<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Re:EMA Server / Client with vpro won't finish configuration for PKI certificate. in Intel vPro® Platform</title>
    <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1484171#M10033</link>
    <description>&lt;P&gt;Thank you for responding. I'm happy to provide any details you require.&lt;/P&gt;
&lt;P&gt;I've gone to bat with this for over a month.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is recent fresh install, both devices have been rebooted, remote access works. I've tried with multiple devices, for this install it has just been the one device. For vpro systems with the same older version I get the same results, I can remote into them, but it's pending configuration and CIRA does not connect.&lt;/P&gt;
&lt;P&gt;For a newer vpro system ,I get a cert verify failure.&lt;/P&gt;
&lt;P&gt;If needed I can join those devices again to generate the logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've attached the logs for this vpro system with the one system trying to provision.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For your direct questions.&lt;/P&gt;
&lt;P&gt;1 &amp;amp; 2.&amp;nbsp; This is an AMT Certificate purchased as such from Sectigo / commodo&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mike_Modality_0-1683564846412.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41074i4E913F173F633E25/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="Mike_Modality_0-1683564846412.png" alt="Mike_Modality_0-1683564846412.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mike_Modality_1-1683564890531.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41075iD10F1D3683D58AD4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="Mike_Modality_1-1683564890531.png" alt="Mike_Modality_1-1683564890531.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. In all my test cases the device was provisioned using the EMA Agent. Systems were as up to date for vpro as possible, rebooted, and I also fully unprovisioned them to clear them out, and also set my network suffix to match the certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4. See attachment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 May 2023 16:58:48 GMT</pubDate>
    <dc:creator>Mike_Modality</dc:creator>
    <dc:date>2023-05-08T16:58:48Z</dc:date>
    <item>
      <title>EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1483206#M10020</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm trying to deploy vpro / ema. I have an off net server running the EMA server with an AMT certificate installed. When I install the ema agent on a device and install the necessary msh file, it connects, I can reboot the system, but it's provisioning is pending configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help with this would be greatly appreciated.&lt;/P&gt;
&lt;P&gt;Here is some information about the setup.&lt;/P&gt;
&lt;P&gt;Server is Server 2022 - I have enabled older SSL protocols for testing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="detail"&gt;&lt;LABEL class="titles"&gt;Intel® AMT profile:&lt;/LABEL&gt; **removed**&lt;/DIV&gt;
&lt;DIV class="detail"&gt;&lt;LABEL class="titles"&gt;Operating System:&lt;/LABEL&gt;&amp;nbsp;&lt;LABEL class="values"&gt;Microsoft® Windows 11&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;DIV class="detail"&gt;&lt;LABEL class="titles"&gt;Intel® EMA Agent:&lt;/LABEL&gt;&amp;nbsp;&lt;LABEL class="values"&gt;Win64-Service v1.10.0&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;DIV class="detail"&gt;&lt;LABEL class="titles"&gt;Intel® ME:&lt;/LABEL&gt;&amp;nbsp;&lt;LABEL class="values"&gt;v9.1.45.3000&lt;/LABEL&gt;&amp;nbsp;&amp;nbsp;&lt;LABEL class="values-provision-state"&gt;Admin Control Mode&lt;/LABEL&gt;&amp;nbsp;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="detail"&gt;&lt;LABEL class="titles"&gt;CIRA selected:&lt;/LABEL&gt;&amp;nbsp;&lt;LABEL id="lbAMTCIRASelectedValue" class="values"&gt;Yes&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;DIV class="detail"&gt;&lt;LABEL class="titles"&gt;Intel® AMT setup status:&lt;/LABEL&gt;&amp;nbsp;&lt;LABEL id="lbAMTSetupRecordStatusValue" class="values-provision-state warnings"&gt;Pending Configuration&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV class="detail" title="MAC: 6C0B84A5DF5C, Gateway MAC: 04D5905E764D"&gt;&lt;LABEL class="titles"&gt;Interface:&lt;/LABEL&gt; **removed**&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="detail"&gt;&lt;LABEL class="titles"&gt;Nearby endpoints:&lt;/LABEL&gt;&amp;nbsp;&lt;LABEL class="values"&gt;0&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;DIV class="detail"&gt;&lt;LABEL class="titles"&gt;Hardware Management Capability:&lt;/LABEL&gt;&amp;nbsp;&lt;LABEL class="values"&gt;Intel® Active Management Technology&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the client side, I see this error when it tries to connect.&lt;/P&gt;
