<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA in Intel vPro® Platform</title>
    <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1659977#M12612</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Vijay,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for your reply.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I attempted the troubleshooting steps in the article provided on &lt;EM&gt;"&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;Steps to resolve Intel® EMA v1.7 Certificate Chaining Issue"&lt;/EM&gt;, but this did not resolve our issue.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Within SQL Server Management Studio, after accessing EMADatabase and navigating to the &lt;EM&gt;Security.Certificates_GetCertificatesByTenantId&lt;/EM&gt; procedure, the &lt;EM&gt;ORDER BY [CertificateId]&lt;/EM&gt; line is already included within the syntax. I tried to execute the procedure, but am still receiving the same error within the &lt;EM&gt;ManageabilitySever&lt;/EM&gt; log, and provisioning will not succeed.&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="none"&gt;2025-01-23 15:23:29.5536|INFO||3112|8|AttemptPhase1_Pki - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.14.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Attempting phase 1 PKI provisioning : (SERVER,71814D91). 
2025-01-23 15:23:29.5536|INFO||3112|8|PerformPkiSetup - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.14.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Get Mesh information (Tenant) : (SERVER,71814D91). 
2025-01-23 15:23:29.5692|INFO||3112|8|PerformPkiSetup - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.14.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Message:Starting PKI Setup process for endpoint: (SERVER,71814D91) ComputerName: SERVER 
2025-01-23 15:23:29.7410|ERROR||3112|8|PerformPkiSetup - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.14.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Error:Unable to get activation certificate chain from the database : (SERVER,71814D91). &lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;We are using the IP Address configuration method, so a DNS record should not be needed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anything else we can try to resolve this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;-RickyB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jan 2025 20:39:08 GMT</pubDate>
    <dc:creator>RickyB</dc:creator>
    <dc:date>2025-01-23T20:39:08Z</dc:date>
    <item>
      <title>Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1659616#M12609</link>
      <description>&lt;P&gt;Hello Intel Community,&lt;/P&gt;&lt;P&gt;I'm having some trouble getting Admin Control Mode fully provisioned on an endpoint I have established through Intel EMA.&lt;/P&gt;&lt;P&gt;We've purchased a Deluxe SSL OV Certificate through GoDaddy and follow the steps from the "How To Purchase and Install GoDaddy* Certificates for Intel AMT Remote Setup and Configuration" document, and uploaded the certificate to Intel EMA. The certificate was created under the FQDN &lt;STRONG&gt;ema-server.drbsystems.com&lt;/STRONG&gt;. Intel EMA seems to recognize the certificate as a valid vPro cert, but issues are still occurring when trying to provision.&lt;/P&gt;&lt;P&gt;I'm able to provision the endpoint in Client Control Mode using Host-Based Provisioning without issues, but if I try to include the certificate for Certificate Provisioning (TLS-PKI), I receive the following error in the&amp;nbsp;EMALog-ManageabilityServer logs (log file attached):&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Error: Unable to get activation certificate chain from the database&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Additionally, I added the PKI DNS Suffix (of &lt;STRONG&gt;drbsystems.com&lt;/STRONG&gt;, and even tried &lt;STRONG&gt;ema-server.drbsystems.com&lt;/STRONG&gt;) onto the endpoint's MEBx - PKI DNS Suffix settings, but the unit still will not provision properly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd also like to add that we installed Intel EMA on our server using the Identity mode of "Use IP Address". This is the only way we can get the endpoint to be detected by the EMA server, and properly provision for CCM. When we try using "FQDN only" or "FQDN first", the Intel EMA will not detect the endpoint and it will not populate on our list of Endpoints on the EMA web-portal.&lt;/P&gt;&lt;P&gt;I'm not sure what I might be missing at this point. Any help would be greatly appreciated!&lt;/P&gt;&lt;P&gt;Please let me know if you need any additional information on our EMA configuration/setup.&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;-Ricky B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 21:57:08 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1659616#M12609</guid>
      <dc:creator>RickyB</dc:creator>
      <dc:date>2025-01-22T21:57:08Z</dc:date>
    </item>
    <item>
