<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Failed PKI provisioning in Intel vPro® Platform</title>
    <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1487415#M10104</link>
    <description>&lt;P&gt;We are trying to adopt EMA in addition to our existing endpoint management solutions and running into some serious issues. We acquired PKI cert with valid OID from GoDaddy. The leaf cert (in the form of pfx), GoDaddy G2 Root CA, and Intermediate cert are added into the server. The first 2 devices were&amp;nbsp;&lt;SPAN&gt;successfully&amp;nbsp;&lt;/SPAN&gt;&lt;FONT face="inherit"&gt;provisioned, but then any new devices we attempt to add are failing.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;- Windows Server 2019 Datacenter (US-English) (EMA server)&lt;/P&gt;&lt;P class=""&gt;- Succeeded client laptop has AMT 14.1.67&lt;/P&gt;&lt;P class=""&gt;- Failed Client laptops have AMT 11 and lower, and AMT 15 and above&lt;/P&gt;&lt;P class=""&gt;- Verified DHCP option 15 is set with correct DNS suffix, which is also in the GoDaddy Deluxe cert&lt;/P&gt;&lt;P class=""&gt;- Correct OID is verified&lt;/P&gt;&lt;P class=""&gt;- Exported EMAAgent files and run -fullinstall on client&lt;/P&gt;&lt;P class=""&gt;- We can see the client in EMA console as power on and connected (but unprovisioned)&lt;/P&gt;&lt;P class=""&gt;- We then attempt to provision the client and it fails provisioning and we see these 2 msgs in the&amp;nbsp;Failed Intel AMT SetupAdmin activation and&amp;nbsp;Failed PKI provisioning&lt;/P&gt;&lt;P class=""&gt;- On the client we see the Intel ME software repeated switching states from "Configured" to "Unconfigured"&lt;/P&gt;&lt;P class=""&gt;-&amp;nbsp; The clients are connected to LAN via USB-C ethernet dongle since these newer laptops don't come with ethernet port anymore&lt;/P&gt;&lt;P class=""&gt;- We've tried searching and following many threads in this forum and other places to no avail&lt;/P&gt;&lt;P class=""&gt;Any help is greatly appreciated.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 18 May 2023 13:53:35 GMT</pubDate>
    <dc:creator>mrant-k</dc:creator>
    <dc:date>2023-05-18T13:53:35Z</dc:date>
    <item>
      <title>Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1487415#M10104</link>
      <description>&lt;P&gt;We are trying to adopt EMA in addition to our existing endpoint management solutions and running into some serious issues. We acquired PKI cert with valid OID from GoDaddy. The leaf cert (in the form of pfx), GoDaddy G2 Root CA, and Intermediate cert are added into the server. The first 2 devices were&amp;nbsp;&lt;SPAN&gt;successfully&amp;nbsp;&lt;/SPAN&gt;&lt;FONT face="inherit"&gt;provisioned, but then any new devices we attempt to add are failing.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;- Windows Server 2019 Datacenter (US-English) (EMA server)&lt;/P&gt;&lt;P class=""&gt;- Succeeded client laptop has AMT 14.1.67&lt;/P&gt;&lt;P class=""&gt;- Failed Client laptops have AMT 11 and lower, and AMT 15 and above&lt;/P&gt;&lt;P class=""&gt;- Verified DHCP option 15 is set with correct DNS suffix, which is also in the GoDaddy Deluxe cert&lt;/P&gt;&lt;P class=""&gt;- Correct OID is verified&lt;/P&gt;&lt;P class=""&gt;- Exported EMAAgent files and run -fullinstall on client&lt;/P&gt;&lt;P class=""&gt;- We can see the client in EMA console as power on and connected (but unprovisioned)&lt;/P&gt;&lt;P class=""&gt;- We then attempt to provision the client and it fails provisioning and we see these 2 msgs in the&amp;nbsp;Failed Intel AMT SetupAdmin activation and&amp;nbsp;Failed PKI provisioning&lt;/P&gt;&lt;P class=""&gt;- On the client we see the Intel ME software repeated switching states from "Configured" to "Unconfigured"&lt;/P&gt;&lt;P class=""&gt;-&amp;nbsp; The clients are connected to LAN via USB-C ethernet dongle since these newer laptops don't come with ethernet port anymore&lt;/P&gt;&lt;P class=""&gt;- We've tried searching and following many threads in this forum and other places to no avail&lt;/P&gt;&lt;P class=""&gt;Any help is greatly appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2023 13:53:35 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1487415#M10104</guid>
      <dc:creator>mrant-k</dc:creator>
      <dc:date>2023-05-18T13:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1487495#M10110</link>