&lt;P&gt;[2023-05-04 01:46:48.411 PM] \Agent\MeshManageability\agent\microstack\ILibAsyncSocket.c:505 internalSocket ERROR: 0. Last error: 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2023-05-04 11:52:21.9499|INFO||6740|50|PerformRound2Provisioning - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=**removed**- [1] - Message:AMT Profile detected : (***removed***,5C675EE9). &lt;BR /&gt;2023-05-04 11:53:08.0998|WARN||6740|50|PerformRound2Provisioning - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=***removed***- [1] - Warning:Unable to connect to Intel AMT computer for round 2, 127.0.0.1:50250 &lt;BR /&gt;2023-05-04 11:53:08.0998|WARN||6740|50|PerformRound2Provisioning - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=***removed*** - [1] - Warning:(Host=127.0.0.1, Computer=***removed***, Domain=, Tls=True, Endpoint=(***removed***,5C675EE9), User=SYSTEM, UserId=00000000-0000-0000-0000-000000000000) &lt;BR /&gt;2023-05-04 11:53:08.0998|WARN||6740|50|AttemptPhase1 - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=***removed*** - [1] - Failed PKI provisioning : (***removed***,5C675EE9).&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 20:58:32 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1483206#M10020</guid>
      <dc:creator>Mike_Modality</dc:creator>
      <dc:date>2023-05-04T20:58:32Z</dc:date>
    </item>
    <item>
      <title>Re:EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1483648#M10027</link>
      <description>&lt;P&gt;Hello, Michael,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I will gladly assist you.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The log is showing a failure while validating the provisioning:&lt;/P&gt;&lt;P&gt;2023-05-04 11:53:08.0998|WARN||6740|50|AttemptPhase1 - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=***removed*** - [1] - Failed PKI provisioning: (***removed***,5C675EE9).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Please confirm if the Remote access to the Endpoint is working even when you are getting the Pending Configuration message in the EMA web console.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If yes, please restart the EMA services or restart the server.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;1- Do you mind giving me more details of the Certificate?&amp;nbsp;Is it a self-Certificate or any authorized OEM Intel® AMT certificate?&lt;/P&gt;&lt;P&gt;2- The Certificate chain (Root, Intermediate, and Leaf) needs to comply with SHA256 ( 2048 bits ).&amp;nbsp; Please send a picture of the Cert chain from the Certificates Path tab.&lt;/P&gt;&lt;P&gt;3- How did you provision the endpoint?&amp;nbsp;Using the EMA agent file or manually in the MEBx BIOS.&lt;/P&gt;&lt;P&gt;4- Please include the EMA log from Server. The path is:&amp;nbsp;&lt;/P&gt;&lt;P&gt;[System drive]\Program File(x86)\Intel\Platform Manager\EmaLogs&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Miguel C.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 05 May 2023 23:31:07 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1483648#M10027</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-05T23:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: Re:EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1484171#M10033</link>
      <description>&lt;P&gt;Thank you for responding. I'm happy to provide any details you require.&lt;/P&gt;
&lt;P&gt;I've gone to bat with this for over a month.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is recent fresh install, both devices have been rebooted, remote access works. I've tried with multiple devices, for this install it has just been the one device. For vpro systems with the same older version I get the same results, I can remote into them, but it's pending configuration and CIRA does not connect.&lt;/P&gt;
&lt;P&gt;For a newer vpro system ,I get a cert verify failure.&lt;/P&gt;
&lt;P&gt;If needed I can join those devices again to generate the logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've attached the logs for this vpro system with the one system trying to provision.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For your direct questions.&lt;/P&gt;
&lt;P&gt;1 &amp;amp; 2.&amp;nbsp; This is an AMT Certificate purchased as such from Sectigo / commodo&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mike_Modality_0-1683564846412.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41074i4E913F173F633E25/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="Mike_Modality_0-1683564846412.png" alt="Mike_Modality_0-1683564846412.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mike_Modality_1-1683564890531.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41075iD10F1D3683D58AD4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="Mike_Modality_1-1683564890531.png" alt="Mike_Modality_1-1683564890531.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. In all my test cases the device was provisioned using the EMA Agent. Systems were as up to date for vpro as possible, rebooted, and I also fully unprovisioned them to clear them out, and also set my network suffix to match the certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4. See attachment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2023 16:58:48 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1484171#M10033</guid>
      <dc:creator>Mike_Modality</dc:creator>
