<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Certificate Error Provisioning All AMT Devices in Intel vPro® Platform</title>
    <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246015#M2473</link>
    <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a brand new Dell Optiplex 755 running BIOS A11 and AMT Firmware 3.2.1. I'm having trouble provisioning it. Everything works up until the certificate request is made from out certificate server, however. I'm getting the below messages in the &lt;B&gt;&lt;I&gt;amtproxymgr.log&lt;/I&gt;&lt;/B&gt; (not &lt;I&gt;amtopmgr.log&lt;/I&gt;) on the ConfigMgr site server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had one of the guys on our server team check out the certificate server, and it is creating multiple certificates for the same client, &lt;B&gt;and&lt;/B&gt; automatically approving them (&lt;I&gt;as is proper&lt;/I&gt;), but for some reason, the site server is rejecting the certificate during the verification of the certificate chain. Our internal root CA certificate is in the Trusted Root CA store on the site server, and I have successfully provisioned other clients before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also verified that this is not the self-signed certificate issue, because I have manually unprovisioned the device in SMB mode, and also pulled the CMOS battery to reset back to factory defaults. The same behavior is persisting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS also is not a problem, as I have verified the forward and reverse records for the client from the site server. DHCP option 15 is also set properly. If either of these were the issue, we wouldn't be getting as far as we are in the provisioning process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Found instruction file: &lt;A&gt;D:\SMS\inboxes\amtproxymgr.box\{50830F19-8E2D-410A-A75B-EC5F0A32F96E}.apx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;Processing Instruction: RCT 1;1;62151;3.2.1;&lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt;;SMS_AMT_OPERATION_MANAGER_PROV;&lt;P&gt;&amp;nbsp;&lt;/P&gt; Request certificate task begin to read Site Control File.&lt;P&gt;&amp;nbsp;&lt;/P&gt; Changes to the site control file settings detected.&lt;P&gt;&amp;nbsp;&lt;/P&gt; Request certificate task success to read parameters from Site Control File.&lt;P&gt;&amp;nbsp;&lt;/P&gt; Request certificate task success to connect to the SQL database.&lt;P&gt;&amp;nbsp;&lt;/P&gt; ERROR: CertCreateCertificateContext failed: 0x80093102, msg=ASN1 unexpected end of data.~&lt;P&gt;&amp;nbsp;&lt;/P&gt; Error: CTaskRequestClientCert::RevokeExistedCertificate failed to get serial number from the certificate binary.&lt;P&gt;&amp;nbsp;&lt;/P&gt; Request certificate task disConnected to the SQL database.&lt;P&gt;&amp;nbsp;&lt;/P&gt; INFO: Enter process request 1&lt;P&gt;&amp;nbsp;&lt;/P&gt;INFO: Save Request&lt;P&gt;&amp;nbsp;&lt;/P&gt; INFO: Add new request&lt;P&gt;&amp;nbsp;&lt;/P&gt;Certificate for &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; has been retrieved.&lt;P&gt;&amp;nbsp;&lt;/P&gt;ERROR: CertGetCertificateChain(...) failed: 0x1000040&lt;P&gt;&amp;nbsp;&lt;/P&gt; ERROR: HandleDisposition failed: the root certificate of the CA is not at the Trust List!&lt;P&gt;&amp;nbsp;&lt;/P&gt; INFO: Enter process request 3&lt;P&gt;&amp;nbsp;&lt;/P&gt; INFO: Delete Request&lt;P&gt;&amp;nbsp;&lt;/P&gt; INFO: Request to delete found&lt;P&gt;&amp;nbsp;&lt;/P&gt; STATMSG: ID=7601 SEV=E LEV=M SOURCE="SMS Server" COMP="SMS_AMT_PROXY_COMPONENT" SYS=PROVSERVER SITE=123 PID=8536 TID=2220 GMTDATE=Thu Jan 08 21:28:22.411 2009 ISTR0="&lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt;" ISTR1="&lt;A href="http://certserver.vprodemo.com"&gt;certserver.vprodemo.com&lt;/A&gt;" ISTR2="" ISTR3="" ISTR4="" ISTR5="" ISTR6="" ISTR7="" ISTR8="" ISTR9="" NUMATTRS=0&lt;P&gt;&amp;nbsp;&lt;/P&gt;Failed to run instruction: RCT 1;1;62151;3.2.1;&lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt;;SMS_AMT_OPERATION_MANAGER_PROV;&lt;P&gt;&amp;nbsp;&lt;/P&gt;Finished Executing Instruction: RCT 1;1;62151;3.2.1;&lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt;;SMS_AMT_OPERATION_MANAGER_PROV; &lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;Thanks,&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Trevor Sullivan&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Systems Engineer&lt;/I&gt;&lt;/P&gt;&lt;P&gt;OfficeMax Corporation&lt;/P&gt;</description>
    <pubDate>Fri, 09 Jan 2009 16:17:42 GMT</pubDate>
    <dc:creator>idata</dc:creator>
    <dc:date>2009-01-09T16:17:42Z</dc:date>
    <item>
