/what-acronym-best-describes-intel-vpro-technology-mms-08</guid>
      <dc:date>2008-05-20T00:10:44Z</dc:date>
      <clearspace:dateToText>4 months, 2 weeks ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/openport/blogs/proexpert/comment/what-acronym-best-describes-intel-vpro-technology-mms-08</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/proexpert/feeds/comments?blogPostID=11186</wfw:commentRss>
    </item>
    <item>
      <title>What does the "v" in Intel vPro technology mean to you?</title>
      <link>http://communities.intel.com/openport/blogs/proexpert/2008/05/19/what-does-the-v-in-intel-vpro-technology-mean-to-you</link>
      <description>When Intel released Intel vPro technology into the marketplace in 2006, the press asked us what the "v" in Intel vPro technology meant. Now that the technology has been in the marketplace for almost two years, we thought that the best answer to the question, "What does the "v" in Intel vPro technology mean to you?" would come from Intel customers, as well as from some of the technical experts from Intel and our partners who deal with our customers on an almost daily basis. See their answers below. &lt;br /&gt;
&lt;br /&gt;
&lt;center&gt;
&lt;object width="425" height="355"&gt;&lt;param name="movie" value="http://www.youtube.com/v/eDHYHEAhPd4&amp;hl=en"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/eDHYHEAhPd4&amp;hl=en" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;
&lt;/center&gt;
&lt;line&gt;
&lt;br /&gt;
&lt;/line&gt;
&lt;br /&gt;
To see more videos from MMS 2008, go here: &lt;a class="jive-link-external" href="http://www.intel.com/go/mms/"&gt;http://www.intel.com/go/mms/&lt;/a&gt;</description>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">mms</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">vpro</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">sccm_sp1</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">sccm</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">intel</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">microsoft</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">vpro</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">mms</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">2008</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">system</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">center</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">configuration</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">manager</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">sms</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">justin_van_buren</category>
      <pubDate>Mon, 19 May 2008 22:28:37 GMT</pubDate>
      <author>jlvb</author>
      <guid>http://communities.intel.com/openport/blogs/proexpert/2008/05/19/what-does-the-v-in-intel-vpro-technology-mean-to-you</guid>
      <dc:date>2008-05-19T22:28:37Z</dc:date>
      <clearspace:dateToText>4 months, 2 weeks ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/openport/blogs/proexpert/comment/what-does-the-v-in-intel-vpro-technology-mean-to-you</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/proexpert/feeds/comments?blogPostID=11183</wfw:commentRss>
    </item>
    <item>
      <title>New known issues and best practices posted! Topics are around SCS and the SMS Add-on.</title>
      <link>http://communities.intel.com/openport/blogs/proexpert/2008/05/08/new-known-issues-and-best-practices-posted-topics-are-around-scs-and-the-sms-addon</link>
      <description>New articles for you to take a look at this week. As always, let me know if you have a best practice or known issue that you want to share or have investigated!&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a class="jive-link-external" href="http://communities.intel.com/docs/DOC-1247#SCS14"&gt;Using international keyboards to create MEBx passwords via Setup and Configuration Service (SCS)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a class="jive-link-external" href="http://communities.intel.com/docs/DOC-1247#SCS15"&gt;What is the Authorized column in SCS?&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a class="jive-link-external" href="http://communities.intel.com/docs/DOC-1247#SMS4"&gt;Do management workstations running the SMS console and SMS Add-on require patches as outlined in the documentation for the Intel(R) AMT Add-on for Microsoft SMS*?&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">vpro</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">sms</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">scs</category>
      <pubDate>Thu, 08 May 2008 16:50:40 GMT</pubDate>
      <author>michelegartner</author>
      <guid>http://communities.intel.com/openport/blogs/proexpert/2008/05/08/new-known-issues-and-best-practices-posted-topics-are-around-scs-and-the-sms-addon</guid>
      <dc:date>2008-05-08T16:50:40Z</dc:date>
      <clearspace:dateToText>5 months, 2 days ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/openport/blogs/proexpert/comment/new-known-issues-and-best-practices-posted-topics-are-around-scs-and-the-sms-addon</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/proexpert/feeds/comments?blogPostID=11144</wfw:commentRss>
    </item>
    <item>
      <title>Matt Royer jumps into vPro's BlogTalkRadio show April 21st!</title>
      <link>http://communities.intel.com/openport/blogs/proexpert/2008/04/18/matt-royer-jumps-into-vpros-blogtalkradio-show-april-21st</link>
      <description>&lt;b&gt;Coming Up:&lt;/b&gt; We are going to have Matt Royer join us again on the show. Josh, Russ, &amp; Jeff Torello will be getting the latest information on WS-MAN translator integration and SMS/SCS to SCCM Migration. Hope you are able to join us!&lt;br /&gt;
When: April 21st @ 3:30 PM&lt;br /&gt;
Call-in Number: (347) 326-9831&lt;br /&gt;
&lt;br&gt;
Check out these blog posts from Matt Royer to get an insight on what our show will be about:&lt;br /&gt;