      <dc:date>2023-05-08T16:58:48Z</dc:date>
    </item>
    <item>
      <title>Re:EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1484338#M10034</link>
      <description>&lt;P&gt;Hello Mike_Modality,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the additional information.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Can you please let us know the brand and model of the systems that you are using and how many systems are you having this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Best regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Sergio S.&lt;/P&gt;&lt;P&gt;&amp;nbsp;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 09 May 2023 00:32:05 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1484338#M10034</guid>
      <dc:creator>SergioS_Intel</dc:creator>
      <dc:date>2023-05-09T00:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1484551#M10042</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;SergioS.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I'm having this problem with at least two systems I've tested. One is a lenovo M80. This M80 had the same error as the 30AH004MUS.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The system that is currently in the logs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="ant-row"&gt;
&lt;DIV class="ant-col ant-col-12"&gt;&lt;SPAN class="Title--1usmvv6 RowLabel--jrufmz hcAyfV"&gt;Manufacturer&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="ant-col ant-col-12"&gt;LENOVO&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="ant-row"&gt;
&lt;DIV class="ant-col ant-col-12"&gt;&lt;SPAN class="Title--1usmvv6 RowLabel--jrufmz hcAyfV"&gt;Model&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="ant-col ant-col-12"&gt;30AH004MUS&lt;/DIV&gt;
&lt;DIV class="ant-col ant-col-12"&gt;--This system is the one in the logs with the current error&lt;/DIV&gt;
&lt;DIV class="ant-col ant-col-12"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="ant-col ant-col-12"&gt;Other system I tried in a previous EMA server installation was&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="ant-col ant-col-12"&gt;
&lt;DIV class="ant-row"&gt;
&lt;DIV class="ant-col ant-col-12"&gt;&lt;SPAN class="Title--1usmvv6 RowLabel--jrufmz hcAyfV"&gt;Manufacturer&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="ant-col ant-col-12"&gt;LENOVO&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="ant-row"&gt;
&lt;DIV class="ant-col ant-col-12"&gt;&lt;SPAN class="Title--1usmvv6 RowLabel--jrufmz hcAyfV"&gt;Model&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="ant-col ant-col-12"&gt;11TG0020US&lt;/DIV&gt;
&lt;DIV class="ant-col ant-col-12"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="ant-col ant-col-12"&gt;This newer system when it pushed the PKI certificate gave me a 'CERT_VERIFY_ERROR' when pushing the chain. My first thought that there was a problem with the certificate but the certificate provider has been less than helpful, and it does get accepted by the M80 and the other system I listed here.&lt;/DIV&gt;
&lt;DIV class="ant-col ant-col-12"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="ant-col ant-col-12"&gt;So far I've actually actually go vpro to fully work on any system as yet to date, we're hoping to add it to our tools if I can make something happen.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 09 May 2023 16:11:50 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1484551#M10042</guid>
      <dc:creator>Mike_Modality</dc:creator>
      <dc:date>2023-05-09T16:11:50Z</dc:date>
    </item>
    <item>
      <title>Re:EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1484601#M10046</link>
      <description>&lt;P&gt;Hello, Mike_Modality,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I reviewed the logs, and only the certificate issue pops-up has seemed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;After reviewing the pictures provided and the documentation available, I noted the following.&amp;nbsp;Sectigo SHA256 Certificate hash was included in systems with Intel® AMT 15 and later.&amp;nbsp; Systems with older AMT versions require a different vendor Certificate.  I am including the documentation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Releases 15.0.45, 16.1, and later support the following root certificate&lt;/P&gt;&lt;P&gt;&lt;A href="https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/WordDocuments/rootcertificatehashes.htm" target="_blank"&gt;https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/WordDocuments/rootcertificatehashes.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The Certificate hash is a code included in the BIOS firmware of the machines, it validates the Certificate included in the EMA server.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;To verify if the current Cert belongs to AMT, go to the Cert - Comodo AMT Cert (leaf) and validate the Enhanced Key usage matches AMT OID: 2.16.840.1.113741.1.2.3&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;It is possible to validate the Intel® AMT version by running:&lt;/P&gt;&lt;P&gt;Endpoint Management Assistant Configuration Tool&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.intel.com/content/www/us/en/download/19805/30485/intel-endpoint-management-assistant-configuration-tool-intel-ema-configuration-tool.html" target="_blank"&gt;https://www.intel.com/content/www/us/en/download/19805/30485/intel-endpoint-management-assistant-configuration-tool-intel-ema-configuration-tool.