<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re:TLS connection error when using Intel Manageability Commander in Intel vPro® Platform</title>
    <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1508963#M10416</link>
    <description>&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Hello, ICIT,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;I understand the provisioning of the machine was completed.&amp;nbsp;&amp;nbsp;The limitation is related to how the endpoint validates EMC and how EMC validates the endpoint connection.&amp;nbsp; This process requires a pre-validated Certificate (SHA256 – TLS).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Miguel C.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Intel Customer Support Technician&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
    <pubDate>Fri, 28 Jul 2023 00:27:41 GMT</pubDate>
    <dc:creator>MIGUEL_C_Intel</dc:creator>
    <dc:date>2023-07-28T00:27:41Z</dc:date>
    <item>
      <title>TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1502683#M10326</link>
      <description>&lt;P&gt;I have a Dell Precision 3460 with AMT 16.1. This version now requires the use of TLS. When I attempt to connect to this device using&amp;nbsp;Intel Manageability Commander, an error message is displayed stating "imcException - A TLS connection could not be established".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MeshCommander however connects with no problem. Likewise, I can connect via web browser via HTTPS on port 16993.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Manageability Commander is the latest version (2.4) installed using the IMCInstaller-2.4.0.msi, although the interface reports that it's 2.3. I suspect this is just a developer oversight.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See attached screenshot of AMT embedded certificate as reported by MeshCommander. No obvious issues there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas why IMC won't connect?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 13:25:10 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1502683#M10326</guid>
      <dc:creator>ICIT</dc:creator>
      <dc:date>2023-07-07T13:25:10Z</dc:date>
    </item>
    <item>
      <title>Re:TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1503265#M10331</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Hello, ICIT,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;I hope this email finds you well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;The certificate issue experienced is expected on endpoints with AMT version 16.X.&amp;nbsp;Self-Certificates are not supported anymore.&amp;nbsp;There is a note at the button of the Intel® Manageability Commander (IMC) download website and in the release note PDF.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Note: Trying to connect to a target system that uses self-signed TLS certificates will result in an error.&amp;nbsp;This is an expected behavior.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Intel® Manageability Commander download page&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;&lt;A href="https://www.intel.com/content/www/us/en/download/18796/intel-manageability-commander.html" target="_blank"&gt;https://www.intel.com/content/www/us/en/download/18796/intel-manageability-commander.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;The troubleshooting is acquiring a third-party Intel® AMT Certificate from authorized Intel Certificate vendors.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Vendor Certificates to Support Intel® AMT&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;&lt;A href="https://www.intel.com/content/www/us/en/architecture-and-technology/vpro/active-management-technology/implementation.html" target="_blank"&gt;https://www.intel.com/content/www/us/en/architecture-and-technology/vpro/active-management-technology/implementation.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;MeshCommander supports self-Certificates.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;I was able to install the latest version of IMC version 2.4, no issues were experienced, my PC is running Wind 10.&amp;nbsp;Please retry using the instructions in section 2 - Installing and Uninstalling, of the user guide.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;&lt;A href="https://downloadmirror.intel.com/27807/Intel%20Manageability%20Commander%20User%20Guide.pdf#page=5" target="_blank"&gt;https://downloadmirror.intel.com/27807/Intel%20Manageability%20Commander%20User%20Guide.pdf#page=5&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;I will gladly provide further assistance if necessary.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Miguel C.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Intel Customer Support Technician&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 10 Jul 2023 17:25:43 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1503265#M10331</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-07-10T17:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: Re:TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504181#M10344</link>
      <description>&lt;P&gt;Got it, thanks. I overlooked the note about connection errors with&amp;nbsp;&lt;SPAN&gt;self-signed TLS certificates.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For your installation&amp;nbsp;of IMC v2.4, when you go to Help &amp;gt; About, what version number is reported?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 19:04:55 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504181#M10344</guid>
      <dc:creator>ICIT</dc:creator>
      <dc:date>2023-07-12T19:04:55Z</dc:date>
    </item>
    <item>
      <title>Re:TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504253#M10347</link>