      <title>Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246015#M2473</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a brand new Dell Optiplex 755 running BIOS A11 and AMT Firmware 3.2.1. I'm having trouble provisioning it. Everything works up until the certificate request is made from out certificate server, however. I'm getting the below messages in the &lt;B&gt;&lt;I&gt;amtproxymgr.log&lt;/I&gt;&lt;/B&gt; (not &lt;I&gt;amtopmgr.log&lt;/I&gt;) on the ConfigMgr site server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had one of the guys on our server team check out the certificate server, and it is creating multiple certificates for the same client, &lt;B&gt;and&lt;/B&gt; automatically approving them (&lt;I&gt;as is proper&lt;/I&gt;), but for some reason, the site server is rejecting the certificate during the verification of the certificate chain. Our internal root CA certificate is in the Trusted Root CA store on the site server, and I have successfully provisioned other clients before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also verified that this is not the self-signed certificate issue, because I have manually unprovisioned the device in SMB mode, and also pulled the CMOS battery to reset back to factory defaults. The same behavior is persisting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS also is not a problem, as I have verified the forward and reverse records for the client from the site server. DHCP option 15 is also set properly. If either of these were the issue, we wouldn't be getting as far as we are in the provisioning process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Found instruction file: &lt;A&gt;D:\SMS\inboxes\amtproxymgr.box\{50830F19-8E2D-410A-A75B-EC5F0A32F96E}.apx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;Processing Instruction: RCT 1;1;62151;3.2.1;&lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt;;SMS_AMT_OPERATION_MANAGER_PROV;&lt;P&gt;&amp;nbsp;&lt;/P&gt; Request certificate task begin to read Site Control File.&lt;P&gt;&amp;nbsp;&lt;/P&gt; Changes to the site control file settings detected.&lt;P&gt;&amp;nbsp;&lt;/P&gt; Request certificate task success to read parameters from Site Control File.&lt;P&gt;&amp;nbsp;&lt;/P&gt; Request certificate task success to connect to the SQL database.&lt;P&gt;&amp;nbsp;&lt;/P&gt; ERROR: CertCreateCertificateContext failed: 0x80093102, msg=ASN1 unexpected end of data.~&lt;P&gt;&amp;nbsp;&lt;/P&gt; Error: CTaskRequestClientCert::RevokeExistedCertificate failed to get serial number from the certificate binary.&lt;P&gt;&amp;nbsp;&lt;/P&gt; Request certificate task disConnected to the SQL database.&lt;P&gt;&amp;nbsp;&lt;/P&gt; INFO: Enter process request 1&lt;P&gt;&amp;nbsp;&lt;/P&gt;INFO: Save Request&lt;P&gt;&amp;nbsp;&lt;/P&gt; INFO: Add new request&lt;P&gt;&amp;nbsp;&lt;/P&gt;Certificate for &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; has been retrieved.&lt;P&gt;&amp;nbsp;&lt;/P&gt;ERROR: CertGetCertificateChain(...) failed: 0x1000040&lt;P&gt;&amp;nbsp;&lt;/P&gt; ERROR: HandleDisposition failed: the root certificate of the CA is not at the Trust List!&lt;P&gt;&amp;nbsp;&lt;/P&gt; INFO: Enter process request 3&lt;P&gt;&amp;nbsp;&lt;/P&gt; INFO: Delete Request&lt;P&gt;&amp;nbsp;&lt;/P&gt; INFO: Request to delete found&lt;P&gt;&amp;nbsp;&lt;/P&gt; STATMSG: ID=7601 SEV=E LEV=M SOURCE="SMS Server" COMP="SMS_AMT_PROXY_COMPONENT" SYS=PROVSERVER SITE=123 PID=8536 TID=2220 GMTDATE=Thu Jan 08 21:28:22.411 2009 ISTR0="&lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt;" ISTR1="&lt;A href="http://certserver.vprodemo.com"&gt;certserver.vprodemo.com&lt;/A&gt;" ISTR2="" ISTR3="" ISTR4="" ISTR5="" ISTR6="" ISTR7="" ISTR8="" ISTR9="" NUMATTRS=0&lt;P&gt;&amp;nbsp;&lt;/P&gt;Failed to run instruction: RCT 1;1;62151;3.2.1;&lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt;;SMS_AMT_OPERATION_MANAGER_PROV;&lt;P&gt;&amp;nbsp;&lt;/P&gt;Finished Executing Instruction: RCT 1;1;62151;3.2.1;&lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt;;SMS_AMT_OPERATION_MANAGER_PROV; &lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;Thanks,&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Trevor Sullivan&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Systems Engineer&lt;/I&gt;&lt;/P&gt;&lt;P&gt;OfficeMax Corporation&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jan 2009 16:17:42 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246015#M2473</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-01-09T16:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246016#M2474</link>
      <description>&lt;P&gt;I am experiencing this same issue on a &lt;B&gt;HP Compaq dc7900&lt;/B&gt; running &lt;B&gt;AMT 5.0.2&lt;/B&gt;. I'd appreciate some feedback on this problem ... any ideas on where it's failing? The certificate authority apperas to be functioning properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which certificate is not in which trust list? I've verified that my internal root and subordinate CA certificates are in their proper locations on the site server. I've also verified that the proper Verisign root and subordinate CA certificates are in their proper locations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Trevor Sullivan&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Systems Engineer&lt;/I&gt;&lt;/P&gt;&lt;P&gt;OfficeMax Corporation&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2009 15:41:28 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246016#M2474</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-01-12T15:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246017#M2475</link>