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Installation:&lt;/P&gt;&lt;P&gt;Double-click the .msi file and follow the prompts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Run:&lt;/P&gt;&lt;P&gt;a-Open a command prompt (alternatively, you can run the tool from within Windows PowerShell*).&lt;/P&gt;&lt;P&gt;b-Navigate to the installation folder (default C:\Program Files (x86)\Intel\EMAConfigTool).&lt;/P&gt;&lt;P&gt;c-Run the command: EMAConfigTool.exe -filename XXXX --verbose&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Miguel C.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 09 May 2023 18:21:55 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1484601#M10046</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-09T18:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1484662#M10047</link>
      <description>&lt;P&gt;Thank you for the reply.&lt;/P&gt;
&lt;P&gt;I have previously verified it had the correct OID.&lt;/P&gt;
&lt;P&gt;Please see below&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mike_Modality_0-1683664495728.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41107i21B013737CE76ED5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="Mike_Modality_0-1683664495728.png" alt="Mike_Modality_0-1683664495728.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Here is the endpoints, you can see their intel AMT version&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mike_Modality_1-1683665442184.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41108iF234CD480C598975/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="Mike_Modality_1-1683665442184.png" alt="Mike_Modality_1-1683665442184.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please see the additional log file attached, this is what happens when the modern AMT system connects. If you need me to submit other / full logs let me know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mike_Modality_2-1683665532329.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41109iD60568854A555D98/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="Mike_Modality_2-1683665532329.png" alt="Mike_Modality_2-1683665532329.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was thinking the same thing you were, that the certificate they gave me would only work on newer systems.&lt;/P&gt;
&lt;P&gt;So I tried it with a newer system, and it didn't work. I received a cert verify failure which is in the log.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 20:53:18 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1484662#M10047</guid>
      <dc:creator>Mike_Modality</dc:creator>
      <dc:date>2023-05-09T20:53:18Z</dc:date>
    </item>
    <item>
      <title>Re:EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1484688#M10048</link>
      <description>&lt;P&gt;Hello, Mike_Modality,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you for your response with the log and pictures.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Taking into consideration that it is a new installation, and the Certificate is new.&amp;nbsp;Do you mind doing the following:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Unconfigure the endpoints.&amp;nbsp;It is possible to perform this by the following:&lt;/P&gt;&lt;P&gt;a- First, we need to access the EMA web console and gather the access password for each endpoint if you selected the randomize option.&amp;nbsp;From the action option of each endpoint, we can gather the password.&amp;nbsp;&lt;/P&gt;&lt;P&gt;b- Unconfigure the endpoint using Endpoint Management Assistant Configuration tool (ECT).&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.intel.com/content/www/us/en/download/19805/30485/intel-endpoint-management-assistant-configuration-tool-intel-ema-configuration-tool.html" target="_blank"&gt;https://www.intel.com/content/www/us/en/download/19805/30485/intel-endpoint-management-assistant-configuration-tool-intel-ema-configuration-tool.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;c- Uninstall and delete the EMA agent file from each endpoint.&lt;/P&gt;&lt;P&gt;d- Finally, go to the EMA web console and stop provisioning the endpoint.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Latest Intel® Endpoint Management Assistant (Intel® EMA) 1.10.1&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.intel.com/content/www/us/en/download/19449/intel-endpoint-management-assistant-intel-ema.html" target="_blank"&gt;https://www.intel.com/content/www/us/en/download/19449/intel-endpoint-management-assistant-intel-ema.html&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Before provisioning the endpoints, please send me the ECT logs from both systems (Intel® AMT version 9 and 16).