&lt;a href="http://communities.intel.com/openport/blogs/proexpert/2008/04/16/sccm-sp1-38-wsman-translator-how-vpro-firmware-versions-less-than-321-are-supported" class="jive-link-blogpost"&gt;SCCM SP1 &amp; WS-MAN Translator: How vPro firmware versions less than 3.2.1 are supported&lt;/a&gt; &lt;br /&gt;
&lt;a href="http://communities.intel.com/openport/blogs/proexpert/2008/04/16/overview-of-smsintel-scs-migration-to-sccm-sp1" class="jive-link-blogpost"&gt;Overview of SMS/Intel SCS migration to SCCM SP1&lt;/a&gt;&lt;br /&gt;
&lt;br&gt;
&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11073-1366/btrbetalogo.gif" alt="btrbetalogo.gif" class="jive-image"  /&gt; &lt;br /&gt;
&lt;a class="jive-link-external" href="http://www.blogtalkradio.com/openport"&gt;http://www.blogtalkradio.com/openport&lt;/a&gt;&lt;br /&gt;
Here's the scoop, yet again, for those who haven't heard...&lt;br /&gt;
Hosted by Josh Hilliker, Russ Pam, &amp; Jeff Torello this bi-weekly informal show will be covering a variety of topics and is a perfect avenue to get your questions answered. Listen in live, give your two cents, or just download the show after it has aired. Make sure not to miss out on this awesome opportunity to learn and engage with the vPro experts. Can’t join us live? Have no fear, blogtalkradio let’s you listen to the show whenever you have the time. Visit the Open Port Radio site (link is above) to hear previous shows and even catch a glimpse of what’s to come!</description>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">matt_royer</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">josh_hilliker</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">russ_pam</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">jeff_torello</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">sccm</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">sms</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">ws-man</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">kelsey_witherow</category>
      <pubDate>Fri, 18 Apr 2008 21:55:45 GMT</pubDate>
      <author>Kelsey_Witherow</author>
      <guid>http://communities.intel.com/openport/blogs/proexpert/2008/04/18/matt-royer-jumps-into-vpros-blogtalkradio-show-april-21st</guid>
      <dc:date>2008-04-18T21:55:45Z</dc:date>
      <clearspace:dateToText>5 months, 3 weeks ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/openport/blogs/proexpert/comment/matt-royer-jumps-into-vpros-blogtalkradio-show-april-21st</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/proexpert/feeds/comments?blogPostID=11073</wfw:commentRss>
    </item>
    <item>
      <title>Two ISV's managing the same client? Sure!</title>
      <link>http://communities.intel.com/openport/blogs/proexpert/2008/03/10/two-isvs-managing-the-same-client-sure</link>
      <description>The Brand Promise Validation team here at Intel came across an issue in the lab which many customers may also run into when they are trying to deploy AMT. The question was, how do I use two different ISVs to manage different aspects of my Enterprise configured AMT client fleet? Theoretically this isn't neccessarily a tough question. Based on how AMT was designed, so long as you have the same authentication and credentials setup between the different managment software, you should be able to access the AMT features. In practice, however, many management applications attempt to configure AMT in such a way that they have sole access by customizing the provisioning settings and then hide those settings away. &lt;br /&gt;
&lt;br /&gt;
However, as I'm about to describe, with a little tweaking, you can force these applications to play nice together.&lt;br /&gt;
&lt;p /&gt;
The main thing to remember anytime you are setting up AMT in enterprise mode is that the key to accessing AMT is having the correct certificates in place. For access that means having a Web Server based certificate template that will be used for TLS communication between the console and AMT. If you are also using PKI provisioning, you'll have to have a properly configured or purchased provisioning certificate in place (I won't be covering the details of PKI provisioning in this blog, but maybe in a future update). Lastly, for SMS and Altiris you'll also need a .pem certificate. Details on how to create a .pem certificate is included in both the Altiris help and Intel AMT Add-on for SMS documentation. A quick summary of a .PEM file certificate is taking each certificate in the chain starting at the top and concatinating those certificates into a single file. This file is used for secure TLS communication during SOL sessions.&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
The two management applicaitons we targetted for implementation was Altiris and SMS using the Intel AMT Add-on for SMS. The reason we targetted these apps is that we have inimate knowledge using these applications since they are used in our validation efforts and they both utilize the Intel SCS for provisioning. &lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
Both Altiris and SMS systems should be in the same domain using the same certificate authority and have the same root certificate installed. While it is definately feasible that you could have the the two management applications in different child domains using wildcard certificates for authentication, this article doesn't cover that specific configuration.&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
I'm not going to go into the details of setting up Altiris and SMS or how to configure SCS for provisioning since it is assumed that if you are attempting to merge these ISVs so that they can manage AMT clients, then you should already know how to get the individual applications to work with AMT.&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
I started off by getting Altiris setup and configured using the built in SCS included in the OOB Management solution for Altiris. At this point I didn't have to do anything special in order to make sure that the SMS Add-on would work, I just setup Altiris as normal to manage AMT clients. Once setup, I verified that I could provision and manage my AMT clients.&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