      <description>&lt;P&gt;Hello, ICIT,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;My IMC says 2.4 in the help section.&amp;nbsp;Did you have the previous version 2.3 on your server?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The latest version of the electron is v25.3.0&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/electron/electron/releases/tag/v25.3.0" target="_blank"&gt;https://github.com/electron/electron/releases/tag/v25.3.0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I look forward to hearing from you.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Miguel C.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 12 Jul 2023 23:01:26 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504253#M10347</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-07-12T23:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: Re:TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504277#M10348</link>
      <description>&lt;P&gt;Hmmm. I uninstalled per the IMC user guide, which is basically just using the Control Panel &amp;gt; Programs &amp;gt; Uninstall a Program function in Windows. I then deleted the&amp;nbsp;&lt;EM&gt;C:\Program Files (x86)\Intel\Intel Manageability Commander&lt;/EM&gt; directory and re-ran the&amp;nbsp;IMCInstaller-2.4.0.msi installer. Note that I checked the SHA1 hash to confirm that my installer wasn't modified/corrupted. Before doing the post-install action of copying Electron to the IMC directory, I looked a few files in there. Here are the first few lines of&amp;nbsp;&amp;nbsp;&lt;EM&gt;C:\Program Files (x86)\Intel\Intel Manageability Commander\resources\app\package.json&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;"name": "imc",&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;"version": "2.3.0",&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;"description": "Intel(R) Active Management Technology console tool",&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;"main": "main-electron.js",&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;"author": "Intel Corporation",&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;"copyright": "Copyright 2016-2021, Intel Corporation",&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure if that's supposed to be 2.3.0 or 2.4.0, I would assume the latter. I then copied Electron to the IMC directory per the instructions in the&amp;nbsp;ReadMe-PostInstall.txt file, which references&amp;nbsp;electron-v8.5.5-win32-ia32.zip. Note that the v2.4 IMC user guide states...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#999999"&gt;Note: Intel MC is tested and verified only with version 8.5.5 of electron (for Win32 and IA32). Use this ver-sion for both 32 bit and 64 bit platforms. Other versions of electron are not tested or supported.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;1. In a web browser, go to &lt;A href="https://github.com/electron/electron/releases/tag/v8.5.5" target="_blank" rel="noopener"&gt;https://github.com/electron/electron/releases/tag/v8.5.5&lt;/A&gt;.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#999999"&gt;2. Scroll down and select electron-v8.5.5-win32-ia32.zip (see note above). The file is downloaded to your system.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you running it with v25.3.0?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In any event, when I launch and go to Help &amp;gt; About it still reports v2.3. I did have a previous version installed before all of this although I don't recall which specific version.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 02:00:59 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504277#M10348</guid>
      <dc:creator>ICIT</dc:creator>
      <dc:date>2023-07-13T02:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504549#M10349</link>
      <description>&lt;P&gt;Hello, ICIT,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope all is well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The tests were performed with both electron versions.&amp;nbsp; The only difference is with the option SHA1.&amp;nbsp;Intel has improved the security with the latest version, only TLS connections are supported, and SHA256 is a requirement.&amp;nbsp; Please try with the option unchecked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am pasting a picture of what I have from add or remove a program.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2_4 Manageability Commander.PNG" style="width: 695px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/43543iE2B5ADDA4D719858/image-size/large?v=v2&amp;amp;px=999&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="2_4 Manageability Commander.PNG" alt="2_4 Manageability Commander.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Miguel C.&lt;/P&gt;
&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 18:21:32 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504549#M10349</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-07-13T18:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504651#M10351</link>
      <description>&lt;P&gt;In Add and Remove Programs on my computer it also shows as v2.4. It's the application GUI where it reports as v2.3. If you go to IMC and select Help &amp;gt; About does is show 2.3 or 2.4?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 02:35:52 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504651#M10351</guid>
      <dc:creator>ICIT</dc:creator>
      <dc:date>2023-07-14T02:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504828#M10355</link>
      <description>&lt;P&gt;BTW, I uninstalled IMC again and reinstalled using Electron v25.3.0. When I launch IMC it just shows a blank window.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ICIT_0-1689347085902.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/43590iF75C39965DE95780/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="ICIT_0-1689347085902.png" alt="ICIT_0-1689347085902.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 15:05:36 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504828#M10355</guid>