&amp;nbsp;Please send them as a zip file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Installation:&lt;/P&gt;&lt;P&gt;Double-click the .msi file and follow the prompts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Run:&lt;/P&gt;&lt;P&gt;a-Open a command prompt (alternatively, you can run the tool from within Windows PowerShell*).&lt;/P&gt;&lt;P&gt;b-Navigate to the installation folder (default C:\Program Files (x86)\Intel\EMAConfigTool).&lt;/P&gt;&lt;P&gt;c-Run the command: EMAConfigTool.exe -filename XXXX --verbose&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I am including a summary of the case:&lt;/P&gt;&lt;P&gt;2- Endpoint&lt;/P&gt;&lt;P&gt;LENOVO Model 30AH004MUS&lt;/P&gt;&lt;P&gt;MIT-WKBNCH-SRV v9.1.45 - Provisioned&lt;/P&gt;&lt;P&gt;SSM-WS02&lt;/P&gt;&lt;P&gt;Windows 10&lt;/P&gt;&lt;P&gt;ME: 16.0.15.1620&lt;/P&gt;&lt;P&gt;AMT status: Pending Activation&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Operating System: Microsoft® Windows 11&lt;/P&gt;&lt;P&gt;Intel® EMA Agent: Win64-Service v1.10.0&lt;/P&gt;&lt;P&gt;Intel® ME: v9.1.45.3000&amp;nbsp;Admin Control Mode&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CIRA selected: Yes&lt;/P&gt;&lt;P&gt;Intel® AMT setup status: Pending Configuration&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;For vpro systems with the same older version I get the same results, I can remote into them, but it's pending configuration and CIRA does not connect.&lt;/P&gt;&lt;P&gt;---------------------------------&lt;/P&gt;&lt;P&gt;3- Endpoint&lt;/P&gt;&lt;P&gt;LENOVO Model 11TG0020US&lt;/P&gt;&lt;P&gt;SSM-WS02&amp;nbsp;&amp;nbsp;&amp;nbsp;v16.0.15 Not Provisioned&lt;/P&gt;&lt;P&gt;2023-05-04 11:53:08.0998|WARN||6740|50|AttemptPhase1 - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=***removed*** - [1] - Failed PKI provisioning: (***removed***,5C675EE9).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;For a newer vpro system, I get a cert verify failure.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;EMALog-ManageabilityServer&lt;/P&gt;&lt;P&gt;2023-05-09 13:48:44.1461|INFO||7048|34|HostBasedAdminUpdate - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Message:Pushing activation certificate - ema.modality.ca : (SSM-WS02,99B51BD7).&amp;nbsp;&lt;/P&gt;&lt;P&gt;2023-05-09 13:48:44.2254|INFO||7048|34|HostBasedAdminUpdate - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Message:Pushing activation certificate - Sectigo RSA Domain Validation Secure Server CA : (SSM-WS02,99B51BD7).&amp;nbsp;&lt;/P&gt;&lt;P&gt;2023-05-09 13:48:44.3081|INFO||7048|34|HostBasedAdminUpdate - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Message:Pushing activation certificate - USERTrust RSA Certification Authority : (SSM-WS02,99B51BD7).&amp;nbsp;&lt;/P&gt;&lt;P&gt;2023-05-09 13:48:44.3831|INFO||7048|34|HostBasedAdminUpdate - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Message:Pushing activation certificate - AAA Certificate Services : (SSM-WS02,99B51BD7).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Excuse me for all the troubleshooting; I am trying to narrow down the issue.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Miguel C.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 09 May 2023 23:29:14 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1484688#M10048</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-09T23:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: Re:EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1485045#M10054</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've completed the steps you requested on the newer device running the 16 version. I have yet to complete it on the older device as I'm getting a WSman connection error, so I may just fresh that system and try it again to get you clean logs. Please see the attach file with the log for SSM-WS02 after it was unprovisioned.&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 21:15:42 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1485045#M10054</guid>
      <dc:creator>Mike_Modality</dc:creator>
      <dc:date>2023-05-10T21:15:42Z</dc:date>
    </item>
    <item>
      <title>Re:EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1485088#M10055</link>
      <description>&lt;P&gt;Hello, Mike_Modality,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I reviewed the ECT log and confirmed the Lenovo 11TG0020US is not provisioned, has no PKI DNS suffix, and it is using ME version 16.0.15.1620.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I noticed, no network is recognized (wire or wireless).&amp;nbsp;Are you using a docking station?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Finally, please double-check if the machine is using the latest BIOS version. I am sending Lenovo’s website. Current BIOS: M40KT3DA&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Lenovo ThinkCentre M80s Gen 3 – SFF&lt;/P&gt;&lt;P&gt;&lt;A href="https://pcsupport.lenovo.com/us/en/products/desktops-and-all-in-ones/thinkcentre-m-series-desktops/thinkcentre-m80s-gen-3/downloads/ds556726-flash-bios-update-for-thinkcentre-m80t-gen-3-m80s-gen-3-m90t-gen-3-m90s-gen-3-neo-70t-gen3?category=BIOS%2FUEFI" target="_blank"&gt;https://pcsupport.lenovo.com/us/en/products/desktops-and-all-in-ones/thinkcentre-m-series-desktops/thinkcentre-m80s-gen-3/downloads/ds556726-flash-bios-update-for-thinkcentre-m80t-gen-3-m80s-gen-3-m90t-gen-3-m90s-gen-3-neo-70t-gen3?category=BIOS%2FUEFI&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I look forward to the pending log and answers.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Miguel C.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 11 May 2023 00:29:24 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1485088#M10055</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-11T00:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Re:EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1485363#M10060</link>