      <description>&lt;P&gt;Here's the out put from config tool if that helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Program Files (x86)\Intel\EMAConfigTool&amp;gt;EMAConfigTool.exe --verbose&lt;/P&gt;&lt;P&gt;Intel EMA Configuration Tool&lt;BR /&gt;Application Version: 1.1.0.183&lt;BR /&gt;Scan Date: 5/18/2023 12:06:32 PM&lt;/P&gt;&lt;P&gt;*** Host Computer Information ***&lt;BR /&gt;Computer Name: "ComputerName"&lt;BR /&gt;Manufacturer: Dell Inc.&lt;BR /&gt;Model: Latitude 9520&lt;BR /&gt;Processor: 11th Gen Intel(R) Core(TM) i7-1185G7 @ 3.00GHz&lt;BR /&gt;Windows Version: Microsoft Windows 10 Enterprise&lt;BR /&gt;BIOS Version: 1.21.0&lt;BR /&gt;UUID: 4C4C4544-005A-3210-8032-C8C04F4B5233&lt;/P&gt;&lt;P&gt;*** SMBIOS Information ***&lt;BR /&gt;AMT Supported: True&lt;BR /&gt;AMT Enabled: True&lt;BR /&gt;SMBIOS ME SKU: Intel(R) Full AMT Manageability&lt;BR /&gt;SMBIOS ME Version: 15.0.42.2235&lt;BR /&gt;KVM Supported: True&lt;BR /&gt;SOL Supported: True&lt;BR /&gt;USB-R supported in BIOS: True&lt;BR /&gt;RSE Supported: True&lt;/P&gt;&lt;P&gt;*** ME Information ***&lt;BR /&gt;Version: 15.0.42.2235&lt;BR /&gt;SKU: Intel(R) Full AMT Manageability&lt;BR /&gt;State: Provisioned&lt;BR /&gt;Control Mode: Client&lt;BR /&gt;Driver Installed: True&lt;BR /&gt;Driver Version: 2220.3.1.0&lt;BR /&gt;PKI DNS Suffix: Not Found&lt;BR /&gt;LMS State: Running&lt;BR /&gt;LMS Version: 2220.3.1.0&lt;BR /&gt;MicroLMS State: NotPresent&lt;BR /&gt;EHBC Enabled: False&lt;/P&gt;&lt;P&gt;*** ME Capabilities ***&lt;BR /&gt;AMT in Enterprise Mode: True&lt;BR /&gt;TLS Enabled: False&lt;BR /&gt;HW Crypto Enabled: True&lt;BR /&gt;Current Provisioning state: POST_PROVISIONING_STATE&lt;BR /&gt;NetworkInterface Enabled: True&lt;BR /&gt;SOL Enabled: True&lt;BR /&gt;IDER Enabled: True&lt;BR /&gt;FWUpdate Enabled: False&lt;BR /&gt;LinkIsUp state: False&lt;BR /&gt;KVM Enabled: False&lt;BR /&gt;RSE Enabled: True&lt;/P&gt;&lt;P&gt;*** Power Management Capabilities ***&lt;BR /&gt;Supported Power States:&lt;BR /&gt;5: PowerCycle_Off_Soft&lt;BR /&gt;8: Off_Soft&lt;BR /&gt;2: On&lt;BR /&gt;10: Master_Bus_Reset&lt;BR /&gt;11: NMI&lt;BR /&gt;7: Hibernate&lt;BR /&gt;12: Off_Soft_Graceful&lt;BR /&gt;14: MasterBusReset_Graceful&lt;BR /&gt;Power Change Capabilities:&lt;BR /&gt;2: On&lt;BR /&gt;3: SleepLight&lt;BR /&gt;4: SleepDeep&lt;BR /&gt;7: Hibernate&lt;BR /&gt;8: Off_Soft&lt;/P&gt;&lt;P&gt;*** CIRA Information ***&lt;BR /&gt;CIRA Server: Not Found&lt;BR /&gt;CIRA Connection Status: NOT_CONNECTED&lt;BR /&gt;CIRA Connection Trigger: USER_INITIATED&lt;/P&gt;&lt;P&gt;*** ME Wired Network Information ***&lt;BR /&gt;ME Wired Interface Not Detected&lt;/P&gt;&lt;P&gt;*** ME Wireless Network Information ***&lt;BR /&gt;Wireless Interface Enabled: False&lt;BR /&gt;Link Status: Down&lt;BR /&gt;IP Address: 0.0.0.0&lt;BR /&gt;MAC Address: "mac_address"&lt;BR /&gt;DHCP Enabled: True&lt;BR /&gt;DHCP Mode: Passive&lt;/P&gt;&lt;P&gt;*** Root Certificate Hash Entries ***&lt;BR /&gt;Root Cert 1: Go Daddy Class 2 CA, SHA256, C3:84:6B:F2:4B:9E:93:CA:64:27:4C:0E:C6:7C:1E:CC:5E:02:4F:FC:AC:D2:D7:40:19:35:0E:81:FE:54:6A:E4, Active, Default;&lt;BR /&gt;Root Cert 2: Go Daddy Root CA-G2, SHA256, 45:14:0B:32:47:EB:9C:C8:C5:B4:F0:D7:B5:30:91:F7:32:92:08:9E:6E:5A:63:E2:74:9D:D3:AC:A9:19:8E:DA, Active, Default;&lt;BR /&gt;Root Cert 3: Comodo AAA CA, SHA256, D7:A7:A0:FB:5D:7E:27:31:D7:71:E9:48:4E:BC:DE:F7:1D:5F:0C:3E:0A:29:48:78:2B:C8:3E:E0:EA:69:9E:F4, Active, Default;&lt;BR /&gt;Root Cert 4: Starfield Class 2 CA, SHA256, 14:65:FA:20:53:97:B8:76:FA:A6:F0:A9:95:8E:55:90:E4:0F:CC:7F:AA:4F:B7:C2:C8:67:75:21:FB:5F:B6:58, Active, Default;&lt;BR /&gt;Root Cert 5: Starfield Root CA-G2, SHA256, 2C:E1:CB:0B:F9:D2:F9:E1:02:99:3F:BE:21:51:52:C3:B2:DD:0C:AB:DE:1C:68:E5:31:9B:83:91:54:DB:B7:F5, Active, Default;&lt;BR /&gt;Root Cert 6: VeriSign Class 3 Primary CA-G5, SHA256, 9A:CF:AB:7E:43:C8:D8:80:D0:6B:26:2A:94:DE:EE:E4:B4:65:99:89:C3:D0:CA:F1:9B:AF:64:05:E4:1A:B7:DF, Active, Default;&lt;BR /&gt;Root Cert 7: Baltimore CyberTrust Root, SHA256, 16:AF:57:A9:F6:76:B0:AB:12:60:95:AA:5E:BA:DE:F2:2A:B3:11:19:D6:44:AC:95:CD:4B:93:DB:F3:F2:6A:EB, Active, Default;&lt;BR /&gt;Root Cert 8: Cybertrust Global Root, SHA256, 96:0A:DF:00:63:E9:63:56:75:0C:29:65:DD:0A:08:67:DA:0B:9C:BD:6E:77:71:4A:EA:FB:23:49:AB:39:3D:A3, Active, Default;&lt;BR /&gt;Root Cert 9: Verizon Global Root, SHA256, 68:AD:50:90:9B:04:36:3C:60:5E:F1:35:81:A9:39:FF:2C:96:37:2E:3F:12:32:5B:0A:68:61:E1:D5:9F:66:03, Active, Default;&lt;BR /&gt;Root Cert 10: Entrust.net CA (2048), SHA256, 6D:C4:71:72:E0:1C:BC:B0:BF:62:58:0D:89:5F:E2:B8:AC:9A:D4:F8:73:80:1E:0C:10:B9:C8:37:D2:1E:B1:77, Active, Default;&lt;BR /&gt;Root Cert 11: Entrust Root CA, SHA256, 73:C1:76:43:4F:1B:C6:D5:AD:F4:5B:0E:76:E7:27:28:7C:8D:E5:76:16:C1:E6:E6:14:1A:2B:2C:BC:7D:8E:4C, Active, Default;&lt;BR /&gt;Root Cert 12: Entrust Root CA-G2, SHA256, 43:DF:57:74:B0:3E:7F:EF:5F:E4:0D:93:1A:7B:ED:F1:BB:2E:6B:42:73:8C:4E:6D:38:41:10:3D:3A:A7:F3:39, Active, Default;&lt;BR /&gt;Root Cert 13: VeriSign Universal Root CA, SHA256, 