      <title>Re:Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1659691#M12611</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Hello RickyB,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Greetings!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Please find the guidance below for addressing the reported issues:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Error: Unable to Get Activation Certificate Chain from the Database&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt; We recommend following the steps outlined in the article:&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt; &lt;/SPAN&gt;&lt;STRONG style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Intel® Endpoint Management Assistant (Intel® EMA) Certificate Chaining Issue&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt; &lt;/SPAN&gt;&lt;A href="https://www.intel.com/content/www/us/en/support/articles/000090529/software/manageability-products.html" rel="noopener noreferrer" target="_blank" style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Intel Support Article&lt;/A&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;This resource should assist in troubleshooting and resolving certificate chaining problems effectively.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Hostname/FQDN or IP Address Configuration During Installation&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt; During the installation process, ensure the following:&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Specify a resolvable value (hostname or IP address) for communication among components.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;If using a hostname or FQDN, ensure it is resolvable by a DNS server in your network.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;In the absence of a DNS server, use a fixed IP address.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Important Notes:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Incorrect hostname or IP configuration will cause Intel® EMA features to malfunction.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;In distributed server architectures, if Active Directory is in use, ensure all related computers (including load balancers) are listed in Active Directory.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Usage of FQDN/IP Addresses in EMA:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Swarm Server Load Balancer FQDN/IP Address:&lt;/STRONG&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt; Used in the agent configuration file for endpoint agents, Intel AMT, or Intel® Standard Manageability.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Ajax &amp;amp; Web Server Load Balancer FQDN/IP Address:&lt;/STRONG&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt; Supports the primary Intel® EMA website HTTPS URL.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Recovery Server Load Balancer FQDN/IP Address:&lt;/STRONG&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt; Facilitates One Click Recovery.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Critical Reminder:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;These settings &lt;/SPAN&gt;&lt;STRONG style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;cannot&lt;/STRONG&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt; be changed post-installation.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Ensure proper DNS resolution and consider using a dynamic DNS entry for flexibility when reconfiguring servers.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Let us know if further assistance is required.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Vijay N.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Intel Customer Support.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 23 Jan 2025 01:06:29 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1659691#M12611</guid>
      <dc:creator>vij1</dc:creator>
      <dc:date>2025-01-23T01:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1659977#M12612</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Vijay,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for your reply.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I attempted the troubleshooting steps in the article provided on &lt;EM&gt;"&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;Steps to resolve Intel® EMA v1.7 Certificate Chaining Issue"&lt;/EM&gt;, but this did not resolve our issue.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Within SQL Server Management Studio, after accessing EMADatabase and navigating to the &lt;EM&gt;Security.Certificates_GetCertificatesByTenantId&lt;/EM&gt; procedure, the &lt;EM&gt;ORDER BY [CertificateId]&lt;/EM&gt; line is already included within the syntax. I tried to execute the procedure, but am still receiving the same error within the &lt;EM&gt;ManageabilitySever&lt;/EM&gt; log, and provisioning will not succeed.&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="none"&gt;2025-01-23 15:23:29.5536|INFO||3112|8|AttemptPhase1_Pki - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.14.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Attempting phase 1 PKI provisioning : (SERVER,71814D91). 
2025-01-23 15:23:29.5536|INFO||3112|8|PerformPkiSetup - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.14.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Get Mesh information (Tenant) : (SERVER,71814D91). 