      <description>&lt;P&gt;Hey Miguel.&lt;/P&gt;&lt;P&gt;I performed an bios update but that didn't seem to change anything.&lt;/P&gt;&lt;P&gt;It's a wired connection, no docking station as this is a SFF PC with DHCP. I'm attaching the relevant IPconfig information. If you need more of the output let me know. It shows the DNS suffix there which is odd that it doesn't show up for the PKI DNS Suffix.&lt;/P&gt;&lt;P&gt;I'm not sure why it shows the IP as 0.0.0.0 in the log from ema config tool, is that just the IP it's binding to or how it reads DHCP vs static? It sounds to me like the AMT is just using the standard 0.0.0.0 any interface configuration that other network applications commonly use.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 17:01:08 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1485363#M10060</guid>
      <dc:creator>Mike_Modality</dc:creator>
      <dc:date>2023-05-11T17:01:08Z</dc:date>
    </item>
    <item>
      <title>Re:EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1485477#M10064</link>
      <description>&lt;P&gt;Hello, Mike_Modality,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Yes, you are right.&amp;nbsp; It is very odd, the IP address is not recognized, and the network connection is working. &amp;nbsp;Intel® AMT uses the same IP address of the machine, it does not create a dedicated connection.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Do you mind running our tool called Intel® System Support Utility for Windows and sharing the results?&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.intel.com/content/www/us/en/download/18377/intel-system-support-utility-for-windows.html" target="_blank"&gt;https://www.intel.com/content/www/us/en/download/18377/intel-system-support-utility-for-windows.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;In addition, please open a command line window and run the command: ipconfig&lt;/P&gt;&lt;P&gt;Please let me know if you have a VPN, proxy, or any restrictions.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Miguel C.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 11 May 2023 22:27:30 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1485477#M10064</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-11T22:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: Re:EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1485479#M10065</link>
      <description>&lt;P&gt;I have no restrictions, no VPN, no proxy, and full access to our internal firewall which is direct to an external static. Nothing should be interfering with it's connection and I have full access to all our configurations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran the command with ipconfig /all&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 22:35:25 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1485479#M10065</guid>
      <dc:creator>Mike_Modality</dc:creator>
      <dc:date>2023-05-11T22:35:25Z</dc:date>
    </item>
    <item>
      <title>Re:EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1485515#M10068</link>
      <description>&lt;P&gt;Hello, Mike_Modality,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you for your quick response.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;It seems the firewall is not letting the EMA server verify the endpoint.&amp;nbsp;Please disable the firewall on both sides.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Note: from the previous post, the PKI DNS suffix is empty in the endpoint because we ran the ECT tool with the command reconfigure.&amp;nbsp; For provisioning, it is necessary to install and run the EMA agent file again.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Miguel C.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 12 May 2023 00:38:49 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1485515#M10068</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-12T00:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: Re:EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1485719#M10073</link>
      <description>&lt;P&gt;Hey Miguel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately I've been running it without the firewall the entire time so it would not be related to that. I've also ensured all the necessary ports are forwarded. Communication shows activity when the devices try to provision, in the example with the 16 version, the error is cert_verify_failure, I would expect a different error message if it was a communication failure by a firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PKI suffix message stays the same on the 16 version even after provisioning the device again, where I stay in the same not activated state, and it just keeps retrying until it gives up until a reboot.&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2023 16:24:52 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1485719#M10073</guid>
