<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Re:Intel AMT Provisioning Certificate with a .local domain in Intel vPro® Platform</title>
    <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1401071#M9241</link>
    <description>&lt;P&gt;Hi Jose,&lt;BR /&gt;&lt;BR /&gt;Thanks for the information.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I'm wondering if you can elaborate on this comment from this thread?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.intel.com/t5/Intel-vPro-Platform/Prevent-DHCP-option-15-check-local-domain/m-p/431258" target="_blank"&gt;https://community.intel.com/t5/Intel-vPro-Platform/Prevent-DHCP-option-15-check-local-domain/m-p/431258&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;"&lt;SPAN&gt;Spoofing of DHCP or additional Reservations only for the process of initial AMT configuration"&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Can you please explain what is happening here?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Jul 2022 04:47:09 GMT</pubDate>
    <dc:creator>S4m</dc:creator>
    <dc:date>2022-07-18T04:47:09Z</dc:date>
    <item>
      <title>Intel AMT Provisioning Certificate with a .local domain</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1397682#M9207</link>
      <description>&lt;P&gt;I have been looking at some old posts and thought to asked if there are any new workarounds for getting a public CA setup for remote configuration -&amp;nbsp; intel AMT admin mode with a .local domain (with a DHCP option 15 that can't be changed.)&lt;BR /&gt;&lt;BR /&gt;I thought to post this question to see if there are any other ways to get around this -&amp;nbsp;&lt;BR /&gt;This is my current setup.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have an EMA machine of "AMTcomputer@thedomain.local"&lt;BR /&gt;DHCP option 15 = thedomain.local&lt;BR /&gt;&lt;BR /&gt;We have another domain as " &lt;A href="mailto:anotherdomain@site.net.au&amp;quot;" target="_blank"&gt;anotherdomain@site.net.au"&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;So the obvious solution here is to change everything to&amp;nbsp;" &lt;A href="mailto:anotherdomain@site.net.au&amp;quot;" target="_blank"&gt;anotherdomain@site.net.au"&lt;/A&gt;&amp;nbsp;including DHCP option 15 so the auto setup PKI could work.&amp;nbsp;&lt;BR /&gt;Unfortunately, this isn't an option.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Any other ways to get an Intel AMT&amp;nbsp;&lt;SPAN&gt;provisioning certificate for internal Domain name?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 02:20:09 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1397682#M9207</guid>
      <dc:creator>S4m</dc:creator>
      <dc:date>2022-07-05T02:20:09Z</dc:date>
    </item>
    <item>
      <title>Re:Intel AMT Provisioning Certificate with a .local domain</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1397717#M9208</link>
      <description>&lt;P&gt;Hello &lt;SPAN style="font-size: 14px;"&gt;S4m&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you for joining the community&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Are you trying to migrate an existing installation without the need to purchase another provisioning cert? You don't need a provisioning cert if your systems are in Client Control Mode&lt;/P&gt;&lt;P&gt;Could you detail a bit more on your current setup?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Jose A.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 05 Jul 2022 06:05:03 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1397717#M9208</guid>
      <dc:creator>JoseH_Intel</dc:creator>
      <dc:date>2022-07-05T06:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Intel AMT Provisioning Certificate with a .local domain</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1397720#M9209</link>
      <description>&lt;P&gt;Hi Jose,&lt;BR /&gt;&lt;BR /&gt;Thanks for the response!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This is a new installation using Windows Authentication + Windows Server 2019. I have my own CA.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I've installed Intel EMA onto a VM "&lt;SPAN&gt;&lt;A href="mailto:AMTcomputer@thedomain.local&amp;quot;" target="_blank"&gt;AMTcomputer@thedomain.local"&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;There is no migration as this is a new setup/prototype.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am looking to get Admin mode to endpoints so I don't have to worry about user consent for advanced OOB functions.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 06:30:48 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1397720#M9209</guid>
      <dc:creator>S4m</dc:creator>
      <dc:date>2022-07-05T06:30:48Z</dc:date>
    </item>
    <item>
      <title>Re:Intel AMT Provisioning Certificate with a .local domain</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1398011#M9211</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN style="font-size: 14px;"&gt;S4m&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;It is certainly possible to use your own certificate but not that convenient as it requires to physically touch every remote system to "inject" your cert hash into the MEBx. The procedure is detailed in section 10.5.3: &lt;A href="https://www.intel.com/content/dam/support/us/en/documents/software/Intel_SCS_User_Guide.pdf#page=222" target="_blank"&gt;https://www.intel.com/content/dam/support/us/en/documents/software/Intel_SCS_User_Guide.pdf#page=222&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Jose A.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 06 Jul 2022 01:01:41 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1398011#M9211</guid>
      <dc:creator>JoseH_Intel</dc:creator>
      <dc:date>2022-07-06T01:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Intel AMT Provisioning Certificate with a .local domain</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1398069#M9213</link>
      <description>&lt;P&gt;Hi Jose,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;With the amount of machines we have -- the overtime alone would be a nightmare!&lt;BR /&gt;&lt;BR /&gt;I would prefer the auto setup.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Any suggestions?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 03:45:17 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1398069#M9213</guid>
      <dc:creator>S4m</dc:creator>
      <dc:date>2022-07-06T03:45:17Z</dc:date>
    </item>
    <item>
      <title>Re:Intel AMT Provisioning Certificate with a .local domain</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1398087#M9214</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN style="font-size: 14px;"&gt;S4m&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The autosetup will require a PKI certificate from 1 out of the 5 already included in the MEBx firmware. GoDaddy, Comodo, Entrust, Sectigo and DigiCert. Probably the amount of time saved will compensate the cost of the commercial certificate.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Jose A.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 06 Jul 2022 05:41:32 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1398087#M9214</guid>