Next step, on a different machine, I setup and configured SMS with the Intel AMT Add-on for SMS. I configured SMS to use it's own SQL server, however, there is no reason that you couldn't have it use the Altiris SQL server (setting up a separate instance) or a stand alone SQL server (again with a separate instance). For ease of configuration, however, I just used a separate SQL install on the same machine as SMS. &lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
Once you have the SMSAMTUser_&amp;lt;sitecode&amp;gt; account created in active directory and have that account as well as whatever user accounts you want to use AMT via SMS added to the Intel(R) AMT groups (there are 3-5 of them depending on the version of the AMT Add-on you are using), you need to add the SMSAMTUser_&amp;lt;sidecode&amp;gt; to the Altiris SCS users list. On the Altiris system go to: View -&amp;gt; Configuration -&amp;gt; Solution Settings -&amp;gt; Platform Administration -&amp;gt; Out of Band Managment -&amp;gt; Provisioning -&amp;gt; Configuration Service Setings -&amp;gt; Users. Click the blue + to add a new user. Click the ... button. Select domain and type in the name query field SMSAMTUser and click Find. Select the SMSAMTUser_&amp;lt;sitecode&amp;gt; that is found in the results field and click OK. Under Role make sure Enterprise Administrator is selected. Click OK. This gives the service account for the Intel(r) AMT Add-on for SMS rights to view and modify the Altiris SCS. &lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
On the SMS system, open up the Intel Add-on Settings dialogue box and configure it to use the Altiris Setup and Configuration Server. In order to find the URL that Altiris uses to connect to the SCS, On the Altiris machine, go to: &lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
View -&amp;gt; Configuration -&amp;gt; Solution Settings -&amp;gt; Platform Administration -&amp;gt; Out of Band Managment -&amp;gt; Provisioning -&amp;gt; Configuration Service Setings -&amp;gt; Service Location. &lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
If you have the Default URL set, you should have something like [/]&amp;lt;fqdn/AMTSCS. If you are using an alternative URL, copy that down. On the SMS machine, open up the Intel Add-on Settings and go to the Setup and Configuration tab. Select the Integrated Setup and Configuration radio button and type in the URL you copied down into the SCS Service URL box. Click the Set Profiles box and the AMT profiles that are setup in Altiris should pop up in a new window. Select the profiles you want to use in SMS (select all of them if you want all profiles to be able to be managed in SMS) and click OK. The list of supported profiles should now be populated with the profiles that are setup in Altiris. &lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
Next step is to setup the .PEM certificate file that was used in Altiris for the Intel AMT Add-on for SMS. Copy the .PEM file used in Altiris to the SMS system. If you don't know where you .PEM file is located in Altiris, go to:&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
View -&amp;gt; Configuration -&amp;gt; Solution Settings -&amp;gt; Real-Time Console Infrastructure -&amp;gt; Configuration. &lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
Click on the Intel(r) AMT Connection Settings tab. Under Redirection Security you should see a box next to the Trusted CA certifcate location. That box should have the path to the .PEM file. Once you have copied that file to your SMS system (doesn't matter where you put the .PEM file on your SMS box, so long as you remember where you put it) open up the Intel Add-on Settings dialogue and click on the Security tab. Check the Enable Intel(r) AMT secure Connection (TLS) box. In the CA Certificate Path put in the path to the location of the .PEM file that was copied onto the SMS system. Click Apply.&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
That is the basicis of what needs to be done. Once you have discovered the AMT clients in SMS and they are populated in the collection, right click on All Systems and go to All Tasks -&amp;gt; Intel(r) AMT Tasks -&amp;gt; Discover Systems. Now when you right click on an AMT system and go to All Tasks -&amp;gt; Intel(r) AMT Tasks you should see the list of AMT functions you can perform such as Asset Identification Information, Power Control Operations, etc.&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
In order to get SOL/IDE-R to work and System Defense to work, you'll need to go into the Intel(r) Add-on Settings in SMS again and setup the location of the ISO images that will be used for IDE-R and the System Defense file that will be used to filter packets using Circuit Breaker. Creating the System Defense file is covered in the Intel(r) AMT Add-on for SMS documentation and will not be explained in detail here. The repository for the ISO images needs to be a network share and can either reside locally on the SMS system (still mapped to the network share location) or can reside in a central repository. If you want both Altiris and SMS to use the same set of images just use the same network path to the ISO images for both applications.&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
That's it. In my environment I'm able to manage AMT machines with either management application. The only slight gotcha (and this is more a security feature of AMT) is that if one management application is currently managing a client (ex. using SoL) then the other is unable to break in and use the client. The gotcha part of this is that neither management application gives a clear indication that the system is currently in use by another management application, the attempt to manage just fails with an authentication error.</description>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">amt</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">sms</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">altiris</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">scs</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">vpro</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">add-on</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">provision</category>