      <dc:creator>Mike_Modality</dc:creator>
      <dc:date>2023-05-12T16:24:52Z</dc:date>
    </item>
    <item>
      <title>Re:EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1485756#M10076</link>
      <description>&lt;P&gt;Hello, Mike_Modality,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I am going to investigate internally the issue with the engineering team; please send me a new ECT log after reinstalling the EMA agent file to the endpoint with AMT 16.&amp;nbsp;In addition, please send a new Server log after trying to provision this endpoint.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EMA Configuration Tool log instructions:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;a-Open a command prompt (alternatively, you can run the tool from within Windows PowerShell*).&lt;/P&gt;&lt;P&gt;b-Navigate to the installation folder (default C:\Program Files (x86)\Intel\EMAConfigTool).&lt;/P&gt;&lt;P&gt;c-Run the command: EMAConfigTool.exe --verbose&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EMA logs from Server&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[System drive]\Program File(x86)\Intel\Platform Manager\EmaLogs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EMA log from the endpoint:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[System drive]\Program Files\Intel\EMA Agent\EMAagentlog&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Miguel C.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 12 May 2023 18:06:38 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1485756#M10076</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-12T18:06:38Z</dc:date>
    </item>
    <item>
      <title>Re:EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1487207#M10102</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Hello, Mike_Modality,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;I hope this post finds you well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;By any chance, have you been able to work on my request?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Miguel C.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Intel Customer Support Technician&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 17 May 2023 22:45:52 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1487207#M10102</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-17T22:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: Re:EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1487214#M10103</link>
      <description>&lt;P&gt;Sorry for the delay in response, it's been busy. Please see the attached logs. There was no EMA agent log folder created after install.&lt;/P&gt;&lt;P&gt;SSMWS02 is the ECT log, and the other EMA logs are well, the EMA logs. These were grabbed right after installing the device and the ema agent provsioning.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mike_Modality_0-1684364571457.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41339iFC0B4F75B9590E99/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="Mike_Modality_0-1684364571457.png" alt="Mike_Modality_0-1684364571457.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 23:04:07 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1487214#M10103</guid>
      <dc:creator>Mike_Modality</dc:creator>
      <dc:date>2023-05-17T23:04:07Z</dc:date>
    </item>
    <item>
      <title>Re:EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1487456#M10105</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Hello, Mike_Modality,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Thank you for providing me with the EMA server logs and the ECT log of the endpoint.&amp;nbsp; We are still getting the issue; the provisioning of the endpoint is failing.&amp;nbsp;This is the reason the endpoint log was not created.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;The Connection-specific DNS Suffix says ema.modality.ca.  Usually, we should see the IP address assigned by the Internet Service Provider or IP assigned by the company and not the URL of EMA.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Your network configuration is not allowing the certificate validation. &amp;nbsp;In addition, please verify which domain was used for the certificate, it should match your company domain.&amp;nbsp;As an example, for Intel it is &lt;/SPAN&gt;&lt;SPAN style="font-size: 16px;"&gt;intel.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;I am adding a summary of the errors:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 14.625px;"&gt;EMALog-ManageabilityServer&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;HostBasedAdminUpdate - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Warning:Failed to push activation certificate - CERT_VERIFY_FAILED : (SSM-WS02,99B51BD7).