      <dc:creator>ICIT</dc:creator>
      <dc:date>2023-07-14T15:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504838#M10356</link>
      <description>&lt;P&gt;After another uninstall and reinstall using Electron 8.5.5, I'm back where I started. IMC is running but still reports v2.3.0 in the UI.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ICIT_1-1689347815962.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/43591i2EC44C1BADDD5A29/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="ICIT_1-1689347815962.png" alt="ICIT_1-1689347815962.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And under Help &amp;gt; About&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ICIT_2-1689347854211.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/43592i457F1DBE83294809/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="ICIT_2-1689347854211.png" alt="ICIT_2-1689347854211.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In Windows Control Panel &amp;gt; Programs and Features it does report as v2.4&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ICIT_3-1689347951420.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/43593iD1787333B3CB6474/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="ICIT_3-1689347951420.png" alt="ICIT_3-1689347951420.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I'm working under the assumption that this is just a UI issue where a version number was not updated in a source file somewhere and likely not a concern regarding functionality.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 15:21:26 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504838#M10356</guid>
      <dc:creator>ICIT</dc:creator>
      <dc:date>2023-07-14T15:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504864#M10357</link>
      <description>&lt;P&gt;*Duplicate*&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jul 2023 00:50:56 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504864#M10357</guid>
      <dc:creator>ICIT</dc:creator>
      <dc:date>2023-07-15T00:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504889#M10358</link>
      <description>&lt;P&gt;Getting back to the original issue of IMC displaying an error when connecting using TLS...&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ICIT_4-1689348239715.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/43594iA2984838ED5D6DE3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="ICIT_4-1689348239715.png" alt="ICIT_4-1689348239715.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Initially was attempting to connect with AMT configured using the embedded self-signed TLS certificate, which, as noted above, is not supported by IMC.&lt;/P&gt;&lt;P&gt;To use TLS to connect to an AMT client using IMC, the following must be in place...&lt;/P&gt;&lt;P&gt;- The hostname must be set to a FQDN, IP address cannot be used&lt;/P&gt;&lt;P&gt;- Use TLS enabled&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ICIT_5-1689348989640.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/43595i934D414E71A102CB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="ICIT_5-1689348989640.png" alt="ICIT_5-1689348989640.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- A certificate must be installed on the AMT device with the Subject CN set to match the FQDN of the device&lt;/P&gt;&lt;P&gt;* Screenshot of certificate in Windows&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ICIT_6-1689349194739.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/43596iD39EF8D064FD8B0E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="ICIT_6-1689349194739.png" alt="ICIT_6-1689349194739.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;* Screenshot showing above certificate installed an AMT device&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ICIT_9-1689349651682.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/43599i2DA4056D529946C5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="ICIT_9-1689349651682.png" alt="ICIT_9-1689349651682.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- The root CA certificate (issuer certificate) must be installed in the&amp;nbsp;Trusted Root Certificate store on the Windows computer where IMC is running. This enables IMC to trust the certificate installed on the AMT device&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ICIT_7-1689349373708.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/43597iEBF154612EEC7FAB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="ICIT_7-1689349373708.png" alt="ICIT_7-1689349373708.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;* Screenshot showing the certificate is indeed trusted on the Windows computer where IMC is running&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ICIT_10-1689349820746.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/43600iE07F2B37D63EB4FC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="ICIT_10-1689349820746.png" alt="ICIT_10-1689349820746.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- IMC v2.4 supports TLS 1.1 and newer, it does not support TLS 1.0. TLS 1.1 was implemented in AMT 11.6 so the connection must be to a computer running this version of AMT firmware or newer.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ICIT_8-1689349575154.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/43598iBEB544464862BE81/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="ICIT_8-1689349575154.png" alt="ICIT_8-1689349575154.