2025-01-23 15:23:29.5692|INFO||3112|8|PerformPkiSetup - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.14.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Message:Starting PKI Setup process for endpoint: (SERVER,71814D91) ComputerName: SERVER 
2025-01-23 15:23:29.7410|ERROR||3112|8|PerformPkiSetup - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.14.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Error:Unable to get activation certificate chain from the database : (SERVER,71814D91). &lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;We are using the IP Address configuration method, so a DNS record should not be needed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anything else we can try to resolve this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;-RickyB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 20:39:08 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1659977#M12612</guid>
      <dc:creator>RickyB</dc:creator>
      <dc:date>2025-01-23T20:39:08Z</dc:date>
    </item>
    <item>
      <title>Re:Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1660031#M12613</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Hello Ricky B,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Greetings!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Thank you for your response. Upon reviewing your previous post, we noticed that the certificate was created under the FQDN ema-server.drbsystems.com.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;We kindly request you to contact your certificate vendor and have the certificate re-issued under the domain name drbsystems.com instead of the FQDN.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Once you receive the updated certificate:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Reinstall the new certificate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Share the output or any findings with us for further review.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Vijay N&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Intel vPro Support Team.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 23 Jan 2025 23:42:02 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1660031#M12613</guid>
      <dc:creator>vij1</dc:creator>
      <dc:date>2025-01-23T23:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1660261#M12615</link>
      <description>&lt;P&gt;Hi Vijay,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll contact my internal teams to see if this can be done, but perhaps I'm confused. All of Intel's instructional documentation states that we can use our full Common name/FQDN, which in this case is &lt;EM&gt;ema-server.drbsystems.com.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This documentation would be:&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;How to Purchase and Install GoDaddy* Certificates for Intel AMT Remote Setup and Configuration&lt;/EM&gt;&lt;/STRONG&gt;. They are using scs.vprodemo.com as their Common name/FQDN in the examples provided. Is there a reason for this discrepancy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm wondering why we need to use the root domain of &lt;EM&gt;drbsystems.com&lt;/EM&gt;, instead of the full FQDN used to configure the Intel EMA portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;-RickyB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2025 15:29:46 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1660261#M12615</guid>
      <dc:creator>RickyB</dc:creator>
      <dc:date>2025-01-24T15:29:46Z</dc:date>
    </item>
    <item>
      <title>Re:Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1660356#M12617</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Hello RickyB,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Greetings!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Thank you for your response.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Please allow me some time to check this internally with my resources. I will get back to you as soon as I have an update.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Vijay N&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Intel vPro Support Team.&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Sat, 25 Jan 2025 01:02:54 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1660356#M12617</guid>
      <dc:creator>vij1</dc:creator>
      <dc:date>2025-01-25T01:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1660947#M12623</link>
      <description>&lt;P&gt;Hi Vijay,&lt;/P&gt;&lt;P&gt;Were you able to find anything regarding this yet from your internal resources?&lt;/P&gt;&lt;P&gt;I checked with our internal teams, and unfortunately we will not be able to update our GoDaddy certificate to reflect only the root domain (drbsystems.com).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise when you have any additional information regarding how we can resolve this issue.&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;-RickyB&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 18:39:31 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1660947#M12623</guid>
      <dc:creator>RickyB</dc:creator>
      <dc:date>2025-01-27T18:39:31Z</dc:date>
    </item>
    <item>
      <title>Re:Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661027#M12626</link>