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;RequestHostBasedProvisioningEx - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Warning:Unable to go to admin mode, rolling back out of client mode : (SSM-WS02,99B51BD7).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;TriggerMeHbpUnprovision - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Message:Connecting to Swarm Server : (SSM-WS02,99B51BD7).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;TriggerMeHbpUnprovision - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Message:Requesting ME unprovisionning : (SSM-WS02,99B51BD7).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;TriggerMeHbpUnprovision - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Disconnecting Swarm Server : (SSM-WS02,99B51BD7).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;PushCredentialsToMeshAgent - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Clearing credentials from ema agent : (SSM-WS02,99B51BD7).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;TriggerMeHbpUnprovision - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Message:Deactivation completed : (SSM-WS02,99B51BD7).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;PerformPkiSetup - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Warning: Failed Intel AMT SetupAdmin activation : (SSM-WS02,99B51BD7).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;AttemptPhase1 - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.10.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Failed PKI provisioning : (SSM-WS02,99B51BD7).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 14.625px;"&gt;ECT log:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;&amp;nbsp;&amp;nbsp;ME Version&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;16.0.15.1620&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;&amp;nbsp;&amp;nbsp;MESKU Intel(R) Full AMT Manageability&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;&amp;nbsp;&amp;nbsp;ME Provisioning State&amp;nbsp;Not Provisioned&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;&amp;nbsp;&amp;nbsp;Is AMT Provisioned&amp;nbsp;False&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;&amp;nbsp;&amp;nbsp;Is AMT Ready For Provisioning&amp;nbsp;True&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;&amp;nbsp;&amp;nbsp;Micro LMS State&amp;nbsp;NotPresent&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;&amp;nbsp;&amp;nbsp;IsEHBCEnabled&amp;nbsp;&amp;nbsp;False&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;&amp;nbsp;&amp;nbsp;ControlMode:&amp;nbsp;&amp;nbsp;&amp;nbsp;None&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;&amp;nbsp;&amp;nbsp;PKI DNS Suffix:&amp;nbsp;&amp;nbsp;&amp;nbsp;Not Found&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;I look forward to hearing from you.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Miguel C.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Intel Customer Support Technician&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 18 May 2023 16:00:15 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1487456#M10105</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-18T16:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: Re:EMA Server / Client with vpro won't finish configuration for PKI certificate.</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1487465#M10106</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello&amp;nbsp;MIGUEL_C_Intel.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes, I'm aware that it fails to provision. That's why I posted the original issue about the PKI certificate failing to provision. I've seen the logs and watched in live with the exact failures you have listed so we're in sync with that part, I'm quite aware of which part is failing. Why it's failing is the part I'm trying to diagnose.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Systems here use Azure, so I'm free to set the domain prefix to anything I'd like. If the certificate is for ema.modality.ca, are you saying the DNS suffix should just be modality.ca? I can make that change without issue if that is the case.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm also not sure how the network is not allowing the certificate to provision. On older vpro systems as demonstrated, which I can get logs and do it again, the certificate gets pushed and is accepted. That's on the exact same network, physically beside the newer vpro system that fails to provision. Everything configuration-wise is the same except the version of vpro. Our firewall has no rules restricting any outbound traffic and return paths on the network these systems are being tested on. If you feel confident the network is at fault I can even test these system in an isolated DMZ network to prove it out.&amp;nbsp; The only problem I have with the older vpro systems, is that the CIRA fails to connect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2023 16:17:01 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/EMA-Server-Client-with-vpro-won-t-finish-configuration-for-PKI/m-p/1487465#M10106</guid>
      <dc:creator>Mike_Modality</dc:creator>
      <dc:date>2023-05-18T16:17:01Z</dc:date>
    </item>
  </channel>
</rss>