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All of the above is in place however I still receive the same connection error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To troubleshoot further I launched IMC in debug mode from the command line&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;C:\Program Files (x86)\Intel\Intel Manageability Commander\electron.exe --loglevel=debug&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This generates debug level messages in the log file located here&lt;/P&gt;&lt;P&gt;C:\Users\Username\AppData\Roaming\Intel\Intel Manageability Commander\application.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From these messages I gather that IMC receives the certificate from the AMT device and saves it as tempCert.cer. It then runs&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;certutil -verify&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;to get details and checks the hostname against the Subject CN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;{"level":"debug","message":"Setting up connection: host=muse.homenet.local; port=16993; authMode=0; username=admin; password=mypassword; useKerberos=false; tls=true"}&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;{"level":"verbose","message":"Getting AMT class CIM_SoftwareIdentity"}&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;{"level":"debug","message":"Writing TLS cert temp file: C:\\Users\\USER~1\\AppData\\Local\\Temp\\tempCert.cer"}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;{"level":"verbose","message":"CertUtil output: \r\nIssuer:\r\n O=ICIT\r\n S=IN\r\n C=US\r\n CN=MeshCommander Root CA\r\n Name Hash(sha1): e6773dcb281d379b6b0a2b5337f57bab814031b9\r\n Name Hash(md5): 7b92aadae2c55fc114b9cf2a27f55b9a\r\nSubject:\r\n O=ICIT\r\n S=IN\r\n C=US\r\n CN=muse.homenet.local\r\n Name Hash(sha1): 8b860183a274ed79ca3edfcb2bede31a3857aa0d\r\n Name Hash(md5): 2a6a59ff610b774414ba5d27bf19fed0\r\nCert Serial Number: 023615\r\n\r\ndwFlags = CA_VERIFY_FLAGS_ALLOW_UNTRUSTED_ROOT (0x1)\r\ndwFlags = CA_VERIFY_FLAGS_IGNORE_OFFLINE (0x2)\r\ndwFlags = CA_VERIFY_FLAGS_FULL_CHAIN_REVOCATION (0x8)\r\ndwFlags = CA_VERIFY_FLAGS_CONSOLE_TRACE (0x20000000)\r\ndwFlags = CA_VERIFY_FLAGS_DUMP_CHAIN (0x40000000)\r\nChainFlags = CERT_CHAIN_REVOCATION_CHECK_CHAIN (0x20000000)\r\nHCCE_LOCAL_MACHINE\r\nCERT_CHAIN_POLICY_BASE\r\n-------- CERT_CHAIN_CONTEXT --------\r\nChainContext.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)\r\nChainContext.dwErrorStatus = CERT_TRUST_REVOCATION_STATUS_UNKNOWN (0x40)\r\n\r\nSimpleChain.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)\r\nSimpleChain.dwErrorStatus = CERT_TRUST_REVOCATION_STATUS_UNKNOWN (0x40)\r\n\r\nCertContext[0][0]: dwInfoStatus=104 dwErrorStatus=40\r\n Issuer: O=ICIT, S=IN, C=US, CN=MeshCommander Root CA\r\n NotBefore: 1/1/2018 1:00 AM\r\n NotAfter: 12/31/2049 1:00 AM\r\n Subject: O=ICIT, S=IN, C=US, CN=muse.homenet.local\r\n Serial: 023615\r\n Cert: 90f01f5b7f0eaa083461992a87274b03d8af38e2\r\n Element.dwInfoStatus = CERT_TRUST_HAS_NAME_MATCH_ISSUER (0x4)\r\n Element.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)\r\n Element.dwErrorStatus = CERT_TRUST_REVOCATION_STATUS_UNKNOWN (0x40)\r\n ---------------- Certificate AIA ----------------\r\n No URLs \"None\" Time: 0 (null)\r\n ---------------- Certificate CDP ----------------\r\n No URLs \"None\" Time: 0 (null)\r\n ---------------- Certificate OCSP ----------------\r\n No URLs \"None\" Time: 0 (null)\r\n --------------------------------\r\n Application[0] = 1.3.6.1.5.5.7.3.1 Server Authentication\r\n\r\nCertContext[0][1]: dwInfoStatus=10c dwErrorStatus=0\r\n Issuer: O=ICIT, S=IN, C=US, CN=MeshCommander Root CA\r\n NotBefore: 1/1/2018 1:00 AM\r\n NotAfter: 12/31/2049 1:00 AM\r\n Subject: O=ICIT, S=IN, C=US, CN=MeshCommander Root CA\r\n Serial: 065494\r\n Cert: 47c7ee6ffcf018ecd493631b7909cbd61cc8030d\r\n Element.dwInfoStatus = CERT_TRUST_HAS_NAME_MATCH_ISSUER (0x4)\r\n Element.dwInfoStatus = CERT_TRUST_IS_SELF_SIGNED (0x8)\r\n Element.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)\r\n ---------------- Certificate AIA ----------------\r\n No URLs \"None\" Time: 0 (null)\r\n ---------------- Certificate CDP ----------------\r\n No URLs \"None\" Time: 0 (null)\r\n ---------------- Certificate OCSP ----------------\r\n No URLs \"None\" Time: 0 (null)\r\n --------------------------------\r\n\r\nExclude leaf cert:\r\n Chain: 90f01f5b7f0eaa083461992a87274b03d8af38e2\r\nFull chain:\r\n Chain: 3bf2b959269132595796685978af13f681842665\r\n------------------------------------\r\nVerified Issuance Policies: None\r\nVerified Application Policies:\r\n 1.3.6.1.5.5.7.3.1 Server Authentication\r\nCert is an End Entity certificate\r\nCannot check leaf certificate revocation status\r\nCertUtil: -verify command completed successfully.\r\n"}&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;{"level":"debug","message":"TLS cert subject CN matches target hostname (muse.homenet.local)? &lt;FONT color="#FF0000"&gt;false&lt;/FONT&gt;"}&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;{"level":"debug","message":"TLS cert DNS Name matches target hostname? &lt;FONT color="#FF0000"&gt;false&lt;/FONT&gt;"}&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;{"level":"verbose","message":"TLS certificate verification results: &lt;FONT color="#FF0000"&gt;false&lt;/FONT&gt;"}&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For some reason IMC is determining that the hostname does not match the certificate Subject CN, when in fact it does. See the &lt;FONT color="#FF0000"&gt;false&lt;/FONT&gt; results in the log messages above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking for some insight on why this is happening and what to try next.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 16:48:30 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504889#M10358</guid>
      <dc:creator>ICIT</dc:creator>
      <dc:date>2023-07-14T16:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504920#M10359</link>