23:99:56:11:27:A5:71:25:DE:8C:EF:EA:61:0D:DF:2F:A0:78:B5:C8:06:7F:4E:82:82:90:BF:B8:60:E8:4B:3C, Active, Default;&lt;BR /&gt;Root Cert 14: Affirm Trust Premium, SHA256, 70:A7:3F:7F:37:6B:60:07:42:48:90:45:34:B1:14:82:D5:BF:0E:69:8E:CC:49:8D:F5:25:77:EB:F2:E9:3B:9A, Active, Default;&lt;BR /&gt;Root Cert 15: DigiCert Global Root CA, SHA256, 43:48:A0:E9:44:4C:78:CB:26:5E:05:8D:5E:89:44:B4:D8:4F:96:62:BD:26:DB:25:7F:89:34:A4:43:C7:01:61, Active, Default;&lt;BR /&gt;Root Cert 16: DigiCert Global Root G2, SHA256, CB:3C:CB:B7:60:31:E5:E0:13:8F:8D:D3:9A:23:F9:DE:47:FF:C3:5E:43:C1:14:4C:EA:27:D4:6A:5A:B1:CB:5F, Active, Default;&lt;BR /&gt;Root Cert 17: DigiCert Global Root G3, SHA256, 31:AD:66:48:F8:10:41:38:C7:38:F3:9E:A4:32:01:33:39:3E:3A:18:CC:02:29:6E:F9:7C:2A:C9:EF:67:31:D0, Active, Default;&lt;BR /&gt;Root Cert 18: DigiCert Trusted Root G4, SHA256, 55:2F:7B:DC:F1:A7:AF:9E:6C:E6:72:01:7F:4F:12:AB:F7:72:40:C7:8E:76:1A:C2:03:D1:D9:D2:0A:C8:99:88, Active, Default;&lt;BR /&gt;Root Cert 19: GlobalSign NP RSA CA 2018, SHA256, 67:54:0A:47:AA:5B:9F:34:57:0A:99:72:3C:FE:FA:96:A9:6E:E3:F0:D9:B8:BF:4D:EF:94:40:B8:06:5D:66:5D, Active, Default;&lt;BR /&gt;Root Cert 20: GlobalSign NP ECC CA 2018, SHA256, 72:24:39:52:22:CD:58:8C:4F:26:83:71:69:22:AD:DB:41:E3:9B:58:1A:C3:4F:A8:7B:39:EF:A8:96:FB:B3:9E, Active, Default;&lt;BR /&gt;Root Cert 21: GlobalSign Root CA - R3, SHA256, CB:B5:22:D7:B7:F1:27:AD:6A:01:13:86:5B:DF:1C:D4:10:2E:7D:07:59:AF:63:5A:7C:F4:72:0D:C9:63:C5:3B, Active, Default;&lt;BR /&gt;Root Cert 22: GlobalSign ECC Root CA - R5, SHA256, 17:9F:BC:14:8A:3D:D0:0F:D2:4E:A1:34:58:CC:43:BF:A7:F5:9C:81:82:D7:83:A5:13:F6:EB:EC:10:0C:89:24, Active, Default;&lt;BR /&gt;Root Cert 23: GlobalSign Root CA - R6, SHA256, 2C:AB:EA:FE:37:D0:6C:A2:2A:BA:73:91:C0:03:3D:25:98:29:52:C4:53:64:73:49:76:3A:3A:B5:AD:6C:CF:69, Active, Default;&lt;/P&gt;&lt;P&gt;Pausing before ending process in 3 sec. The duration of this pause can be adjusted using the --delayterm option.&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2023 17:09:30 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1487495#M10110</guid>
      <dc:creator>mrant-k</dc:creator>
      <dc:date>2023-05-18T17:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1487650#M10112</link>
      <description>&lt;P&gt;Hello, mrant-k,&lt;/P&gt;
&lt;P&gt;The issue seems to be a hardware limitation.&amp;nbsp; The endpoints (client) need to have Intel® vPro in the processor, chipset, and embedded network card (only Intel® wired and wireless cards).&amp;nbsp; Few docking stations are prepared for Intel® vPro.&lt;/P&gt;
&lt;P&gt;I suggest you try the following:&lt;BR /&gt;1- Review the EMA agent profile settings, and make sure the WiFi configuration is set. If not, do the changes and re-install the new EMA agent file to the endpoints.&lt;BR /&gt;2- Unplug the USB-C ethernet dongle and try the provisioning and connection using the WiFi connection. I am sorry for the limitation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bear in mind, Intel® EMA requires endpoints with AMT version 11.8.79 and later.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Look forward to your response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Miguel C.&lt;BR /&gt;Intel Customer Support Technician&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 00:26:52 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1487650#M10112</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-19T00:26:52Z</dc:date>
    </item>
    <item>
      <title>Re:Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1488891#M10120</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Hello, mrant-k,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;I hope this email finds you well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;By any chance, have you been able to work on my previous suggestions?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Look forward to your response.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Miguel C.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Intel Customer Support Technician&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 23 May 2023 17:31:32 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1488891#M10120</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-23T17:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1488927#M10121</link>
      <description>&lt;P&gt;Hello Miguel,&lt;/P&gt;&lt;P&gt;Unfortunately, still hasn't worked for us. We use certificate-based authentication for corporate WiFi, and I have not been able to PKI provision any of these new laptops that don't have ethernet port even after creating WiFi profile to my best knowledge. If I do host-based provisioning, it provisions just fine, but then it goes to CCM mode.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 19:11:42 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1488927#M10121</guid>