      <description>&lt;P&gt;Here is what the amtopmgr.log file is showing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;Provision task begin&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;p&amp;gt;&amp;nbsp;&lt;/P&gt;Provision target is indicated with SMS resource id. (MachineId = 62378 &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt;)&lt;P&gt;&amp;nbsp;&lt;/P&gt;AMT Provision Worker: 1 task(s) are sent to the task pool successfully.~&lt;P&gt;&amp;nbsp;&lt;/P&gt; AMT Provision Worker: Wait 20 seconds...&lt;P&gt;&amp;nbsp;&lt;/P&gt; Found valid basic machine property for machine id = 62378.&lt;P&gt;&amp;nbsp;&lt;/P&gt; Warning: Currently we don't support mutual auth. Change to TLS server auth mode.&lt;P&gt;&amp;nbsp;&lt;/P&gt;The provision mode for device &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; is 1.&lt;P&gt;&amp;nbsp;&lt;/P&gt; Attempting to establish connection with target device using SOAP. &lt;P&gt;&amp;nbsp;&lt;/P&gt; Found matched certificate hash in current memory of provisioning certificate&lt;P&gt;&amp;nbsp;&lt;/P&gt;Create provisionHelper with (Hash: 0CE62E1E26D22E86F2C31BB6D95471C968C9903B)&lt;P&gt;&amp;nbsp;&lt;/P&gt;Set credential on provisionHelper…&lt;P&gt;&amp;nbsp;&lt;/P&gt;Try to use provisioning account to connect target machine vproclient.vprodemo.com...&lt;P&gt;&amp;nbsp;&lt;/P&gt; HTTP digest authentication failed with status = 401.~&lt;P&gt;&amp;nbsp;&lt;/P&gt; Fail to connect and get core version of machine &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; using provisioning account # 0.&lt;P&gt;&amp;nbsp;&lt;/P&gt; Try to use default factory account to connect target machine vproclient.vprodemo.com...&lt;P&gt;&amp;nbsp;&lt;/P&gt; Succeed to connect target machine &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; and core version with 5.0.2 using default factory account.&lt;P&gt;&amp;nbsp;&lt;/P&gt; GeneralInfo.GetProvisioningState finished with HResult = 0x0, status = 0x0, clientError = 0.~&lt;P&gt;&amp;nbsp;&lt;/P&gt; Get device provisioning state is In Provisioning&lt;P&gt;&amp;nbsp;&lt;/P&gt; Passed OTP check on AMT device &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt;.&lt;P&gt;&amp;nbsp;&lt;/P&gt; Machine &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; will be added and published to AD and OU is LDAP://.&lt;P&gt;&amp;nbsp;&lt;/P&gt;Send request to AMT proxy component to add machine &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; to AD.&lt;P&gt;&amp;nbsp;&lt;/P&gt; Successfully created instruction file for AMT proxy task: &lt;A&gt;D:\SMS\inboxes\amtproxymgr.box~&lt;/A&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt; Processing provision on AMT device &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt;…&lt;P&gt;&amp;nbsp;&lt;/P&gt;Send request to AMT proxy component to generate client certificate. (MachineId = 62378)&lt;P&gt;&amp;nbsp;&lt;/P&gt;Successfully created instruction file for AMT proxy task: &lt;A&gt;D:\SMS\inboxes\amtproxymgr.box~&lt;/A&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt; Wait 20 seconds to find client certificate for AMT device &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; being generated again…&lt;P&gt;&amp;nbsp;&lt;/P&gt;Auto-worker Thread Pool: Current size of the thread pool is 1&lt;P&gt;&amp;nbsp;&lt;/P&gt; AMT Provision Worker: Wakes up to process instruction files&lt;P&gt;&amp;nbsp;&lt;/P&gt;AMT Provision Worker: Wait 20 seconds…&lt;P&gt;&amp;nbsp;&lt;/P&gt;RETRY(1) - Validate client certificate for AMT device &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; being generated.&lt;P&gt;&amp;nbsp;&lt;/P&gt;Wait 20 seconds to find client certificate for AMT device &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; being generated again...&lt;P&gt;&amp;nbsp;&lt;/P&gt; AMT Provision Worker: Wakes up to process instruction files&lt;P&gt;&amp;nbsp;&lt;/P&gt; AMT Provision Worker: Wait 20 seconds...&lt;P&gt;&amp;nbsp;&lt;/P&gt; RETRY(2) - Validate client certificate for AMT device &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; being generated.&lt;P&gt;&amp;nbsp;&lt;/P&gt; Wait 20 seconds to find client certificate for AMT device &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; being generated again...&lt;P&gt;&amp;nbsp;&lt;/P&gt; AMT Provision Worker: Wakes up to process instruction files&lt;P&gt;&amp;nbsp;&lt;/P&gt;AMT Provision Worker: Wait 20 seconds…&lt;P&gt;&amp;nbsp;&lt;/P&gt;RETRY(3) - Validate client certificate for AMT device &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; being generated.&lt;P&gt;&amp;nbsp;&lt;/P&gt;Wait 20 seconds to find client certificate for AMT device &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; being generated again…&lt;P&gt;&amp;nbsp;&lt;/P&gt;AMT Provision Worker: Wakes up to process instruction files&lt;P&gt;&amp;nbsp;&lt;/P&gt; AMT Provision Worker: Wait 20 seconds...&lt;P&gt;&amp;nbsp;&lt;/P&gt; RETRY(4) - Validate client certificate for AMT device &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; being generated.