      <description>&lt;P&gt;Hello RickyB,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Greetings!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;We would like to clarify that the article "How to Purchase and Install GoDaddy Certificates for Intel AMT Remote Setup and Configuration"* refers to the previous tool, Intel® SCS, and is not up-to-date with the requirements for Intel® Endpoint Management Assistant (Intel® EMA).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;For Intel® EMA, the certificate must be created under a public domain name (domain only, not an FQDN).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;We apologize for any misunderstanding caused by this reference. Please ensure the certificate aligns with this updated requirement.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;If you need further assistance or clarification, feel free to reach out.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Vijay N.&lt;/P&gt;&lt;P&gt;Intel Customer Support.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 28 Jan 2025 00:49:40 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661027#M12626</guid>
      <dc:creator>vij1</dc:creator>
      <dc:date>2025-01-28T00:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661194#M12629</link>
      <description>&lt;P&gt;Hi Ricky,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In fact, you can use a provisioning certificate containing the FQDN of the server requesting the certificate in the CN field. The document referencing how to purchase a certificate from GoDaddy is still valid for Intel EMA. AMT only checks up to level 2 and level 3 of the domain suffix of the FQDN. You can reference the technical details &lt;A href="https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/default.htm?turl=WordDocuments%2Fpkicertificateverificationmethods.htm" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Given the error messages in the log, your Intel EMA server may be missing the intermediate cert and root cert in the certification path of your provisioning certificate. You can check this under Certificates in the Intel EMA web console. If you are only seeing the provisioning certificate but not the intermediate and root certificates. You are missing those. You can fix it by trying one of the methods below:&lt;/P&gt;&lt;P&gt;1) Re-export your provisioning certificate again to a new file and make sure to include the full certification chain and the private key. Remove the old certificate from the Intel EMA web console and upload the new certificate file.&lt;/P&gt;&lt;P&gt;2) Follow the certificate path of your provisioning certificate, and download the intermediate and root certificates from the CA. Import those to the Intel EMA server via the web console.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jimmy Wai&lt;/P&gt;&lt;P&gt;Technical Sales Specialist, Intel&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 10:47:11 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661194#M12629</guid>
      <dc:creator>Jimmy_Wai_Intel</dc:creator>
      <dc:date>2025-01-28T10:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661326#M12633</link>
      <description>&lt;P&gt;&lt;a href="https://community.intel.com/t5/user/viewprofilepage/user-id/298368"&gt;@vij1&lt;/a&gt; – Unfortunately, we are not able to adjust this with our CA, due to internal complications we may face with already existing certificates associated to our root domain.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.intel.com/t5/user/viewprofilepage/user-id/5449"&gt;@Jimmy_Wai_Intel&lt;/a&gt; – Thank you for your reply. Can you provide some clarity on which certificate would be considered the Provisioning Cert? We were only provided with 3 files from GoDaddy for our Deluxe OV Certificate. (.crt, .pem and .p7b files). Which would be considered the Provisioning Cert? The only files types supported by the EMA web interface are .pfx &amp;amp; .cer.&lt;/P&gt;&lt;P&gt;Also, I’ve attached screenshots of the certificates installed on our test environment (EMA Server). What I believe to be the Provision Certificate is highlighted in the MMC capture. I’m showing the root certificate as the “Go Daddy Root Certificate Authority – G2”, but I am not seeing anything listed as the Intermediate cert.&lt;/P&gt;&lt;P&gt;Is there any documentation that Intel provides that can help to give better clarity on setting up the PKI certificate for Admin Control Mode? All documentation I’m finding is either outdated, or not directly referring to the current version of Intel EMA (SCS).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 22:05:17 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661326#M12633</guid>
      <dc:creator>RickyB</dc:creator>
      <dc:date>2025-01-28T22:05:17Z</dc:date>
    </item>
    <item>
      <title>Re:Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661380#M12637</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Hello RickyB,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Greetings!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Thank you for your response.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Could you please share the details from the Enhanced Key Usage section of the certificate? Kindly provide a screenshot for our review.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Looking forward to your response.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Vijay N.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Intel Customer Support.&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 29 Jan 2025 01:06:45 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661380#M12637</guid>
      <dc:creator>vij1</dc:creator>
      <dc:date>2025-01-29T01:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661504#M12640</link>
