<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Re:Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA in Intel vPro® Platform</title>
    <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1484059#M10032</link>
    <description>&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;&amp;nbsp;Hello Victor, we had already created the certificate with the OID 2.16.840.1.113741.1.2.3 and sha256.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;We have followed the guide and AMT Auto-Setup is enabled.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt; &lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;As I explained to you, the certificate is correctly loaded on the server, but there is no communication with our clients.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;'We think that we must load our server CA on the clients manually.'&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;Could you please help us?&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;Thanks in advance,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Xevi&lt;/P&gt;</description>
    <pubDate>Mon, 08 May 2023 09:53:02 GMT</pubDate>
    <dc:creator>xevi</dc:creator>
    <dc:date>2023-05-08T09:53:02Z</dc:date>
    <item>
      <title>Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1482364#M9996</link>
      <description>&lt;P&gt;Hi everybody, we are trying to work with EMA and ACM.&lt;/P&gt;
&lt;P&gt;In Client Control Mode everything works fine between EMA server and clients.&lt;/P&gt;
&lt;P&gt;We have create a certificate with our internal CA Server and this Certificate Provisionig(TLS-PKI) is correctly uploaded in EMA Server.&lt;/P&gt;
&lt;P&gt;The problem is that there is no communication between clients and server.&lt;/P&gt;
&lt;P&gt;We think that we must load our server CA on the clients manually.&lt;/P&gt;
&lt;P&gt;Is there any way to make this with EMA Agent?&lt;/P&gt;
&lt;P&gt;Or is there some other better method?&lt;/P&gt;
&lt;P&gt;Is there documentation on this specific topìc?&lt;/P&gt;
&lt;P&gt;Thanks in advance,&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 17:17:24 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1482364#M9996</guid>
      <dc:creator>xevi</dc:creator>
      <dc:date>2023-05-02T17:17:24Z</dc:date>
    </item>
    <item>
      <title>Re:Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1482791#M10005</link>
      <description>&lt;P&gt;Hello xevi,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you so much for contacting Intel customer support,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Before moving forward with your request please provide the information below:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;EMA version being used:&lt;/LI&gt;&lt;LI&gt;AMT version(s) used:&lt;/LI&gt;&lt;LI&gt;Are the endpoints landless systems?&lt;/LI&gt;&lt;LI&gt;Is the EMA server installed on a physical server or a virtual machine?&lt;/LI&gt;&lt;LI&gt;Are the endpoints in the same network as the EMA server?&lt;/LI&gt;&lt;LI&gt;How many endpoints do you have in your deployment?&lt;/LI&gt;&lt;LI&gt;Please share the OS being used on the EMA server.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Victor G. &lt;/P&gt;&lt;P&gt;Intel Technical Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 03 May 2023 17:44:59 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1482791#M10005</guid>
      <dc:creator>Victor_G_Intel</dc:creator>
      <dc:date>2023-05-03T17:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1482811#M10006</link>
      <description>&lt;P&gt;&amp;nbsp;Hello Victor, I answer your request:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Intel EMA v1.9.1.0&lt;BR /&gt;EMA Agent v1.9.0&lt;BR /&gt;Intel ME v16.1.25.1932&lt;BR /&gt;Windows Server 2022 21H2 physical server&lt;BR /&gt;Endpoints with Windows 11 22H2 and connected wired&lt;BR /&gt;At the moment 7 endpoint, but it will be many more&lt;BR /&gt;With Client Control Mode we can 'see' our computers CIRA connected in band, out band and also outside and inside our company.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Xevi&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 18:43:28 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1482811#M10006</guid>
      <dc:creator>xevi</dc:creator>
      <dc:date>2023-05-03T18:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1482966#M10012</link>
      <description>&lt;P&gt;Sorry Victor,&lt;/P&gt;
&lt;P&gt;Windows Server 2022 21H2 virtualized server&lt;/P&gt;
&lt;P&gt;In case it's important&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 07:12:57 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1482966#M10012</guid>
      <dc:creator>xevi</dc:creator>
      <dc:date>2023-05-04T07:12:57Z</dc:date>
    </item>
    <item>
      <title>Re:Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1483155#M10017</link>
      <description>&lt;P&gt;Hello xevi,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you for your response&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regarding your questions, most of the information you need to set up your endpoints correctly in ACM is in our &lt;A href="https://www.intel.com/content/dam/support/us/en/documents/software/manageability-products/intel-ema-admin-and-usage-guide.pdf" rel="noopener noreferrer" target="_blank"&gt;Intel® Endpoint Management Assistant (Intel® EMA) Administration and Usage Guide&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Since your systems are not LAN-less what you need to do based on the instructions provided in our guide is to upload a PKI certificate, which will enable Intel EMA to set the endpoint’s Intel AMT into Admin Control Mode (ACM); however, there are a few considerations that you need to keep in mind, the certificate file needs to have the full certificate chain; additionally, it needs to be issued with the supported OID 2.16.840.1.113741.1.2.3 (this is the unique Intel AMT OID).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Another important thing to consider here is that starting with Intel ME 15.0 firmware for desktops, and Intel ME 16.0 firmware for all platforms, Intel is removing support of SHA1 root certificates and RSA key sizes smaller than 2048 bits for Intel AMT provisioning. In those releases and later, it is no longer possible to add SHA1 hashes; therefore, all your certs must be SHA256 based on the AMT version you are currently working with.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;In regard to the options to do the provisioning in ACM, we recommend enabling the Intel® AMT Auto-Setup (section 3.6 page 27 of our guide).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Victor G. &lt;/P&gt;&lt;P&gt;Intel Technical Support Technician&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 04 May 2023 18:44:57 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1483155#M10017</guid>