      <dc:creator>mrant-k</dc:creator>
      <dc:date>2023-05-23T19:11:42Z</dc:date>
    </item>
    <item>
      <title>Re:Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1488967#M10123</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Hello, mrant-k,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Thank you for your update.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Thank you for your update on the status of the laptops.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Please keep using the wireless network card.&amp;nbsp; The full provisioning of the laptops in Admin control mode requires manual configuration the first time.&amp;nbsp;It is necessary to include the PKI DNS suffix manually into the MEBx (AMT BIOS).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Please review if the PKI DNS suffix was included.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Steps:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;-Adding PKI DNS suffix to MEBx&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;-From the MEBx Main Menu, click MEBx Login, and type your password.&amp;nbsp; The Default is admin, if I am not wrong, you set a password for all the endpoints in the EMA web console.&amp;nbsp;If a randomized password was set, select the endpoint, click the Actions button, and it displays the password of the endpoint.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;-Click over Intel® AMT Configuration&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;-Scroll down and select Remote Setup and Configuration&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;-Select TLS PKI&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;-Select PKI DNS Suffix, hit enter&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;-Type your PKI DNS Suffix, hit Enter&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;The new Window will display the new PKI DNS Suffix&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;-Then, keep pressing Exit until you close MEBX.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;At this point, the Endpoint will be in Admin Mode with the company PKI DNS Suffix.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Details in the document: Configuring LAN-less Endpoints to ACM &lt;A href="https://www.intel.com/content/dam/support/us/en/documents/software/manageability-products/configuring-lan-less-endpoints-to-acm.pdf" target="_blank"&gt;https://www.intel.com/content/dam/support/us/en/documents/software/manageability-products/configuring-lan-less-endpoints-to-acm.pdf&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Look forward to your response.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Miguel C.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Intel Customer Support Technician&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 23 May 2023 21:02:25 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1488967#M10123</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-23T21:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1489001#M10125</link>
      <description>&lt;P&gt;Hi Miguel,&lt;/P&gt;&lt;P&gt;I deprovisioned one of the laptops, uninstall agent, and "stop managing endpoint" in EMA. And follow your instructions to enter those info, yet the issue persists.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mrantk_0-1684879122811.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41506i73F6CFA403087655/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="mrantk_0-1684879122811.png" alt="mrantk_0-1684879122811.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 21:58:56 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1489001#M10125</guid>
      <dc:creator>mrant-k</dc:creator>
      <dc:date>2023-05-23T21:58:56Z</dc:date>
    </item>
    <item>
      <title>Re:Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1489029#M10126</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Hello, mrant-k,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;I am sorry to hear about the issue.&amp;nbsp; Do you mind confirming if the PKI DNS suffix was included manually in MEBx BIOS?  In addition, if you are using the wireless card instead of the USB-Network dongle.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;The PKI DNS suffix needs to match the PKI DNS of the AMT certificate.&amp;nbsp; Do you mind sending a new EMA Configuration log from the endpoint that you are trying to provision?