      <pubDate>Mon, 10 Mar 2008 21:18:41 GMT</pubDate>
      <author>mprimros</author>
      <guid>http://communities.intel.com/openport/blogs/proexpert/2008/03/10/two-isvs-managing-the-same-client-sure</guid>
      <dc:date>2008-03-10T21:18:41Z</dc:date>
      <clearspace:dateToText>7 months, 21 hours ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/openport/blogs/proexpert/comment/two-isvs-managing-the-same-client-sure</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/proexpert/feeds/comments?blogPostID=10971</wfw:commentRss>
    </item>
    <item>
      <title>Client Manageability Add-on version 3.2 for SMS 2003 Released</title>
      <link>http://communities.intel.com/openport/blogs/proexpert/2008/02/16/client-manageability-addon-version-32-for-sms-2003-released</link>
      <description>Client Manageability Add-on (aka AMT Add-on) version 3.2 for SMS 2003 has been released. For download and more information, please visit: &lt;a class="jive-link-external" href="http://softwarecommunity.intel.com/articles/eng/1356.htm"&gt;http://softwarecommunity.intel.com/articles/eng/1356.htm&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
Bug Fixes / Issues Resolved &lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;An Intel&amp;reg; AMT PC can be configured to use HTTP Digest network communication. Part of the Digest header is a random string which includes the platform UUID. Under certain circumstances depending on the manufacturing flow, it is possible that the Digest UUID and the actual platform UUID as stored in the hardware inventory table do not match. The Intel&amp;reg; Add-on for SMS would reject HTTP Digest communications from a system with mismatching UUIDs. Note that the Digest string uses the UUID purely as a random number and does not use it as an identifier, so there is no reason that they must match. This hotfix amends the functioning to ignore mismatching UUIDs.&lt;/li&gt;
&lt;li&gt;There were cases involving sites containing very large numbers of AMT devices where menu selections would be displayed unacceptably slowly. This has been solved.&lt;/li&gt;
&lt;li&gt;In rare cases, expired advertisements would wake up AMT devices. This has been solved.&lt;/li&gt;
&lt;li&gt;Due to the way in which SMS performs log message collection large numbers of messages are collected, many of which are not critical AMT device messages. Although these messages are valid, they are nonetheless not required in many situations. A workaround has been implemented that allows for the suppression of various levels of non-critical messages.&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
New Features from 3.1 to 3.2 &lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;The Add-on service account no longer requires local administrator permissions.&lt;/li&gt;
&lt;li&gt;There is no longer a need for a dedicated Add-on service account. The user specifies the Add-on service account during installation.&lt;/li&gt;
&lt;li&gt;New Active Directory groups.&lt;/li&gt;
&lt;li&gt;The Add-on is integrated with version 3.3 of the Intel&amp;reg; AMT Setup and Configuration Service.&lt;/li&gt;
&lt;li&gt;Operations no longer require SMS Administer permissions, except for changing the Add-on Settings.&lt;/li&gt;
&lt;li&gt;A user in the Redirection Managers group can terminate another user's redirection operation.&lt;/li&gt;
&lt;/ul&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
Matt Royer</description>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">sms</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">vpro</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">add-on</category>
      <pubDate>Sat, 16 Feb 2008 07:20:33 GMT</pubDate>
      <author>miroyer</author>
      <guid>http://communities.intel.com/openport/blogs/proexpert/2008/02/16/client-manageability-addon-version-32-for-sms-2003-released</guid>
      <dc:date>2008-02-16T07:20:33Z</dc:date>
      <clearspace:dateToText>7 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/openport/blogs/proexpert/comment/client-manageability-addon-version-32-for-sms-2003-released</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/proexpert/feeds/comments?blogPostID=10914</wfw:commentRss>
    </item>
    <item>
      <title>New items posted to Known Issues/Best Practices wiki</title>
      <link>http://communities.intel.com/openport/blogs/proexpert/2008/02/08/new-items-posted-to-known-issuesbest-practices-wiki</link>
      <description>&lt;h5&gt;Here's the weekly update of issues posted to the &lt;a class="jive-link-wiki" href="http://communities.intel.com/openport/docs/DOC-1247"&gt;Known Issues, Best Practices, and Workarounds&lt;/a&gt; wiki:&lt;/h5&gt;
&lt;span style="font-size:11px"&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a class="jive-link-external" href="http://communities.intel.com/docs/DOC-1247#INF1"&gt;Is an IDE-R recommended over a WAN?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="jive-link-external" href="http://communities.intel.com/docs/DOC-1247#ISV_A2"&gt;Can the Default provisionserver naming conventions be changed?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="jive-link-external" href="http://communities.intel.com/docs/DOC-1247#SMS3"&gt;The Intel(R) AMT Add-on for Microsoft* SMS is unable to communicate with the SCS over a standard HTTP connection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="jive-link-external" href="http://communities.intel.com/docs/DOC-1247#O-BIOS3"&gt;Ctrl + P prompt missing when CMOS battery unplugged&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/span&gt;</description>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">sms</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">amt</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">scs</category>