      <dc:creator>Victor_G_Intel</dc:creator>
      <dc:date>2023-05-04T18:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1484059#M10032</link>
      <description>&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;&amp;nbsp;Hello Victor, we had already created the certificate with the OID 2.16.840.1.113741.1.2.3 and sha256.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;We have followed the guide and AMT Auto-Setup is enabled.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt; &lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;As I explained to you, the certificate is correctly loaded on the server, but there is no communication with our clients.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;'We think that we must load our server CA on the clients manually.'&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;Could you please help us?&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;Thanks in advance,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Xevi&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2023 09:53:02 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1484059#M10032</guid>
      <dc:creator>xevi</dc:creator>
      <dc:date>2023-05-08T09:53:02Z</dc:date>
    </item>
    <item>
      <title>Re:Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1484341#M10035</link>
      <description>&lt;P&gt;Hello xevi,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;This looks like there are 2 separate issues here. &lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Communication between EMA server - nodes&lt;/LI&gt;&lt;LI&gt;Provisioning certificate to make the nodes Admin Control Mode&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The connectivity issue might be related to your network environment. For testing purposes, you want to have the EMA server and the provisioned nodes within the same LAN. External LAN is possible by opening ports&lt;/P&gt;&lt;P&gt;The provisioning cert is only required for provisioning the nodes in Admin Control Mode (ACM). Without the cert the node will provision in Client Control Mode, but the communication should still exist. &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Jose A.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 09 May 2023 00:48:00 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1484341#M10035</guid>
      <dc:creator>JoseH_Intel</dc:creator>
      <dc:date>2023-05-09T00:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1484434#M10040</link>
      <description>&lt;P&gt;&amp;nbsp;Hello Jose A., the first sentence of the post was:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;'&lt;SPAN class="sub_section_element_selectors"&gt;In Client Control Mode everything works fine between EMA server and clients.&lt;/SPAN&gt;'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue is in ACM, and because our autosigned cert. No communication with endpoinds.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please help us?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Xevi&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 08:31:41 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1484434#M10040</guid>
      <dc:creator>xevi</dc:creator>
      <dc:date>2023-05-09T08:31:41Z</dc:date>
    </item>
    <item>
      <title>Re:Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1484573#M10044</link>
      <description>&lt;P&gt;Hello Xevi,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you for your response.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;To continue with the assistance and continue investigating on our end please provide the following:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Can you please confirm if the certificate you are using is a self-sign certificate or if it is a certificate provided by a vendor?&lt;/LI&gt;&lt;LI&gt;We will require some pictures of the certificate you are using with EMA, in specific we will require a screenshot showing the full enhanced key usage tab, the full certification path tab, and the OID. Additionally, you will have to make sure all the certificates found in the certificate path of the EMA certificate are SHA256.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Victor G. &lt;/P&gt;&lt;P&gt;Intel Technical Support Technician&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 09 May 2023 17:22:08 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1484573#M10044</guid>
      <dc:creator>Victor_G_Intel</dc:creator>
      <dc:date>2023-05-09T17:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1484969#M10051</link>
      <description>&lt;P&gt;&amp;nbsp;Hello Victor, I send you the pictures.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture_1.PNG" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41138iCFAA2A0BFA3C67E4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="Capture_1.PNG" alt="Capture_1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture_2.PNG" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41139iE613C1CF164D23D8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="Capture_2.PNG" alt="Capture_2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If you need something else, please ask me&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Xevi&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 17:52:07 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1484969#M10051</guid>
      <dc:creator>xevi</dc:creator>
      <dc:date>2023-05-10T17:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1484970#M10052</link>
      <description>&lt;P&gt;Hello, as you can see we are using a self-signed certificate.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Xevi&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 17:54:53 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1484970#M10052</guid>
      <dc:creator>xevi</dc:creator>
      <dc:date>2023-05-10T17:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1485394#M10063</link>
