Home > Intel Communities > Open Port IT Community > Intel® vPro™ Expert Center > Ask An Expert > Discussions

This Question is Possibly Answered

1 "correct" answer available (4 pts) 2 "helpful" answers available (2 pts)
38 Replies Last post: Apr 10, 2008 2:53 AM by Sebastian Belz   1 2 3 Previous Next
Sebastian Belz   1 posts since
Apr 10, 2008
Reply
Currently Being Moderated

Apr 10, 2008 8:32 AM

SCCM SP1 Out of Band Mgmt AMT Client Settings

 

We are deploying a lot of new clients. Dell hasn't out a AMT 3.2 version yet on their clients wich is required for SCCM Out of Band Mgmt. So we can't test the integration with SCCM SP1 Beta.

 

 

We must order the clients now and don't know the required AMT Client Settings. We want to set all the settings by our OEM (Dell) before the hardware delivery.

 

 

We have an internal Microsoft Enterprise Root CA. We want to use Remote Configuration. When not required we want to use internal certificates and not official certificates.

 

 

What settings are required in the AMT Bios that we can automatically integrate our clients to SCCM SP1 Out of Band Mgmt?

 

 

Do we need to import the Root CA from our internal MS Enterprise Root CA on the AMT Clients or can we do this over Remote Configuration? Are any other settings requires? (Passwords, Ent. Mode, Provision Server)

 

 

Thanks and best regards

 

 

Reply
Average User Rating
(0 ratings)




Matt Royer   123 posts since
Aug 31, 2007
Currently Being Moderated
1. Apr 10, 2008 9:02 AM in response to: Sebastian Belz
Re: SCCM SP1 Out of Band Mgmt AMT Client Settings

 

Microsoft and Intel have included support for AMT firmware versions less than 3.2 with the inclusion of the WS-MAN Translator that will be released and integrated with SCCM SP1 with the release RC1. The SCCM SP1 beta today does support 3.x clients for testing validation purposes; however, there will be a hard requirement to use the WS-Translator with any client less than 3.2 once RC1 releases.

To avoid having to manually configure your internal CA root hash, you can work with your OEM to have the cert hash of your provisioning cert issuing CA pre-loaded into firmware. Other then the root cert hash of your internal CA, that should be all you need to do. Although, the default admin password will be changed as SCCM goes through the provisioning process, you can request the OEM to pre-configure the MEBx password for you. This will need to match what you configured your SCCM environment with.

 

 

 

 

Matt Royer

 

 

David Randall   26 posts since
May 2, 2008
Currently Being Moderated
2. May 3, 2008 9:18 AM in response to: Sebastian Belz
Re: SCCM SP1 Out of Band Mgmt AMT Client Settings

 

I realize your question was about the Beta build, and we've now shipped the RC (release candidate) build, but I'll answer your questions specifically about Beta first, then about the Release candidate.

 

 

FOR BETA: The only setting required in BIOS (MEBx really) to enable remote provisioning initiated by the SCCM client agent is the root certificate hash of your internal CA must be entered in the cert hash list. Now, if you've entered in the root cert hash through the MEBx (or the USBFILE utility), you've also likely had to change the MEBx password, so you'll need to add that into the list of provisioning accounts/passwords (admin is the account name, and enter the MEBx account's password as your provisioning password). We only support Enterprise mode, so AMT will need to be set to run in that mode (which is the default mode).

 

 

The beta actually supports the Dell 3.0 firmware version. There were some changes between Beta and RC that required 3.2 - so if you're testing the RC, you'll need the 3.2, but if you're still testing the Beta version, you can use your Dell 755's with the 3.0 firmware. And, Matt's comment about the translator applies to 3.0 firmware for the final release of SP1 - you'll need that if you have systems that aren't updated to 3.2, or you have 2.1, 2.2, 2.5 or 2.6 AMT in your environment.

 

 

FOR RC: The only setting required in BIOS (MEBx really) to enable remote provisioning initiated by the SCCM client agent is the root certificate hash of your internal CA must be entered in the cert hash list. Again, if you've added the cert hash manually, then enter the MEBx password into the "Provisioning/Discovery" account list.

 

 

SCCM can automatically register an alias in DNS for the out of band service point (checkbox option in the Out of Band Management properties in Component Configuration), so you wont' need to update the firmware with the IP address or name of your provisioning server (unless you want to).

 

 

Lastly, if you have downloaded the release candidate from the connect.microsoft.com web site, you should take a look through the help file. Click the search tab, and type in "out of band" to find all the AMT related content. There are step by step walkthroughs of setting up your certificates, cert templates, and lots of information on the prerequisites and specific requirements.

 

 

Hope that helps, and please ask more questions if you have them.

 

 

Dave Randall

 

 

kobile   16 posts since
Jun 2, 2008
Currently Being Moderated
3. Jun 2, 2008 12:20 PM in response to: David Randall
Re: SCCM SP1 Out of Band Mgmt AMT Client Settings

 

Hi,

 

 

i just finished setup all the requerments including the HASH and still the SCCM having problems to provisin my Dell 755 machine, in the \SCCMInstall\Logs\amtopmgr.log i'm getting :

 

 

incoming connection from (client ip address) x.x.x.x:16994

incoming data is: Configuration version: PKI Configuration

Count: 5

UUID: The client UUID

Found matched hash from hello ......

Warrnig: AMT device UUID is SMS Client: Reject hello message to provision

waiting to incoming hello....

 

 

i can't get any luck with this , any idea?

 

 

thanks in advanced,

 

 

Kobi

 

 

David Randall   26 posts since
May 2, 2008
Currently Being Moderated
4. Jun 2, 2008 12:59 PM in response to: kobile
Re: SCCM SP1 Out of Band Mgmt AMT Client Settings

 

The log file indicates that your computer currently has the SCCM agent installed. When the OOBSP receives a hello packet from a computer that is already a SCCM client, it will reject the packet.

 

 

To initiate provisioning for that computer, make a collection with that one computer in it (a direct member collection is fine). Then, right click the collection, choose "Modify collection settings" and select the Out of Band tab. Enable the checkbox on that page and save the settings. Then, right click the collection and choose "update collection membership" to get the policy generated right away.

 

 

Now, your client will get the policy and initiate provisioning. Normally, the policy polling interval is 60 minutes. You could go to the ctrl panel applet on that client system and do the "initiate machine policy retrieval and evaluation" to kick start it.

 

 

Let us know how it goes.

 

 

Dave

 

 

More Like This

  • Retrieving data ...