&lt;P&gt;&amp;nbsp;&lt;/P&gt;Wait 20 seconds to find client certificate for AMT device &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; being generated again…&lt;P&gt;&amp;nbsp;&lt;/P&gt;AMT Provision Worker: Wakes up to process instruction files&lt;P&gt;&amp;nbsp;&lt;/P&gt;AMT Provision Worker: Wait 20 seconds...&lt;P&gt;&amp;nbsp;&lt;/P&gt; RETRY(5) - Validate client certificate for AMT device &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; being generated.&lt;P&gt;&amp;nbsp;&lt;/P&gt; Error: Missed device certificate. To provision device with TLS server or Mutual authentication mode, device certficate is required. (MachineId = 62378)&lt;P&gt;&amp;nbsp;&lt;/P&gt; Error: Can't finish provision on AMT device &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt; with configuration code (0)!&lt;P&gt;&amp;nbsp;&lt;/P&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;Provision task end&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;/span&amp;gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Trevor Sullivan&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Systems Engineer&lt;/I&gt;&lt;/P&gt;&lt;P&gt;OfficeMax Corporation&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2009 15:56:24 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246017#M2475</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-01-12T15:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246018#M2476</link>
      <description>&lt;P&gt;Another piece of information: I've disabled support for the Intel WS-MAN Translator v1.1 Build 552, which is installed on the same site server. While I'm trying to figure this problem out, I want to reduce the number of variables present.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Trevor Sullivan&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Systems Engineer&lt;/I&gt;&lt;/P&gt;&lt;P&gt;OfficeMax Corporation&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2009 16:05:22 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246018#M2476</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-01-12T16:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246019#M2477</link>
      <description>&lt;P&gt;Have you reviewed the errors\explanations at &lt;A href="http://technet.microsoft.com/en-us/library/cc161803.aspx"&gt;http://technet.microsoft.com/en-us/library/cc161803.aspx&lt;/A&gt;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You mention that the setup\process was working fine previously, yet not now.  Just to validate - no changes made to server\infrastructructure?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the logs - references to "&lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt;" - and the TLS certificates being issued to this FQDN?  Are you working in a production or test environment?  (&lt;A href="http://vprodemo.com"&gt;vprodemo.com&lt;/A&gt; is a test\demonstration environment used by Intel)&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2009 17:53:06 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246019#M2477</guid>
      <dc:creator>Terry_C_Intel</dc:creator>
      <dc:date>2009-01-12T17:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246020#M2478</link>
      <description>&lt;P&gt;Terry,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't recall exactly when the problem started occurring, but I believe that it was before the holidays, and after I had installed the WS-MAN Translator. I don't specifically recall ever getting a successful provision after installing the Translator.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I have reviewed the documentation you referenced. I don't believe it to be any of those issues. My &lt;I&gt;schannel.dll&lt;/I&gt; is the correct version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Trevor Sullivan&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Systems Engineer&lt;/I&gt;&lt;/P&gt;&lt;P&gt;OfficeMax Corporation&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2009 20:03:11 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246020#M2478</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-01-12T20:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246021#M2479</link>
      <description>&lt;P&gt;Is this a test or production environment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the log - specific client noted is &lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt;.  You also noted "I had one of the guys on our server team check out the certificate server, and  it is creating multiple certificates for the same client"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see the 5 retries to obtain the certificate which you state was created.  To clarify - this didn't happen until the Translator was added on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will you run the AMTSCAN tool and provide a summary of the data captured about the client(s) having issues?  Information on the AMTSCAN tool, including link for download, is available at &lt;A href="http://communities.intel.com/docs/DOC-2062"&gt;http://communities.intel.com/docs/DOC-2062&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Were any other systems provisioned with this particular setup, before the issue arose?  