      <description>&lt;P&gt;Hello xevi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you so much for your response,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The self-Certificate picture you sent only shows 2 lines on the chain. It should have 3 lines, each line needs to be SHA256.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In order to create a new certificate please follow the document called: Intel® Setup and Configuration Software (Intel® SCS) User Guide&amp;nbsp;v12.2. You will need to follow sections 10.5, 10.5.1 only.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: Intel will release a newer document for self-certificate for EMA later.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additionally, the installation of the PKI DNS suffix will have to be manually made on each endpoint, this need to be done this way when using a self-certificate. The BIOS of the endpoints only contains the certificate hash of validated OEM Certs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All you need for the task ahead is in the links below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How to Create a Self-Certificate Hash for Intel® Active Management Technology (Intel® AMT) Version 14 or Higher&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.intel.com/content/www/us/en/support/articles/000059996.html" target="_blank" rel="noopener noreferrer"&gt;https://www.intel.com/content/www/us/en/support/articles/000059996.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Intel® AMT SDK&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.intel.com/content/www/us/en/download/704388/intel-amt-sdk.html?cache=1639697797" target="_blank" rel="noopener noreferrer"&gt;https://www.intel.com/content/www/us/en/download/704388/intel-amt-sdk.html?cache=1639697797&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Intel® Setup and Configuration Software (Intel® SCS) User Guide&amp;nbsp;v12.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.intel.com/content/dam/support/us/en/documents/software/Intel_SCS_User_Guide.pdf" target="_blank" rel="noopener noreferrer"&gt;https://www.intel.com/content/dam/support/us/en/documents/software/Intel_SCS_User_Guide.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As an example, the Certificate should be viewed as the one showed in the attached picture; however, please bear in mind this is an OEM cert.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Victor G.&lt;/P&gt;
&lt;P&gt;Intel Technical Support Technician&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 18:37:09 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1485394#M10063</guid>
      <dc:creator>Victor_G_Intel</dc:creator>
      <dc:date>2023-05-11T18:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1486612#M10095</link>
      <description>&lt;P&gt;Hello xevi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Were you able to check the previous post?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please let me know if you need further assistance.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Victor G.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Intel Technical Support Technician&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2023 17:05:43 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1486612#M10095</guid>
      <dc:creator>Victor_G_Intel</dc:creator>
      <dc:date>2023-05-16T17:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1487796#M10114</link>
      <description>&lt;P&gt;Hello Victor_G,&lt;/P&gt;&lt;P&gt;I'm sorry I didn't reply earlier. My boss locked me in a cage and threw me peanuts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The certificate is already created correctly. We had entered the PKI DNS sufix in the bios, we even tried to save the certificate hash (this has not been possible).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The certificate that you show with three lines, is from a certifying entity that is already available in all bios that have VPRO. We think ours has two lines because it is self-signed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you can provide us with more information, we would greatly appreciate it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Xevi&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 11:38:45 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1487796#M10114</guid>
      <dc:creator>xevi</dc:creator>
      <dc:date>2023-05-19T11:38:45Z</dc:date>
    </item>
    <item>
      <title>Re:Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1487924#M10116</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Hello, Xevi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;The Self Certificate creation is tricky and takes some extra time.&amp;nbsp;First, please follow the steps of the article:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;How to Create a Self-Certificate Hash for Intel® Active Management Technology (Intel® AMT) Version 14 or Higher&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;&lt;A href="https://www.intel.com/content/www/us/en/support/articles/000059996.html" target="_blank"&gt;https://www.intel.com/content/www/us/en/support/articles/000059996.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;In the first section, it will describe the Certificate creation, then it provides the tool to generate a SHA256 PKI DNS and copy it to the endpoint.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;The USBFile.exe tool is included in the Intel® Active Management Technology SDK .zip file.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;If you found issues while creating the Self Certificate, please send us screenshots of the errors.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Miguel C.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Intel Customer Support Technician&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 19 May 2023 19:24:56 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1487924#M10116</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-19T19:24:56Z</dc:date>
    </item>
    <item>
      <title>Re:Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1489330#M10130</link>
      <description>&lt;P&gt;Hello &lt;SPAN style="font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 10.5pt;"&gt;xevi&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Were you able to check the previous post?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Please let me know if you need further assistance.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Victor G.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Intel Technical Support Technician&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 24 May 2023 16:41:49 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1489330#M10130</guid>
      <dc:creator>Victor_G_Intel</dc:creator>
      <dc:date>2023-05-24T16:41:49Z</dc:date>
    </item>
    <item>
      <title>Re:Intel EMA in Admin Control Mode.  Issue with autosigned certificate from internal Server CA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1490922#M10143</link>
      <description>&lt;P&gt;Hello xevi,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;We have not heard back from you. &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;If you need any additional information, please submit a new question as this thread will no longer be monitored. &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Victor G. &lt;/P&gt;&lt;P&gt;Intel Technical Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 29 May 2023 17:19:36 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-EMA-in-Admin-Control-Mode-Issue-with-autosigned/m-p/1490922#M10143</guid>
      <dc:creator>Victor_G_Intel</dc:creator>
      <dc:date>2023-05-29T17:19:36Z</dc:date>
    </item>
  </channel>
</rss>