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;EMA Configuration Tool&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;&lt;A href="https://www.intel.com/content/www/us/en/download/19805/30485/intel-endpoint-management-assistant-configuration-tool-intel-ema-configuration-tool.html" target="_blank"&gt;https://www.intel.com/content/www/us/en/download/19805/30485/intel-endpoint-management-assistant-configuration-tool-intel-ema-configuration-tool.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Run:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;a-Open a command prompt (alternatively, you can run the tool from within Windows PowerShell*) as administrator.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;b-Navigate to the installation folder (default C:\Program Files (x86)\Intel\EMAConfigTool).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;c-Run the command: EMAConfigTool.exe –verbose&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Look forward to your response.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Miguel C.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Intel Customer Support Technician&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 23 May 2023 23:28:33 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1489029#M10126</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-23T23:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1489250#M10127</link>
      <description>&lt;P&gt;Hello Miguel,&lt;/P&gt;&lt;P&gt;Yes, I confirm DNS suffix is added to MBEx. The laptops are directly connected to corp WiFi. Here's verbose result of one of the laptops.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Program Files (x86)\Intel\EMAConfigTool&amp;gt;EMAConfigTool.exe --verbose&lt;/P&gt;&lt;P&gt;Intel EMA Configuration Tool&lt;BR /&gt;Application Version: 1.1.0.183&lt;BR /&gt;Scan Date: 5/24/2023 8:17:57 AM&lt;/P&gt;&lt;P&gt;*** Host Computer Information ***&lt;BR /&gt;Computer Name: LTxxxx&lt;BR /&gt;Manufacturer: Dell Inc.&lt;BR /&gt;Model: Latitude 9520&lt;BR /&gt;Processor: 11th Gen Intel(R) Core(TM) i7-1185G7 @ 3.00GHz&lt;BR /&gt;Windows Version: Microsoft Windows 10 Enterprise&lt;BR /&gt;BIOS Version: 1.21.0&lt;BR /&gt;UUID: 4C4C4544-005A-3210-8032-C8C04F4B5233&lt;/P&gt;&lt;P&gt;*** SMBIOS Information ***&lt;BR /&gt;AMT Supported: True&lt;BR /&gt;AMT Enabled: True&lt;BR /&gt;SMBIOS ME SKU: Intel(R) Full AMT Manageability&lt;BR /&gt;SMBIOS ME Version: 15.0.42.2235&lt;BR /&gt;KVM Supported: True&lt;BR /&gt;SOL Supported: True&lt;BR /&gt;USB-R supported in BIOS: True&lt;BR /&gt;RSE Supported: True&lt;/P&gt;&lt;P&gt;*** ME Information ***&lt;BR /&gt;Version: 15.0.42.2235&lt;BR /&gt;SKU: Intel(R) Full AMT Manageability&lt;BR /&gt;State: Provisioned&lt;BR /&gt;Control Mode: Client&lt;BR /&gt;Driver Installed: True&lt;BR /&gt;Driver Version: 2220.3.1.0&lt;BR /&gt;PKI DNS Suffix: Not Found&lt;BR /&gt;LMS State: Running&lt;BR /&gt;LMS Version: 2220.3.1.0&lt;BR /&gt;MicroLMS State: NotPresent&lt;BR /&gt;EHBC Enabled: False&lt;/P&gt;&lt;P&gt;*** ME Capabilities ***&lt;BR /&gt;AMT in Enterprise Mode: True&lt;BR /&gt;TLS Enabled: False&lt;BR /&gt;HW Crypto Enabled: True&lt;BR /&gt;Current Provisioning state: POST_PROVISIONING_STATE&lt;BR /&gt;NetworkInterface Enabled: True&lt;BR /&gt;SOL Enabled: True&lt;BR /&gt;IDER Enabled: True&lt;BR /&gt;FWUpdate Enabled: False&lt;BR /&gt;LinkIsUp state: False&lt;BR /&gt;KVM Enabled: False&lt;BR /&gt;RSE Enabled: True&lt;/P&gt;&lt;P&gt;*** Power Management Capabilities ***&lt;BR /&gt;Supported Power States:&lt;BR /&gt;5: PowerCycle_Off_Soft&lt;BR /&gt;8: Off_Soft&lt;BR /&gt;2: On&lt;BR /&gt;10: Master_Bus_Reset&lt;BR /&gt;11: NMI&lt;BR /&gt;7: Hibernate&lt;BR /&gt;12: Off_Soft_Graceful&lt;BR /&gt;14: MasterBusReset_Graceful&lt;BR /&gt;Power Change Capabilities:&lt;BR /&gt;2: On&lt;BR /&gt;3: SleepLight&lt;BR /&gt;4: SleepDeep&lt;BR /&gt;7: Hibernate&lt;BR /&gt;8: Off_Soft&lt;/P&gt;&lt;P&gt;*** CIRA Information ***&lt;BR /&gt;CIRA Server: Not Found&lt;BR /&gt;CIRA Connection Status: NOT_CONNECTED&lt;BR /&gt;CIRA Connection Trigger: USER_INITIATED&lt;/P&gt;&lt;P&gt;*** ME Wired Network Information ***&lt;BR /&gt;ME Wired Interface Not Detected&lt;/P&gt;&lt;P&gt;*** ME Wireless Network Information ***&lt;BR /&gt;Wireless Interface Enabled: False&lt;BR /&gt;Link Status: Down&lt;BR /&gt;IP Address: 0.0.0.0&lt;BR /&gt;MAC Address: Information Unavailable&lt;BR /&gt;DHCP Enabled: True&lt;BR /&gt;DHCP Mode: Unknown&lt;/P&gt;&lt;P&gt;*** Root Certificate Hash Entries ***&lt;BR /&gt;Root certs HERE&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 16:26:52 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1489250#M10127</guid>
      <dc:creator>mrant-k</dc:creator>
      <dc:date>2023-05-24T16:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1489252#M10128</link>