Are those client systems responding to subsequent commands?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has the server been restarted before\after the issue started to occur?   Have you tried restarting the services in the following order:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Stop Translator&lt;/LI&gt;&lt;LI&gt;Stop IIS&lt;/LI&gt;&lt;LI&gt;Start IIS&lt;/LI&gt;&lt;LI&gt;Start Translator&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once service restarts completed - any reported errors on service starts?  What about the &lt;I&gt;amtopmgr.log?&lt;/I&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2009 20:26:35 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246021#M2479</guid>
      <dc:creator>Terry_C_Intel</dc:creator>
      <dc:date>2009-01-12T20:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246022#M2480</link>
      <description>&lt;P&gt;Terry,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for the incomplete response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a production Configuration Manager infrastructure. The reason you are seeing &lt;I&gt;&lt;A href="http://vproclient.vprodemo.com"&gt;vproclient.vprodemo.com&lt;/A&gt;&lt;/I&gt;, is because I scrubbed the log files for company-specific information that would be undesirable to disclose.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 5 certificate retries are occurring as a result of the failure to validate the certificate chain in the &lt;I&gt;amtproxymgr.log&lt;/I&gt; file. The same behavior (in &lt;I&gt;amtopmgr.log&lt;/I&gt;) occurs when the CA is configured to &lt;B&gt;not&lt;/B&gt; automatically approve certificate requests. This is not the case however, as I verified with our server team, that the CA &lt;B&gt;is&lt;/B&gt; automatically approving certificate requests. And yes, I don't believe that this behavior started occurring until after the Translator was installed ... I cannot confirm this 100% though, because my ConfigMgr log files have rotated at least several times since then.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do have a system (&lt;I&gt;Dell OptiPlex 755, iAMT 3.2.1, BIOS A11&lt;/I&gt;) that was provisioned by the same site server that I'm currently experiencing the problem with, yes. The system works fine, and I can control it through the Microsoft OOB console, as well as the reference tools included with Intel AMT DTK. Because of this, it is inherent that kerberos authentication is working as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still have two follow-up items:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Let me get back to you with the output from the iAMT executable that you referenced.&lt;/LI&gt;&lt;LI&gt;I will also investigate restarting the IIS service, but as I said above, the Intel WS-MAN Translator integration is disabled from within Configuration Manager.&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Trevor Sullivan&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Systems Engineer&lt;/I&gt;&lt;/P&gt;&lt;P&gt;OfficeMax Corporation&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2009 21:03:02 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246022#M2480</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-01-12T21:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246023#M2481</link>
      <description>&lt;P&gt;Hi Trevor,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ran into a similar issue a while back, although I don't quite remember if it was with an HP dc7800 or a Dell Optiplex 755. I, too, saw the multiple "validate certificate for AMT device" errors and I noticed that the certificates generated for the AMT client were quickly revoked with every RETRY message being logged. I was reusing the client name and when I previously performed a full-unprovision, the AD object was not deleted from the AMT OU container. Shortly after I manually deleted the stale object from AMT OU, provisioning went through successfully. Might be worth to take a look to see if the same object already exists in AMT OU or not.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2009 01:25:01 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246023#M2481</guid>
      <dc:creator>Tony_C_Intel</dc:creator>
      <dc:date>2009-01-13T01:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246024#M2482</link>
      <description>&lt;P&gt;Tony,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the idea. I think my machine is hosed up at the moment, because it completed first-stage provisioning, so I'll have to go reset the CMOS again tomorrow morning, when I get back into the office. Good thinking though!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Trevor Sullivan&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Systems Engineer&lt;/I&gt;&lt;/P&gt;&lt;P&gt;OfficeMax Corporation&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2009 01:38:22 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246024#M2482</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-01-13T01:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246025#M2483</link>