      <description>&lt;P&gt;Side note: Do posts here need to be approved by a moderator before appearing on the site? I didn't think so as usually when I post something it appears right away. However I posted a reply to this thread earlier that is not showing up.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 18:37:46 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504920#M10359</guid>
      <dc:creator>ICIT</dc:creator>
      <dc:date>2023-07-14T18:37:46Z</dc:date>
    </item>
    <item>
      <title>Re:TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504923#M10360</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Hello, ICIT,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;The new posts are instantly included on the website, no moderator approval is necessary; maybe the tool had an issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Regarding the IMC version installed; did you uncheck the SHA1 option while doing the update?&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Miguel C.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Intel Customer Support Technician&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 14 Jul 2023 18:54:02 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504923#M10360</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-07-14T18:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: Re:TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504925#M10361</link>
      <description>&lt;P&gt;Hmm, ok. It looks like my post was lost. I'll work on recreating. Sigh.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you say "&lt;SPAN&gt;did you uncheck the SHA1 option while doing the update" I'm not sure what you're referring to. I simply ran the&amp;nbsp;IMCInstaller-2.4.0.msi installer, I don't think there was any option regarding SHA1 during that process. Can you elaborate?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 18:58:16 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504925#M10361</guid>
      <dc:creator>ICIT</dc:creator>
      <dc:date>2023-07-14T18:58:16Z</dc:date>
    </item>
    <item>
      <title>Re:TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504978#M10363</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;‎Hello, ICIT,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;I was referring to your comment on 07-12-2023 at 06:59 PM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;I uninstalled it per the IMC user guide, which is basically just using the Control Panel &amp;gt; Programs &amp;gt; Uninstall a Program function in Windows.&amp;nbsp;I then deleted the C:\Program Files (x86)\Intel\Intel Manageability Commander directory and re-ran the IMCInstaller-2.4.0.msi installer.&amp;nbsp; Note that I checked the SHA1 hash to confirm that my installer wasn't modified/corrupted.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Miguel C.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Intel Customer Support Technician&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 14 Jul 2023 22:01:35 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1504978#M10363</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-07-14T22:01:35Z</dc:date>
    </item>
    <item>
      <title>Re: TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1505017#M10365</link>
      <description>&lt;P&gt;I just meant that I verified the SHA1 hash of the file I downloaded matched was is shown on the download page&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ICIT_0-1689382372415.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/43607iDFDCC69A621F59EB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="ICIT_0-1689382372415.png" alt="ICIT_0-1689382372415.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I see that my missing post finally showed up (twice).&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jul 2023 00:54:32 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1505017#M10365</guid>
      <dc:creator>ICIT</dc:creator>
      <dc:date>2023-07-15T00:54:32Z</dc:date>
    </item>
    <item>
      <title>Re:TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1505419#M10368</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Hello, ICIT,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;I hope this email finds you well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;The Certificate issue is known; self-Certificates are not supported anymore.&amp;nbsp;In section 4 - Known Issues of the Intel® Manageability Commander (Intel® MC) Release Notes further details are available.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;It is necessary for a third-party Intel® AMT certificate chain.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Vendor Certificates to Support Intel® AMT, bottom of the page.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;&lt;A href="https://www.intel.com/content/www/us/en/architecture-and-technology/vpro/active-management-technology/implementation.html" target="_blank"&gt;https://www.intel.com/content/www/us/en/architecture-and-technology/vpro/active-management-technology/implementation.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;About the IMC version issue, I am working with the engineering department; I will make sure to provide an update in a few days.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Miguel C.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.625px;"&gt;Intel Customer Support Technician&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 17 Jul 2023 14:18:41 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1505419#M10368</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-07-17T14:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: Re:TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1505437#M10369</link>