      <pubDate>Fri, 08 Feb 2008 21:13:35 GMT</pubDate>
      <author>michelegartner</author>
      <guid>http://communities.intel.com/openport/blogs/proexpert/2008/02/08/new-items-posted-to-known-issuesbest-practices-wiki</guid>
      <dc:date>2008-02-08T21:13:35Z</dc:date>
      <clearspace:dateToText>8 months, 5 days ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/openport/blogs/proexpert/comment/new-items-posted-to-known-issuesbest-practices-wiki</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/proexpert/feeds/comments?blogPostID=10881</wfw:commentRss>
    </item>
    <item>
      <title>Intel(R) AMT Add-on for SMS - Hotfix 3 is available</title>
      <link>http://communities.intel.com/openport/blogs/proexpert/2007/11/05/intelr-amt-addon-for-sms-hotfix-3-is-available</link>
      <description>&lt;h4&gt;Using the Intel&amp;reg; Active Management Technology (Intel&amp;reg; AMT) add-on for Microsoft SMS 2003* on a Dell 755 returns a UUID error&lt;/h4&gt;
&lt;b&gt;PROBLEM&lt;/b&gt;&lt;br /&gt;
Using the Intel^&amp;reg;^ AMT add-on for Microsoft SMS 2003* on a Dell 755 returns this error: &lt;br clear="all" /&gt;&lt;i&gt;Current system UUID is different from last discovered UUID. Please rediscover the system.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;RESOLUTION&lt;/b&gt;&lt;br /&gt;
An Intel^&amp;reg;^ AMT add-on for Microsoft SMS 3.0 hot fix 3 is available online at &lt;a class="jive-link-external" href="http://www.intel.com/software/sms-add-on"&gt;http://www.intel.com/software/sms-add-on&lt;/a&gt;. &lt;br clear="all" /&gt;This hot fix removes the continuity check between the SMBIOS and the Digest UUID, which was determined to be an unnecessary check. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;MORE INFORMATION&lt;/b&gt;&lt;br /&gt;
&lt;a class="jive-link-external" href="http://downloadcenter.intel.com/detail_desc.aspx?strstate=live&amp;#38;productid=2609&amp;#38;dwnldid=11609&amp;#38;agr=n&amp;#38;lang=eng&amp;#38;prdmap=2609"&gt;Click here to download the hot fix&lt;/a&gt;. &lt;br clear="all" /&gt;Please review the &lt;a class="jive-link-external" href="http://downloadmirror.intel.com/11609/ENG/Release%20Notes%20Add-on%203.0.pdf"&gt;release notes&lt;/a&gt; and the &lt;a class="jive-link-external" href="http://downloadmirror.intel.com/11609/ENG/SMS%20Add-on%20Quick%20Start%20Guide.pdf"&gt;Read Me&lt;/a&gt; file to learn more.</description>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">amt</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">vpro</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">vpro_expert_center</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">sms</category>
      <pubDate>Mon, 05 Nov 2007 18:02:00 GMT</pubDate>
      <author>michelegartner</author>
      <guid>http://communities.intel.com/openport/blogs/proexpert/2007/11/05/intelr-amt-addon-for-sms-hotfix-3-is-available</guid>
      <dc:date>2007-11-05T18:02:00Z</dc:date>
      <clearspace:dateToText>11 months, 1 week ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/openport/blogs/proexpert/comment/intelr-amt-addon-for-sms-hotfix-3-is-available</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/proexpert/feeds/comments?blogPostID=10713</wfw:commentRss>
    </item>
    <item>
      <title>I’d Like to Tell YOU where to Stick that Certificate</title>
      <link>http://communities.intel.com/openport/blogs/proexpert/2007/10/05/i-d-like-to-tell-you-where-to-stick-that-certificate</link>
      <description>Well, it probably won&amp;rsquo;t work if you stick it there, but the&lt;br /&gt;
truth is that there are a lot of certificates used in AMT, and knowing where to&lt;br /&gt;
put those certificates and their private keys can save a lot of hair pulling&lt;br /&gt;
down the line. &lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=if+gte+vml+1"&gt;if gte vml 1&lt;/a&gt;&gt;&lt;v:shapetype&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
id="_x0000_t75" coordsize="21600,21600" o:spt="75" o:preferrelative="t"&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f"&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:stroke joinstyle="miter"/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:formulas&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:f eqn="if lineDrawn pixelLineWidth 0"/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:f eqn="sum @0 1 0"/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:f eqn="sum 0 0 @1"/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:f eqn="prod @2 1 2"/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:f eqn="prod @3 21600 pixelWidth"/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:f eqn="prod @3 21600 pixelHeight"/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:f eqn="sum @0 0 1"/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:f eqn="prod @6 1 2"/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:f eqn="prod @7 21600 pixelWidth"/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:f eqn="sum @8 21600 0"/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:f eqn="prod @7 21600 pixelHeight"/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:f eqn="sum @10 21600 0"/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;/v:formulas&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect"/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;o:lock v:ext="edit" aspectratio="t"/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;/v:shapetype&gt;&lt;v:shape id="_x0000_i1025" type="#_x0000_t75" style='width:561pt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
height:433.5pt' o:ole=""&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:imagedata src="file:///C:\DOCUME~1\gjbevan\LOCALS~1\Temp\msohtmlclip1\01\clip_image001.emz"&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