      <description>&lt;P&gt;Trevor,&lt;/P&gt;&lt;P&gt;Remember that a CMOS clear re-surfaces that self-signed cert issue.  Make sure after you CMOS clear the system, you go through one of the methods to clear the self-signed cert problem that exist on AMT FW &amp;lt;3.2.2.  I would clear everything (OU, Certs, etc) and try to re-establish provisioning.  Are you working with only on root CA?  Have you validated that single root CA is in the trusted root store of the local SCCM system?  You might try to remove and re-add as well.  From the logs ou posted, it appears that it can't validate the root CA for the cert being generated.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2009 03:08:18 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246025#M2483</guid>
      <dc:creator>William_Y_Intel</dc:creator>
      <dc:date>2009-01-13T03:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246026#M2484</link>
      <description>&lt;P&gt;Bill,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't realize that resetting the CMOS reset the self-signed certificate issue. I will try that again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a root CA and a subordinate CA internally. As I stated earlier, I verified that the root and subordinate CA certificates are in their respective containers in the computer's certificate store. I could delete them and re-add them I suppose, but the certificates both show as valid (no red X), if I open them up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree that it looks like it can't validate the root CA, but I just have a hard time understanding why, considering the root CA certificate doesn't expire for a few years at least ... 2012 I think. I don't know why it would suddenly just stop working. Could the certificate configuration in the translator have impacted those somehow? I suppose I could peruse through the source code .... but I really don't feel like it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Trevor Sullivan&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Systems Engineer&lt;/I&gt;&lt;/P&gt;&lt;P&gt;OfficeMax Corporation&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2009 03:33:38 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246026#M2484</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-01-13T03:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246027#M2485</link>
      <description>&lt;P&gt;Ah, that is another piece of the puzzle.  If you have a root and subordinate CA, there is a known issue in SCCM that has trouble validating the chain (subordinate in the intermediate store and the Root CA in the Trusted Root Store).  The work-around for this issue is to load both the Root CA and the Subordinate CA into the trusted root store (local computer store).  For some reason, SCCM does not look into the intermediate store as it should.  We have reported this issue to Microsoft.  Give that a try (after manually fixing the self signed certificate) and see if provisioning will succeed.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2009 03:41:58 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246027#M2485</guid>
      <dc:creator>William_Y_Intel</dc:creator>
      <dc:date>2009-01-13T03:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246028#M2486</link>
      <description>&lt;P&gt;Actually, I'm pretty sure the subordinate CA certificate is already in the computer's Trusted Root CA store, but I will definitely verify that. I did actually run into that issue (in another thread) when trying to use a Windows Vista or Windows 7 system to establish a Serial-over-LAN session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll post back with more information tomorrow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Trevor Sullivan&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Systems Engineer&lt;/I&gt;&lt;/P&gt;&lt;P&gt;OfficeMax Corporation&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2009 05:46:12 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246028#M2486</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-01-13T05:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246029#M2487</link>
      <description>&lt;P&gt;I'm having this issue across the board. I'm working with two separate AMT 5.0.x systems, and they are both failing to provision with these same error messages. I re-imported the subordinate and the root CA certificates, and it is still failing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The certificate chain can't be validated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Trevor Sullivan&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Systems Engineer&lt;/I&gt;&lt;/P&gt;&lt;P&gt;OfficeMax Corporation&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2009 19:17:22 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246029#M2487</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-01-13T19:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246030#M2488</link>
