We are deploying a lot of new clients. Dell hasn't out a AMT 3.2 version yet on their clients wich is required for SCCM Out of Band Mgmt. So we can't test the integration with SCCM SP1 Beta.
We must order the clients now and don't know the required AMT Client Settings. We want to set all the settings by our OEM (Dell) before the hardware delivery.
We have an internal Microsoft Enterprise Root CA. We want to use Remote Configuration. When not required we want to use internal certificates and not official certificates.
What settings are required in the AMT Bios that we can automatically integrate our clients to SCCM SP1 Out of Band Mgmt?
Do we need to import the Root CA from our internal MS Enterprise Root CA on the AMT Clients or can we do this over Remote Configuration? Are any other settings requires? (Passwords, Ent. Mode, Provision Server)
Thanks and best regards
Microsoft and Intel have included support for AMT firmware versions less than 3.2 with the inclusion of the WS-MAN Translator that will be released and integrated with SCCM SP1 with the release RC1. The SCCM SP1 beta today does support 3.x clients for testing validation purposes; however, there will be a hard requirement to use the WS-Translator with any client less than 3.2 once RC1 releases.
To avoid having to manually configure your internal CA root hash, you can work with your OEM to have the cert hash of your provisioning cert issuing CA pre-loaded into firmware. Other then the root cert hash of your internal CA, that should be all you need to do. Although, the default admin password will be changed as SCCM goes through the provisioning process, you can request the OEM to pre-configure the MEBx password for you. This will need to match what you configured your SCCM environment with.
Matt Royer
I realize your question was about the Beta build, and we've now shipped the RC (release candidate) build, but I'll answer your questions specifically about Beta first, then about the Release candidate.
FOR BETA: The only setting required in BIOS (MEBx really) to enable remote provisioning initiated by the SCCM client agent is the root certificate hash of your internal CA must be entered in the cert hash list. Now, if you've entered in the root cert hash through the MEBx (or the USBFILE utility), you've also likely had to change the MEBx password, so you'll need to add that into the list of provisioning accounts/passwords (admin is the account name, and enter the MEBx account's password as your provisioning password). We only support Enterprise mode, so AMT will need to be set to run in that mode (which is the default mode).
The beta actually supports the Dell 3.0 firmware version. There were some changes between Beta and RC that required 3.2 - so if you're testing the RC, you'll need the 3.2, but if you're still testing the Beta version, you can use your Dell 755's with the 3.0 firmware. And, Matt's comment about the translator applies to 3.0 firmware for the final release of SP1 - you'll need that if you have systems that aren't updated to 3.2, or you have 2.1, 2.2, 2.5 or 2.6 AMT in your environment.
FOR RC: The only setting required in BIOS (MEBx really) to enable remote provisioning initiated by the SCCM client agent is the root certificate hash of your internal CA must be entered in the cert hash list. Again, if you've added the cert hash manually, then enter the MEBx password into the "Provisioning/Discovery" account list.
SCCM can automatically register an alias in DNS for the out of band service point (checkbox option in the Out of Band Management properties in Component Configuration), so you wont' need to update the firmware with the IP address or name of your provisioning server (unless you want to).
Lastly, if you have downloaded the release candidate from the connect.microsoft.com web site, you should take a look through the help file. Click the search tab, and type in "out of band" to find all the AMT related content. There are step by step walkthroughs of setting up your certificates, cert templates, and lots of information on the prerequisites and specific requirements.
Hope that helps, and please ask more questions if you have them.
Dave Randall
Hi,
i just finished setup all the requerments including the HASH and still the SCCM having problems to provisin my Dell 755 machine, in the \SCCMInstall\Logs\amtopmgr.log i'm getting :
incoming connection from (client ip address) x.x.x.x:16994
incoming data is: Configuration version: PKI Configuration
Count: 5
UUID: The client UUID
Found matched hash from hello ......
Warrnig: AMT device UUID is SMS Client: Reject hello message to provision
waiting to incoming hello....
i can't get any luck with this , any idea?
thanks in advanced,
Kobi
The log file indicates that your computer currently has the SCCM agent installed. When the OOBSP receives a hello packet from a computer that is already a SCCM client, it will reject the packet.
To initiate provisioning for that computer, make a collection with that one computer in it (a direct member collection is fine). Then, right click the collection, choose "Modify collection settings" and select the Out of Band tab. Enable the checkbox on that page and save the settings. Then, right click the collection and choose "update collection membership" to get the policy generated right away.
Now, your client will get the policy and initiate provisioning. Normally, the policy polling interval is 60 minutes. You could go to the ctrl panel applet on that client system and do the "initiate machine policy retrieval and evaluation" to kick start it.
Let us know how it goes.
Dave
This site contains user submitted content, comments and opinions and is for informational and entertainment purposes only. INTEL MAKES NO WARRANTIES, EXPRESS OR IMPLIED, WITH REGARDS TO THIS CONTENT. All postings and use of the content on this site are subject to the Terms of Use and Terms of Service of the site.