o:title=""/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;/v:shape&gt;&lt;!&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=endif"&gt;endif&lt;/a&gt;--&gt;&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=if+%21vml"&gt;if !vml&lt;/a&gt;--&gt;&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-10659-1075/AMT+Certs.jpg" alt="AMT Certs.jpg" width="620" class="jive-image-thumbnail jive-image" onclick="myJiveImage.start(this, 'http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-10659-1075/AMT+Certs.jpg');return false;"/&gt;&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=endif"&gt;endif&lt;/a&gt;--&gt;&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=if+gte+mso+9"&gt;if gte mso 9&lt;/a&gt;&gt;&lt;xml&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;o:OLEObject Type="Embed" ProgID="Visio.Drawing.11" ShapeID="_x0000_i1025"&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
DrawAspect="Content" ObjectID="_1253102892"&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;/o:OLEObject&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;/xml&gt;&lt;!&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=endif"&gt;endif&lt;/a&gt;--&gt;&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
&lt;h1&gt;AMT Certificates&lt;/h1&gt;
Let&amp;rsquo;s start with the AMT system itself. &lt;br /&gt;
&lt;br /&gt;
&lt;h2&gt;TLS Certificate&lt;/h2&gt;
If the SCS profile calls for TLS to be enabled then a&lt;br /&gt;
private key and certificate are generated at the SCS and then installed on the&lt;br /&gt;
Amt device as part of the provisioning process. This certificate and key are&lt;br /&gt;
then used in future communications between the SCS and the AMT device and the&lt;br /&gt;
Management Console and the AMT device. I&amp;rsquo;m going to use the SMS Add-on as an&lt;br /&gt;
example of the management console because it uses gSOAP libraries which have&lt;br /&gt;
addition certificate storage requirements. &lt;br /&gt;
&lt;br /&gt;
&lt;h2&gt;802.1x Certificate&lt;/h2&gt;
If the SCS profile calls for and 802.1x certificate then a&lt;br /&gt;
private key and certificate are generated at the SCS and installed on the AMT&lt;br /&gt;
device as part of the provisioning process. This certificate and key are used&lt;br /&gt;
to allow the AMT device to connect to an 802.1x protected network without the&lt;br /&gt;
host operating system being available. &lt;br /&gt;
&lt;br /&gt;
&lt;h2&gt;Mutual Authentication Root Certificate (MTLS Root)&lt;/h2&gt;
The MTLS root certificate is used by the AMT device to&lt;br /&gt;
validate the mutual authentication certificate provided by the SCS or&lt;br /&gt;
management console after provisioning has completed. (Assuming of course that&lt;br /&gt;
the SCS profile used for provisioning configures MTLS). This certificate is&lt;br /&gt;
installed during the provisioning process. Note only the certificate is&lt;br /&gt;
installed &amp;ndash; there is no private key installed for this certificate. &lt;br /&gt;
&lt;br /&gt;
&lt;h1&gt;h1. Remote Configuration&lt;/h1&gt;
The remaining two certificates on the AMT device are used&lt;br /&gt;
for Remote Configuration. This feature is available in AMT 2.2, 2.6 and 3.0.&lt;br /&gt;
(Note that does not include 2.5).&lt;br /&gt;
&lt;br /&gt;
&lt;h2&gt;Remote Configuration Root Certificate (RCFG Root)&lt;/h2&gt;
Actually this is not a whole certificate. It&amp;rsquo;s just the&lt;br /&gt;
certificate thumbnail, referred to as a hash. The certificate hashes can come&lt;br /&gt;
from a couple of places:&lt;br /&gt;
&lt;br /&gt;
&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=if+%21supportLists"&gt;if !supportLists&lt;/a&gt;--&gt;&lt;span style="font-family:Symbol"&gt;&amp;middot;&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal"&gt;{font:'Times New Roman'}&lt;span style="font-size:7pt"&gt;        &lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=endif"&gt;endif&lt;/a&gt;--&gt;The AMT systems come with default certificate&lt;br /&gt;
hashes from VeriSign, GoDaddy and Comodo.&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=if+%21supportLists"&gt;if !supportLists&lt;/a&gt;--&gt;&lt;span style="font-family:Symbol"&gt;&amp;middot;&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal"&gt;{font:'Times New Roman'}&lt;span style="font-size:7pt"&gt;        &lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=endif"&gt;endif&lt;/a&gt;--&gt;Your OEM can place a certificate hash of your&lt;br /&gt;
choosing on to the AMT devices you buy as part of their manufacturing process.&lt;br /&gt;
E.g. if you have your own PKI and wish to use your own root certificate.&lt;br /&gt;
&lt;br /&gt;
&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=if+%21supportLists"&gt;if !supportLists&lt;/a&gt;--&gt;{font:Symbol}&amp;middot;&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal"&gt;{font:'Times New Roman'}&lt;span style="font-size:7pt"&gt;        &lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=endif"&gt;endif&lt;/a&gt;--&gt; You can&lt;br /&gt;
manually enter the certificate hash into the MEBx screen.&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
The advantages and disadvantages of each of these methods&lt;br /&gt;
are best left for another discussion.&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
This certificate is used to validate the remote&lt;br /&gt;
configuration certificate provided to the AMT device by the SCS service that is&lt;br /&gt;
trying to provision the AMT device. The details of this validation are somewhat&lt;br /&gt;
complicated and also best left to another discussion. &lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
&lt;h2&gt;Remote Configuration Self Signed Certificate&lt;/h2&gt;
Finally the remote &lt;br /&gt;
configuration processes requires the AMT device to generated its own self&lt;br /&gt;
signed (i.e. there is no certificate authority involved &amp;ndash; and hence no trust&lt;br /&gt;
established) certificate to serve as a TLS/SSL certificate in place of the Pre&lt;br /&gt;