      <description>&lt;P&gt;Client logs also show pretty much the same as before.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mrantk_0-1684934562890.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41580i60068C91EF04BC8A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="mrantk_0-1684934562890.png" alt="mrantk_0-1684934562890.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 13:22:10 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1489252#M10128</guid>
      <dc:creator>mrant-k</dc:creator>
      <dc:date>2023-05-24T13:22:10Z</dc:date>
    </item>
    <item>
      <title>Re:Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1489764#M10131</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Hello, mrant-k,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;The ECT log is showing the PKI DNS as not found in this wireless machine.&amp;nbsp; Please remember the ethernet USB dongle is not supported.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Please review the MEBx BIOS, and check if the PKI DNS suffix is there.&amp;nbsp; I sent you an email with a Word document with pictures as an example.&amp;nbsp;Please review if the machine is running the latest BIOS and Management Engine Interface driver.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;We can continue privately in order to gather the EMA url that you are using, the PKI DNS suffix, the certificate configuration, and how many endpoints will you provision.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Look forward to your response; if there is no response to this email, I will send you a follow-up on 5/26/2023.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Miguel C.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Intel Customer Support Technician&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 24 May 2023 22:24:59 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1489764#M10131</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-24T22:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1490008#M10135</link>
      <description>&lt;P&gt;Hello Miguel,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I confirm the correct dns suffix was already set. We are not using USB dongle nor docking sttion.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mrantk_0-1685026403166.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41929i9C1C31EB780E5B56/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="mrantk_0-1685026403166.png" alt="mrantk_0-1685026403166.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Yet, I'm still getting the same "Failed PKI provisioning" error.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did follow your instructions, too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;log into MEBx&lt;/LI&gt;&lt;LI&gt;full unprovision&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In addition to that,&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I also ran "EMAConfigTool.exe --unconfigure --password PASSWORD" and got confirmation it was successfully unconfigured&lt;/LI&gt;&lt;LI&gt;And then I uninstalled the agent&lt;/LI&gt;&lt;LI&gt;Logged into MEBx again and made sure it is full unprovisioned and the DNS suffix is still there&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mrantk_1-1685027028380.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41930i67FB67ED3D525B9B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="mrantk_1-1685027028380.png" alt="mrantk_1-1685027028380.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Logged back into Windows and reinstalled the agent&lt;/LI&gt;&lt;LI&gt;Get that very same error&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 25 May 2023 15:06:30 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1490008#M10135</guid>
      <dc:creator>mrant-k</dc:creator>
      <dc:date>2023-05-25T15:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1490021#M10136</link>
      <description>&lt;P&gt;Here are the new agent logs:&lt;/P&gt;&lt;P&gt;[2023-05-25 10:24:42.803 AM] \Agent\MeshManageability\agent\core\meshctrl.c:1143 Packet is not encrypted correctly or uses an old key. Last error: 0&lt;BR /&gt;[2023-05-25 10:24:52.888 AM] \Agent\MeshManageability\agent\core\meshctrl.c:1143 Packet is not encrypted correctly or uses an old key. Last error: 0&lt;BR /&gt;[2023-05-25 10:25:01.826 AM] \Agent\MeshManageability\agent\core\meshctrl.c:1143 Packet is not encrypted correctly or uses an old key. Last error: 0&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 15:27:38 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1490021#M10136</guid>
      <dc:creator>mrant-k</dc:creator>
      <dc:date>2023-05-25T15:27:38Z</dc:date>
    </item>
    <item>