      <description>&lt;P&gt;Hi Ricky,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After you have got the 3 files from GoDaddy, you still need to complete the certificate request and export the final certificate to a file. This is your provisioning certificate. The steps are in section 4 of the&amp;nbsp;&lt;SPAN&gt;How To Purchase and Install GoDaddy* Certificates for Intel AMT Remote Setup and Configuration document. Although not shown in the document, if you are presented with the options to include the private key and the certificates in certificate chain/path in the exported file, please be sure to include those.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Once you have completed the certificate, you should also check if the certificate was issued with the correct property for AMT provisioning. You can find the completed certificate in the certificate store of the local machine. Just like Vijay said, check the Enhanced Key Usage properties of the certificate and look for AMT Provisioning (2.16.840.1.113741.1.2.3). If don't see this, you need to work with GoDaddy to have the certificate reissued with the right properties.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Once the certificate is confirmed to be good, remove the existing certificate in the EMA server console and upload the newly exported certificate file. Now, you should be able to choose certificate provisioning and pick the new certificate in AMT autosetup.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jimmy_Wai_Intel_2-1738146094347.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/62296iB1D249C08F29ACAB/image-size/medium?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="Jimmy_Wai_Intel_2-1738146094347.png" alt="Jimmy_Wai_Intel_2-1738146094347.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 10:22:43 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661504#M12640</guid>
      <dc:creator>Jimmy_Wai_Intel</dc:creator>
      <dc:date>2025-01-29T10:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661575#M12641</link>
      <description>&lt;P&gt;&lt;a href="https://community.intel.com/t5/user/viewprofilepage/user-id/298368"&gt;@vij1&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.intel.com/t5/user/viewprofilepage/user-id/5449"&gt;@Jimmy_Wai_Intel&lt;/a&gt;&amp;nbsp; - The key that we are using currently already includes that value within the Enhanced Key Usage. Server &amp;amp; Client Authentication also shows the same values. The only difference is my certificate shows the label as Unknown Key Usage, while yours states AMT Provisioning, but the OID value is exactly the same. See screenshot below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RickyB_0-1738160885803.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/62302iB248C24C1AF1F02D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="RickyB_0-1738160885803.png" alt="RickyB_0-1738160885803.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I deleted this existing certificate and went through the "Complete Certificate Request..." process again, but IIS Manager does not give an option to include the Private Key. Only asked for the .crt certificate file, Friendly Name, and to select a certificate store (Personal).&lt;/P&gt;&lt;UL class="lia-list-style-type-circle"&gt;&lt;LI&gt;Once this was done, the "Enhanced Key Usage" still shows the same values and OID has not changed (showing correctly as 2.16.840.1.113741.1.2.3, but with the Unknown Key Usage label, instead of AMT Provisioning).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;After attempting another export, I then installed the PFX Certificate again onto the EMA Server (under Current User - Personal Certificate Store). I then uploading the .pfx certificate file to the EMA web interface, I attempted to provision the endpoint again.&lt;/P&gt;&lt;P&gt;Here are the steps I followed:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;1st - I configured my AMT profile for HBP (Host Based Provisioning) for CCM (Client Control Mode) to verify that the connections were still working as they should.&amp;nbsp;&lt;UL class="lia-list-style-type-circle"&gt;&lt;LI&gt;Everything worked fine after setting this up for CCM. Was able to connect without issues, but only in CCM.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;2nd - I then un-provisioned the endpoint, and attempted to re-provision with the updated AMT Profile set to PKI Provisioning for ACM (Admin Control Mode).&lt;UL class="lia-list-style-type-circle"&gt;&lt;LI&gt;While doing this I also updated the installed Agent services to reflect the updated AMT Profile changed to PKI Provisioning.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;3rd - After updating the AMT Profile and Agent services on the endpoint and attempted re-provisioning for ACM, I received the same errors as before within the EMALog-ManageabilityServer logs, and ACM provisioning was not successful.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="none"&gt;2025-01-29 10:08:23.9357|INFO||3112|8|AttemptPhase1_Pki - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.14.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Attempting phase 1 PKI provisioning : (SERVER,71814D91). 
2025-01-29 10:08:23.9357|INFO||3112|8|PerformPkiSetup - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.14.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Get Mesh information (Tenant) : (SERVER,71814D91). 
2025-01-29 10:08:23.9523|INFO||3112|8|PerformPkiSetup - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.14.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Message:Starting PKI Setup process for endpoint: (SERVER,71814D91) ComputerName: SERVER 
2025-01-29 10:08:24.1190|ERROR||3112|8|PerformPkiSetup - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.14.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Error:Unable to get activation certificate chain from the database : (SERVER,71814D91). 