      <description>&lt;P&gt;This is not a self-signed certificate though. I created it using MeshCommander's built-in certificate authority. It is signed by a root CA certificate, also created in MeshCommander, that is trusted on the Windows system that IMC is running on.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ICIT_0-1689604492876.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/43662iEDA055946812A2F5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="ICIT_0-1689604492876.png" alt="ICIT_0-1689604492876.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;There is a valid chain of trust so it should work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as Intel AMT specific certificates, it's my understanding that those are needed only for initial provisioning when the AMT client is reaching out to the&amp;nbsp;Setup and Configuration Application (SCA). That type of certificate must be installed on the SCA device, for example, when using Endpoint Management Assistant server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't find any documentation stating that creating TLS connections to a client require a special certificate. Per the IMC documentation, the only requirement mentioned regarding certificates is that a certificate must be trusted on the Windows computer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#3366FF"&gt;6 Certificate Checking&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#808080"&gt;Intel MC automatically verifies that certificates, used in TLS, chain down to a root in the Windows Computer Account Trusted Root certificate store of the machine from which it is run. Additionally, the Intel MC will verify that the DNS name or Subject Name in the certificate matches the host name of the Intel AMT device. Just like in web browsers, the machine will automatically connect and display a lock indicating that the connection is secured via TLS. If the certificate cannot chain to a root in the certificate store, then Intel MC will reject the connection and display an appropriate error message.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additionally, I looked at section 4 of the IMC release notes but there is nothing mentioned about certificates.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 14:48:43 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1505437#M10369</guid>
      <dc:creator>ICIT</dc:creator>
      <dc:date>2023-07-17T14:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1505533#M10372</link>
      <description>&lt;P&gt;Hello, ICIT,&lt;/P&gt;
&lt;P&gt;I am working on both questions with the engineering department.&amp;nbsp; An answer will be provided in a timely manner.&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Miguel C.&lt;BR /&gt;Intel Customer Support Technician&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 18:11:04 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1505533#M10372</guid>
      <dc:creator>MIGUEL_C_Intel</dc:creator>
      <dc:date>2023-07-17T18:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: TLS connection error when using Intel Manageability Commander</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1506794#M10388</link>
      <description>&lt;P&gt;Thanks. In the meantime I tried a different approach by adding an AMT certificate via PowerShell, using OpenSSL to generate the certificate. I followed the procedure documented here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Intel vPro Technology Module for Windows PowerShell Installation and User Guide.pdf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;6.14 TLS Configuration Flow Using PowerShell Snippets&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Intel AMT Implementation and Reference Guide&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/WordDocuments/enrollacertificate1.htm" target="_blank"&gt;https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/WordDocuments/enrollacertificate1.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/rgl/intel-amt-notes#tls-certificate" target="_blank"&gt;GitHub - rgl/intel-amt-notes: notes about intel amt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a new root CA certificate in OpenSSL that is trusted on the Windows computer where IMC is running. The AMT certificate is signed by that root CA.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ICIT_0-1689897102874.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/43837i2520ABF92B238D7F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="ICIT_0-1689897102874.png" alt="ICIT_0-1689897102874.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the end no luck, I still get the TLS error when attempting to connect. Although I did notice the IMC debug log was lightly different&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;{"level":"debug","message":"TLS cert subject CN matches target hostname (muse.homenet.local)? &lt;FONT color="#FF0000"&gt;true&lt;/FONT&gt;"}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;{"level":"debug","message":"TLS cert DNS Name matches target hostname? false"}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;{"level":"verbose","message":"TLS certificate verification results: false"}&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It now shows that the cert subject CN matches the target hostname, whereas before it returned false. The DNS name match is still false, although I'm not certain if that's required to be true. There's nothing in the documentation that I can find that mentions anything about a DNS name needing to be in the TLS certificate other than the Subject CN.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 23:58:16 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/TLS-connection-error-when-using-Intel-Manageability-Commander/m-p/1506794#M10388</guid>
      <dc:creator>ICIT</dc:creator>
      <dc:date>2023-07-20T23:58:16Z</dc:date>
    </item>
  </channel>
</rss>