      <title>Re:Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1490098#M10137</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Hello, mrant-k,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;It seems GoDaddy’s certificate does not match Intel® EMA requirements, the root, intermediate, and leaf need to be SHA256.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Please validate this information by doing the following:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;-Open IIS, go to the personal store, and open the Certificate, you should see the Cert. chain (3 lines) in the Certificate Path tab.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;-Open each line (Details tab) and verify they match the encryption of SHA 256 (SHA2) (2048 bits).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;-In addition, for the leaf; from the Details tab, scroll down and confirm the Enhanced Key usage matches the OID number 2.16.840.1.113741.1.2.3.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;I would appreciate it if you can share screenshots.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Look forward to your response.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Miguel C.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Intel Customer Support Technician&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 25 May 2023 19:34:29 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1490098#M10137</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-25T19:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1490110#M10138</link>
      <description>&lt;P&gt;Hi Miguel,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's my GoDaddy SSL with correct OID.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mrantk_0-1685044095493.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41944i83D1C4CC2E4EA538/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="mrantk_0-1685044095493.png" alt="mrantk_0-1685044095493.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The chain however shows "Go Daddy Class 2 Cert Authority" having SHA1.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mrantk_1-1685044168547.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41942i860A665DEE03A6F3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="mrantk_1-1685044168547.png" alt="mrantk_1-1685044168547.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mrantk_2-1685044192047.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41943i5F4078C6CF8C9B50/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="mrantk_2-1685044192047.png" alt="mrantk_2-1685044192047.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The other two certs (Go Daddy Root CA and Go Daddy Secure CA) have SHA256.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mrantk_4-1685044331271.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41946i0394B97E5AC6AE6D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="mrantk_4-1685044331271.png" alt="mrantk_4-1685044331271.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mrantk_3-1685044313291.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/41945i7BC0FC143684B153/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="mrantk_3-1685044313291.png" alt="mrantk_3-1685044313291.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 19:51:36 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1490110#M10138</guid>
      <dc:creator>mrant-k</dc:creator>
      <dc:date>2023-05-25T19:51:36Z</dc:date>
    </item>
    <item>
      <title>Re:Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1490175#M10139</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Hello, mrant-k,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;You are right, the certificate chain is wrong.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;It is necessary to get in touch with GoDaddy.&amp;nbsp; The Certificate chain usually has 3 lines only. &amp;nbsp;I am sending a link with an example of the Root section of the certificate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;&lt;A href="https://certs.godaddy.com/repository/gdroot-g2.crt" target="_blank"&gt;https://certs.godaddy.com/repository/gdroot-g2.crt&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Miguel C.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Intel Customer Support Technician&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 25 May 2023 23:18:33 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1490175#M10139</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-25T23:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1491211#M10147</link>