2025-01-29 10:08:24.1190|WARN||3112|8|AttemptPhase1 - MeshManageabilityServer.CentralManageabilityServer, EMAManageabilityServer, Version=1.14.1.0, Culture=neutral, PublicKeyToken=57d11e903ea1ca2c - [1] - Failed PKI provisioning : (SERVER,71814D91). &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure what else to do at this point. The only other options I can think of would be to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Either uninstall all Intel EMA components from the EMA Server &amp;amp; endpoint, delete all of the certificates from MMC, re-install Intel EMA Server components, install the needed certificates (GoDaddy Deluxe OV, Intermediate, , and try the process again for Admin Control Mode.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Or completely re-image the EMA Server (fresh OS image), re-install SQL Server Express, re-install EMA Server components, re-install certificates needed, and try the ACM Provisioning again.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any other guidance on this will be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;-RickyB&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 15:40:12 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661575#M12641</guid>
      <dc:creator>RickyB</dc:creator>
      <dc:date>2025-01-29T15:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661592#M12642</link>
      <description>&lt;P&gt;Hi Ricky,&lt;/P&gt;&lt;P&gt;It is OK to see Unknown Key Usage in the certificate properties as long as OID&amp;nbsp;&lt;SPAN&gt;2.16.840.1.113741.1.2.3 is there. I would not suggest to re-install the server as this is definitely a certificate issue. The error is reproduceable if you do not have everything correct in the provisioning certificate file uploaded to the Intel EMA server - OID, private key, intermediate and root certs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Could you try the following to export the provisioning certificate on the server?&lt;/P&gt;&lt;P&gt;1) Open MMC and add the certificate snap in for computer account&lt;/P&gt;&lt;P&gt;2) Check all the certs in the certificate path of your provisioning certificate are not missing in the intermediate and root certificate stores. If any is missing, find it from GoDaddy website, download and import it.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jimmy_Wai_Intel_1-1738169874912.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/62316iA097ACCB377608AA/image-size/medium?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="Jimmy_Wai_Intel_1-1738169874912.png" alt="Jimmy_Wai_Intel_1-1738169874912.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Locate the provisioning certificate your completed in the personal certificate store&lt;/P&gt;&lt;P&gt;3) Right click on the certificate, choose All Tasks, and then Export&lt;/P&gt;&lt;P&gt;4) Choose to include private key. If you don't have the option, it means either your user account do not have access right, or the key is marked not exportable in the certificate. You need to resolve this.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jimmy_Wai_Intel_0-1738169516571.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/62315iFD83E437B9A9A7BD/image-size/medium?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="Jimmy_Wai_Intel_0-1738169516571.png" alt="Jimmy_Wai_Intel_0-1738169516571.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;5) Choose to include all certificates in the certification path&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jimmy_Wai_Intel_2-1738169926132.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/62317iBA43A87F10B02ABA/image-size/medium?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="Jimmy_Wai_Intel_2-1738169926132.png" alt="Jimmy_Wai_Intel_2-1738169926132.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;6) Provide a password to protect the private key, and complete the export process. If you missed to include the private key, you won't be asked for a password.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jimmy_Wai_Intel_4-1738170601845.png" style="width: 400px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/62320i732146616E8D00E1/image-size/medium?v=v2&amp;amp;px=400&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="Jimmy_Wai_Intel_4-1738170601845.png" alt="Jimmy_Wai_Intel_4-1738170601845.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once you completed the export, repeat the process as before - remove the pervious certificate from the EMA web console, import the newly exported certificate file, update your AMT autosetup settings, and then try provision your client again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 17:11:37 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661592#M12642</guid>
      <dc:creator>Jimmy_Wai_Intel</dc:creator>
      <dc:date>2025-01-29T17:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661610#M12643</link>
      <description>&lt;P&gt;&lt;a href="https://community.intel.com/t5/user/viewprofilepage/user-id/5449"&gt;@Jimmy_Wai_Intel&lt;/a&gt;&amp;nbsp; - That worked! Exporting the certificate the way you mentioned, w/ the Private Key included allowed me to properly provision the Endpoint into ACM!&lt;/P&gt;&lt;P&gt;Thank you so much for all your help! I've been trying to figure this out for months! You're a lifesaver!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 17:59:50 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661610#M12643</guid>
      <dc:creator>RickyB</dc:creator>
      <dc:date>2025-01-29T17:59:50Z</dc:date>
    </item>
    <item>
      <title>Re:Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661635#M12644</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Hello RickyB,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Greetings!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Thank you for your response. Since you have confirmed that the issue is resolved, we will proceed with closing this thread.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Please don’t hesitate to reach out if you need any further assistance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Thank you for using Intel products and services.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Vijay N.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Intel Customer Support.&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 29 Jan 2025 21:45:15 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661635#M12644</guid>
      <dc:creator>vij1</dc:creator>
      <dc:date>2025-01-29T21:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Getting Endpoint to Provision for Admin Control Mode - Intel EMA</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661789#M12646</link>
      <description>&lt;P&gt;My pleasure! I'm glad it is now working for you.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 08:40:34 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Issues-Getting-Endpoint-to-Provision-for-Admin-Control-Mode/m-p/1661789#M12646</guid>
      <dc:creator>Jimmy_Wai_Intel</dc:creator>
      <dc:date>2025-01-30T08:40:34Z</dc:date>
    </item>
  </channel>
</rss>