Shared Key (PSK) that was used to protect provision in earlier version of AMT.&lt;br /&gt;
Both the certificate and the key are generated locally on the AMT system.&lt;br /&gt;
&lt;br /&gt;
&lt;h1&gt;SCS Certificates&lt;/h1&gt;
Once we get to the server side, certificates become more&lt;br /&gt;
interesting as we have to know which Windows certificate store to put the&lt;br /&gt;
certificate and private key.&lt;br /&gt;
&lt;br /&gt;
The SCS requires four certificates. &lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
&lt;h2&gt;SSL Certificate&lt;/h2&gt;
The SCS service runs as a web service within IIS.&lt;br /&gt;
Connections to the service can be carried out by the SCS console or by an ISV&lt;br /&gt;
supplied UI. To secure this traffic the SCS service requires that these web&lt;br /&gt;
services be protected by TLS/SSL. The SSL certificate is the same type used to&lt;br /&gt;
secure other web servers like amazon.com or eBay. &lt;br /&gt;
&lt;br /&gt;
This certificate is installed in the Windows certificate&lt;br /&gt;
store of the service account used to run IIS. If you use the IIS &amp;ldquo;Server&lt;br /&gt;
Certificate&amp;rdquo; this is a two step process. First the IIS server generates the&lt;br /&gt;
private key and a certificate request. The private key is stored in the IIS&lt;br /&gt;
service account key store, and the request is stored in a text file. The&lt;br /&gt;
certificate request is then sent to the CA who issues the certificate. The&lt;br /&gt;
wizard then installs the certificate and matches it up with the private key. &lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=if+gte+vml+1"&gt;if gte vml 1&lt;/a&gt;&gt;&lt;v:shape id="_x0000_i1026"&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
type="#_x0000_t75" style='width:555pt;height:444pt' o:ole=""&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:imagedata src="file:///C:\DOCUME~1\gjbevan\LOCALS~1\Temp\msohtmlclip1\01\clip_image003.emz"&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
o:title=""/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;/v:shape&gt;&lt;!&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=endif"&gt;endif&lt;/a&gt;--&gt;&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=if+%21vml"&gt;if !vml&lt;/a&gt;--&gt;&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-10659-1077/SCS+Certs.jpg" alt="SCS Certs.jpg" width="620" class="jive-image-thumbnail jive-image" onclick="myJiveImage.start(this, 'http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-10659-1077/SCS+Certs.jpg');return false;"/&gt;&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=endif"&gt;endif&lt;/a&gt;--&gt;&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=if+gte+mso+9"&gt;if gte mso 9&lt;/a&gt;&gt;&lt;xml&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;o:OLEObject Type="Embed" ProgID="Visio.Drawing.11" ShapeID="_x0000_i1026"&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
DrawAspect="Content" ObjectID="_1253102893"&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;/o:OLEObject&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;/xml&gt;&lt;!&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=endif"&gt;endif&lt;/a&gt;--&gt;&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
&lt;h2&gt;TLS Root&lt;/h2&gt;
The TLS root certificate is the root certificate from the&lt;br /&gt;
certificate chain that issued the TLS certificates to the AMT devices. This may&lt;br /&gt;
or may not be the same as your MTLS Root, depending on how you issue your&lt;br /&gt;
certs. This certificate is used to validate the TLS certificate provided by the&lt;br /&gt;
AMT device when the SCS connects to the device to perform some function after&lt;br /&gt;
initial provisioning. This could be re-provisioning or one of the maintenance&lt;br /&gt;
tasks that the SCS performs &amp;ndash; like setting the AMT system time. &lt;br /&gt;
&lt;br /&gt;
There is no private key associated with this certificate.&lt;br /&gt;
The certificate should be stored in the &amp;ldquo;Trusted Root Certification&lt;br /&gt;
Authorities&amp;rdquo; folder of the SCS service accounts certificate store. &lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
&lt;h2&gt;Mutual TLS Authentication Certificate&lt;/h2&gt;
This certificate is used by the SCS to authenticate itself&lt;br /&gt;
to the AMT devices. Both the certificate and the private key should be stored&lt;br /&gt;
in the SCS service accounts &amp;ldquo;Personal&amp;rdquo; certificate store. The root certificate&lt;br /&gt;
of the chain must be installed on the AMT device during provisioning to allow&lt;br /&gt;
this authentication mechanism to work correctly. &lt;br /&gt;
&lt;br /&gt;
&lt;h2&gt;Remote Configuration Certificate&lt;/h2&gt;
This is the most interesting of the three SCS service&lt;br /&gt;
certificates. This is because the certificate needs to be in two certificate&lt;br /&gt;
stores &amp;ndash; but the private key only needs to be in one. The SCS service presents&lt;br /&gt;
this certificate to the AMT device to start remote provisioning. As this is a&lt;br /&gt;
mutually authenticated TLS session, the SCS service must have access to the&lt;br /&gt;
private key. So the certificate and private key should be installed in the SCS&lt;br /&gt;
service accounts certificate store. &lt;br /&gt;
&lt;br /&gt;
To configure SCS for remote configuration, a utility called&lt;br /&gt;
&amp;ldquo;loadcert.exe&amp;rdquo; is run. This utility lists the certificates in the local&lt;br /&gt;
computer store and you select the one you want the SCS service to use for&lt;br /&gt;
remote configuration. The utility then make a registry entry containing the&lt;br /&gt;
thumbnail of the certificate. The SCS service looks at this registry entry and&lt;br /&gt;
then looks up the selected certificate in the SCS service account certificate&lt;br /&gt;
store. Because the loadcert.exe utility reads from the local computer store,&lt;br /&gt;
the remote configuration certificate needs to be installed in there. But,&lt;br /&gt;