      <description>&lt;P&gt;We're getting an error on our subordinate certificate authority logged very frequently (probably for each provisioning attempt).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;The "Windows default" Exit Module "Notify" method returned an error. The requested property value is empty. The returned status code is 0x80094004 (-2146877436). The Certification Authority was unable to send an email notification for EXITEVENT_CERTISSUED to ???.&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Trevor Sullivan&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Systems Engineer&lt;/I&gt;&lt;/P&gt;&lt;P&gt;OfficeMax Corporation&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2009 19:37:43 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246030#M2488</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-01-13T19:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246031#M2489</link>
      <description>&lt;P&gt;I just found a thread over on the Microsoft Technet forums from October 2008 by some guy named Matt Royer  It sounds like he knows what he's talking about.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://social.technet.microsoft.com/Forums/en-US/configmgrgeneral/thread/91580f69-2007-4070-bf89-99c4d7d120ef/"&gt;http://social.technet.microsoft.com/Forums/en-US/configmgrgeneral/thread/91580f69-2007-4070-bf89-99c4d7d120ef/&lt;/A&gt; &lt;A href="http://social.technet.microsoft.com/Forums/en-US/configmgrgeneral/thread/91580f69-2007-4070-bf89-99c4d7d120ef/"&gt;http://social.technet.microsoft.com/Forums/en-US/configmgrgeneral/thread/91580f69-2007-4070-bf89-99c4d7d120ef/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt, could you possibly expand on what your issue was back then? What exactly did you mean by an "expired CRL"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The errors that you and I have experienced are slightly different, but it appears that there may be an issue related to our subordinate CA configuration somehow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Trevor Sullivan&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Systems Engineer&lt;/I&gt;&lt;/P&gt;&lt;P&gt;OfficeMax Corporation&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2009 20:01:40 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246031#M2489</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-01-13T20:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246032#M2490</link>
      <description>&lt;P&gt;For this issues...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error: CTaskRequestClientCert::RevokeExistedCertificate failed to get serial number from the certificate binary. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;... the CRL or &lt;A href="http://en.wikipedia.org/wiki/Certificate_revocation_list"&gt;http://en.wikipedia.org/wiki/Certificate_revocation_list&lt;/A&gt; Certificate Revocation List was expired on the Subordinate/Issuing CA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would take a look at the following TechNet Articles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc782162.aspx"&gt;http://technet.microsoft.com/en-us/library/cc782162.aspx&lt;/A&gt; Revoking certificates and publishing CRLs&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc740209.aspx"&gt;http://technet.microsoft.com/en-us/library/cc740209.aspx&lt;/A&gt; Renewing a certification authority&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Matt Royer&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2009 00:38:37 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246032#M2490</guid>
      <dc:creator>Matthew_R_Intel</dc:creator>
      <dc:date>2009-01-14T00:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246033#M2491</link>
      <description>&lt;P&gt;Matt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I actually had the server team check this out, and our CRL isn't expired (still not sure what that means).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I opened a ticket with Microsoft earlier today on this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Trevor Sullivan&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Systems Engineer&lt;/I&gt;&lt;/P&gt;&lt;P&gt;OfficeMax Corporation&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2009 05:26:35 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246033#M2491</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-01-14T05:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Error Provisioning All AMT Devices</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246034#M2492</link>
      <description>&lt;P&gt;FYI, this is still an issue. I could use some recommendations ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Trevor Sullivan&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Systems Engineer&lt;/I&gt;&lt;/P&gt;&lt;P&gt;OfficeMax Corporation&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2009 22:00:14 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Certificate-Error-Provisioning-All-AMT-Devices/m-p/246034#M2492</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-02-02T22:00:14Z</dc:date>
    </item>
  </channel>
</rss>

