<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AMT Provisioning issue in Intel vPro® Platform</title>
    <link>https://community.intel.com/t5/Intel-vPro-Platform/AMT-Provisioning-issue/m-p/253263#M2732</link>
    <description>&lt;P&gt;That is my understanding, yes. Back when I was at my last company, I had requested a Verisign certificate prior to the changeover to G2 certs, so these days, I typically recommend that people use Godaddy, since they're more consistent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Trevor Sullivan&lt;/P&gt;</description>
    <pubDate>Mon, 07 Dec 2009 20:39:07 GMT</pubDate>
    <dc:creator>idata</dc:creator>
    <dc:date>2009-12-07T20:39:07Z</dc:date>
    <item>
      <title>AMT Provisioning issue</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/AMT-Provisioning-issue/m-p/253260#M2729</link>
      <description>&lt;P&gt;We had tested intel amt provisioning using sccm 2007 sp1 earlier. for the test we used a private certificate for testing. i entered the hash manually int eh client and amt provisioning was working fine. now we purchased the certificate from veresign and installed it in sccm OOB. now i unprovision the client and try to provision it again and on the lientlog (oobmgmt.log) it gives an error " Failed to call checkcertificate provider method,80041001". the certificate that we purchased from veresign has a different root hash than what we have built in in the amt bios of the clients. its like doig it with a private certificate. i installed the proper root, intermediate certificated that i got from veresign but still cannot. juts for testing i manually entered the rooot hash in the client and the client was provisioned. BUT the client log said device provisioned successfully. amt log in the server said provisioning successfull but i was not able to connect to the client using OOB or Power control. if i dont include the certificate hash in the client device manually if fails. i am attaching a log for your info. i am not sure if it is an issue with the veresign certificate or our web server certificate. i verefied in the local CA that a certificate was issued to the client which was provisioned. &lt;/P&gt;</description>
      <pubDate>Sat, 05 Dec 2009 09:25:21 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/AMT-Provisioning-issue/m-p/253260#M2729</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-12-05T09:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: AMT Provisioning issue</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/AMT-Provisioning-issue/m-p/253261#M2730</link>
      <description>&lt;P&gt;I'd suggest starting with this article from Buz Brodin at Microsoft.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://blogs.technet.com/configurationmgr/archive/2009/04/30/configmgr-2007-amt-provisioning-error-hash-list-of-amt-device-doesn-t-contain-our-provision-server-certificate-hash.aspx"&gt;http://blogs.technet.com/configurationmgr/archive/2009/04/30/configmgr-2007-amt-provisioning-error-hash-list-of-amt-device-doesn-t-contain-our-provision-server-certificate-hash.aspx&lt;/A&gt; &lt;A href="http://blogs.technet.com/configurationmgr/archive/2009/04/30/configmgr-2007-amt-provisioning-error-hash-list-of-amt-device-doesn-t-contain-our-provision-server-certificate-hash.aspx"&gt;http://blogs.technet.com/configurationmgr/archive/2009/04/30/configmgr-2007-amt-provisioning-error-hash-list-of-amt-device-doesn-t-contain-our-provision-server-certificate-hash.aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's my understanding that Verisign changed their root CA certificate a few months back. Any certificates obtained after that point in time have a mismatching hash with the ones embedded in the AMT firmware. Terry Cutler talks about this situation in this article:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/community/openportit/vproexpert/activation/blog/2009/05/22/how-does-the-verisign-root-certificate-change-affect-intel-vpro &lt;A href="http://communities.intel.com/community/openportit/vproexpert/activation/blog/2009/05/22/how-does-the-verisign-root-certificate-change-affect-intel-vpro"&gt;http://communities.intel.com/community/openportit/vproexpert/activation/blog/2009/05/22/how-does-the-verisign-root-certificate-change-affect-intel-vpro&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would probably be desirable to update your systems to the latest AMT firmware, in order to ensure that the appropriate hashes are available. I don't know if any OEMs actually followed through with the G2 update or not, but it's worth checking on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Trevor Sullivan&lt;/P&gt;</description>
      <pubDate>Sun, 06 Dec 2009 05:44:15 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/AMT-Provisioning-issue/m-p/253261#M2730</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-12-06T05:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: AMT Provisioning issue</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/AMT-Provisioning-issue/m-p/253262#M2731</link>
      <description>&lt;P&gt;Thanks for your reply. So in my case if i understand correctly i should request Verisign to reissue the certificate wit a root hash of G1 premium which matches the root hashes in the intel vpro machines. i will contact verisign and update accordingly. this might be a common problem and was curios to know ehat other people are doain about this.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2009 08:14:02 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/AMT-Provisioning-issue/m-p/253262#M2731</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-12-07T08:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: AMT Provisioning issue</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/AMT-Provisioning-issue/m-p/253263#M2732</link>
      <description>&lt;P&gt;That is my understanding, yes. Back when I was at my last company, I had requested a Verisign certificate prior to the changeover to G2 certs, so these days, I typically recommend that people use Godaddy, since they're more consistent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Trevor Sullivan&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2009 20:39:07 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/AMT-Provisioning-issue/m-p/253263#M2732</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-12-07T20:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: AMT Provisioning issue</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/AMT-Provisioning-issue/m-p/253264#M2733</link>
      <description>&lt;P&gt;I just noticed that Steve Davies with Intel just recently updated a document on the vPro Expert Center. Please review the last page of this document for information on default certificate hashes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/docs/DOC-2110 &lt;A href="http://communities.intel.com/docs/DOC-2110"&gt;http://communities.intel.com/docs/DOC-2110&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!     &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Trevor Sullivan&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2009 06:36:27 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/AMT-Provisioning-issue/m-p/253264#M2733</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-12-09T06:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: AMT Provisioning issue</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/AMT-Provisioning-issue/m-p/253265#M2734</link>
      <description>&lt;P&gt;WE had to return the server certificate to verisign and request for a new secure site pro certificate which has a root hash maching the hash on the intel vpro machines.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2009 17:17:46 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/AMT-Provisioning-issue/m-p/253265#M2734</guid>
      <dc:creator>idata</dc:creator>
      <dc:date>2009-12-29T17:17:46Z</dc:date>
    </item>
  </channel>
</rss>