because it is only read by the utility to extract the thumbnail, the private&lt;br /&gt;
key does not have to be installed in the local computer store.&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
&lt;h1&gt;SMS (Management Console) Certificates&lt;/h1&gt;
Certificates for the SMS Add-on are complicated by the use&lt;br /&gt;
of the gSOAP libraries. GSOAP is a cross platform, open source web services&lt;br /&gt;
development toolkit. Because it is cross platform it does not (obviously) use&lt;br /&gt;
the windows certificate store. Instead it uses a file format called PEM (from&lt;br /&gt;
the Privacy Enhanced Mail system). PEM files store certificates and keys as&lt;br /&gt;
base-64 encoded strings. This makes them easy to manipulate (with things like&lt;br /&gt;
notepad) and portable between systems. The following discussion assumes a 3&lt;br /&gt;
level PKI hierarchy, with a root CA, policy CA and an issuing CA. If there is&lt;br /&gt;
sufficient interest I can talk about PKI hierarchies on a separate thread.&lt;br /&gt;
&lt;br /&gt;
As the SMS is also a windows program, it also needs its&lt;br /&gt;
certificates in the windows store.&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=if+gte+vml+1"&gt;if gte vml 1&lt;/a&gt;&gt;&lt;v:shape id="_x0000_i1027"&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
type="#_x0000_t75" style='width:566.25pt;height:407.25pt' o:ole=""&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;v:imagedata src="file:///C:\DOCUME~1\gjbevan\LOCALS~1\Temp\msohtmlclip1\01\clip_image005.emz"&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
o:title=""/&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;/v:shape&gt;&lt;!&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=endif"&gt;endif&lt;/a&gt;--&gt;&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=if+%21vml"&gt;if !vml&lt;/a&gt;--&gt;&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-10659-1076/SMS+Certs.jpg" alt="SMS Certs.jpg" width="620" class="jive-image-thumbnail jive-image" onclick="myJiveImage.start(this, 'http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-10659-1076/SMS+Certs.jpg');return false;"/&gt;&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=endif"&gt;endif&lt;/a&gt;--&gt;&lt;!--&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=if+gte+mso+9"&gt;if gte mso 9&lt;/a&gt;&gt;&lt;xml&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;o:OLEObject Type="Embed" ProgID="Visio.Drawing.11" ShapeID="_x0000_i1027"&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
DrawAspect="Content" ObjectID="_1253102894"&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;/o:OLEObject&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;/xml&gt;&lt;!&lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=endif"&gt;endif&lt;/a&gt;--&gt;&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
&lt;h2&gt;h2. Mutual Authentication Certificate (MTLS)&lt;/h2&gt;
If the AMT profile the SCS calls for mutual TLS, then the&lt;br /&gt;
management console needs to supply an MTLSS certificate. This certificate, and&lt;br /&gt;
its private key, needs to be installed in SMS Add-on Service account&lt;br /&gt;
certificate store. This allows the SMS Add-on service to access the key for&lt;br /&gt;
operations such as power management.  Because&lt;br /&gt;
the windows certificate store can &amp;ldquo;walk certificate chains&amp;rdquo;, only the MTLS cert&lt;br /&gt;
needs to be installed. Windows will work out where to get the rest of the chain&lt;br /&gt;
from on its own. &lt;br /&gt;
&lt;br /&gt;
This is not true for the PEM file. In order for the gSOAP&lt;br /&gt;
library to have access to the certificate chain, all the chain entries must be&lt;br /&gt;
placed in the file (in the right order). &lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
&lt;h2&gt;TLS Root Certificate&lt;/h2&gt;
When a connection to the AMT device is made, it presents its&lt;br /&gt;
TLS certificate. In order for the Management console to trust the certificate,&lt;br /&gt;
the root certificate the issued the AMT certificate must be installed in the&lt;br /&gt;
&amp;ldquo;Trusted Root Certification Authorities&amp;rdquo; folder in the SMS Add-on&amp;rsquo;s certificate&lt;br /&gt;
store. .  Because the windows certificate&lt;br /&gt;
store can &amp;ldquo;walk certificate chains&amp;rdquo;, only the TLS root cert needs to be installed.&lt;br /&gt;
&lt;br /&gt;
Again, this is not true for the PEM file. In order for the&lt;br /&gt;
gSOAP library to have access to the certificate chain, all the chain entries&lt;br /&gt;
must be placed in the file (in the right order). &lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;br /&gt;</description>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">certificates</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">pki</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">amt</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">vpro</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">remote_config</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">pem</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">keys</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">private_key</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">public_key</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">scs</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">sms</category>
      <pubDate>Fri, 05 Oct 2007 22:39:00 GMT</pubDate>
      <author>Gareth Bevan</author>
      <guid>http://communities.intel.com/openport/blogs/proexpert/2007/10/05/i-d-like-to-tell-you-where-to-stick-that-certificate</guid>
      <dc:date>2007-10-05T22:39:00Z</dc:date>
      <clearspace:dateToText>1 year, 2 days ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/openport/blogs/proexpert/comment/i-d-like-to-tell-you-where-to-stick-that-certificate</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/proexpert/feeds/comments?blogPostID=10659</wfw:commentRss>
    </item>
  </channel>
</rss>