      <description>&lt;P&gt;Hi Miguel,&lt;/P&gt;&lt;P&gt;I did contact them, but they didn't have any clue what needs to be done. In fact, most of the support reps I've been dealing at Go Daddy aren't familiar with vPro at all. Can you tell me what information I need to relay to them so I can get a correct cert?&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 15:39:41 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1491211#M10147</guid>
      <dc:creator>mrant-k</dc:creator>
      <dc:date>2023-05-30T15:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1491226#M10148</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello, mrant-k,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I apologize for the inconvenience experienced with GoDaddy.&amp;nbsp;I have a piece of old information, hopefully, this with help as a guide.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;While you are selecting the type of certificate, choose the option that says: Organizational Validation (OV) SLL Certificate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Then, a pop-up should appear, and select Intel® vPro.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vPro.PNG" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/42078i48317A4CCEE7379E/image-size/medium?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="vPro.PNG" alt="vPro.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I look forward to hearing from you.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Miguel C.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Intel Customer Support Technician&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 16:24:53 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1491226#M10148</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-30T16:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1491277#M10150</link>
      <description>&lt;P&gt;Hi Miguel,&lt;/P&gt;&lt;P&gt;That was how I set up our cert. It is why some of the devices are getting provisioned successfully. The issue here is that some devices don't get provisioned. One thing I notice is that if I open the cert on my laptop, I can see it has presumably correct certificate chain.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mrantk_0-1685472867318.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/42081iBD9DE7C354BE4FB5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="mrantk_0-1685472867318.png" alt="mrantk_0-1685472867318.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if I open it on vPro server, it shows one additional CA (the class 2 one) in the chain for some reason.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mrantk_1-1685472926763.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/42082iBA77E7645DFC7B7C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="mrantk_1-1685472926763.png" alt="mrantk_1-1685472926763.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 18:55:24 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1491277#M10150</guid>
      <dc:creator>mrant-k</dc:creator>
      <dc:date>2023-05-30T18:55:24Z</dc:date>
    </item>
    <item>
      <title>Re:Failed PKI provisioning</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1491336#M10154</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Hello, mrant-k,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Thank you for your quick response.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;The certificate is showing an extra line as you mentioned, and it is SHA1.&amp;nbsp;This is the Certificate issue. We need a Certificate chain with SHA2 (SHA256) in all the lines.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;I found this public GoDaddy link, it talks about how to request an Intel® vPro Certificate.&amp;nbsp; Please review it and confirm with GoDaddy if they send you the correct certificate.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;GoDaddy certificate instructions&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;&lt;A href="https://www.godaddy.com/help/intel-vpro-certificate-info-5260" target="_blank"&gt;https://www.godaddy.com/help/intel-vpro-certificate-info-5260&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;If I understand correctly, it is necessary to choose the “Organizational Validation (OV) SLL Certificate” option.&amp;nbsp;&amp;nbsp;When the product is added to the shopping cart, the terminology changes to “You’ve chosen a Deluxe SSL OV”.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;I hope that Go Daddy will provide the correct Cert this time.&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 30 May 2023 22:23:42 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Failed-PKI-provisioning/m-p/1491336#M10154</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-05-30T22:23:42Z</dc:date>
    </item>
  </channel>
</rss>