      <dc:creator>JoseH_Intel</dc:creator>
      <dc:date>2022-07-06T05:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Intel AMT Provisioning Certificate with a .local domain</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1398093#M9215</link>
      <description>&lt;P&gt;Thanks Jose,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am aware of the process of getting a public cert - but it is my domain name and DHCP DNS suffix which is causing me some greif.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;As stated in the original post - my domain name has .local it it.&lt;BR /&gt;.local is a TLD that you simply can't get a cert for -- or domain name for that matter.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I wondering if you know any workarounds for this?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Perhaps this thread will help with understanding what I am after.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.intel.com/t5/Intel-vPro-Platform/Prevent-DHCP-option-15-check-local-domain/m-p/431258" target="_blank"&gt;Prevent DHCP option 15 check (.local domain) - Intel Communities&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 05:56:11 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1398093#M9215</guid>
      <dc:creator>S4m</dc:creator>
      <dc:date>2022-07-06T05:56:11Z</dc:date>
    </item>
    <item>
      <title>Re:Intel AMT Provisioning Certificate with a .local domain</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1399254#M9219</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN style="font-size: 14px;"&gt;S4m&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you for the clarification. Let me try to research on this. I will get back to you soon.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Jose A.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 11 Jul 2022 00:52:12 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1399254#M9219</guid>
      <dc:creator>JoseH_Intel</dc:creator>
      <dc:date>2022-07-11T00:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: Intel AMT Provisioning Certificate with a .local domain</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1399821#M9223</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;S4m&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After consulting with our senior team we got the following: The short answer is no. Not if you want to use .local as your domain. You must use a domain that is recognized by AMT for an ACM provisioning cert. This is true even if you set up a self-sign CA server. You want to take a look at:&amp;nbsp;&lt;A href="https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/default.htm?turl=WordDocuments%2Fpkicertificateverificationmethods.htm" target="_blank"&gt;Intel® AMT SDK Implementation and Reference Guide&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jose A.&lt;/P&gt;
&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 01:16:57 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1399821#M9223</guid>
      <dc:creator>JoseH_Intel</dc:creator>
      <dc:date>2022-07-13T01:16:57Z</dc:date>
    </item>
    <item>
      <title>Re:Intel AMT Provisioning Certificate with a .local domain</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1401065#M9239</link>
      <description>&lt;P&gt;Hello&amp;nbsp;S4m&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am just following up to double-check if you found the provided information useful. If you have further questions please don't hesitate to ask. If you consider the issue to be completed please let us know so we can proceed to mark this ticket as resolved. I will try to reach you as a very last time on next Thursday 21th. After that the thread will be automatically archived.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jose A.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 18 Jul 2022 04:23:16 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1401065#M9239</guid>
      <dc:creator>JoseH_Intel</dc:creator>
      <dc:date>2022-07-18T04:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Intel AMT Provisioning Certificate with a .local domain</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1401071#M9241</link>
      <description>&lt;P&gt;Hi Jose,&lt;BR /&gt;&lt;BR /&gt;Thanks for the information.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I'm wondering if you can elaborate on this comment from this thread?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.intel.com/t5/Intel-vPro-Platform/Prevent-DHCP-option-15-check-local-domain/m-p/431258" target="_blank"&gt;https://community.intel.com/t5/Intel-vPro-Platform/Prevent-DHCP-option-15-check-local-domain/m-p/431258&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;"&lt;SPAN&gt;Spoofing of DHCP or additional Reservations only for the process of initial AMT configuration"&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Can you please explain what is happening here?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 04:47:09 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1401071#M9241</guid>
      <dc:creator>S4m</dc:creator>
      <dc:date>2022-07-18T04:47:09Z</dc:date>
    </item>
    <item>
      <title>Re:Intel AMT Provisioning Certificate with a .local domain</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1401084#M9242</link>
      <description>&lt;P&gt;Hello&amp;nbsp;S4m&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well, that particular comment was written by the community user JWint3, which makes it difficult to guess exactly what we meant. What we know is that option 15 is not available on latest versions of AMT, unfortunately.  &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jose A.&lt;/P&gt;&lt;P&gt;Intel Customer Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 18 Jul 2022 05:52:28 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1401084#M9242</guid>
      <dc:creator>JoseH_Intel</dc:creator>
      <dc:date>2022-07-18T05:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Intel AMT Provisioning Certificate with a .local domain</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1402216#M9252</link>
      <description>&lt;P&gt;Hi S4m,&lt;/P&gt;
&lt;P&gt;As Jose described&amp;nbsp; for AMT Admin Control Mode you will have to meet&amp;nbsp; general Intel AMT&amp;nbsp; FW design requirements:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Intel AMT Wired built in LAN&amp;nbsp; +&amp;nbsp; AMT Provisioning certificate issued by one of Intel AMT supported/trusted Public CAs -which for obvious reasons of DV process you can get for your publicly registered domain name&amp;nbsp; + DHCP Option 15 set to value that will match domain name part of AMT provisioning cert&amp;nbsp; CN.&lt;BR /&gt;OR&lt;/LI&gt;
&lt;LI&gt;Add your own self signed CA Root cert hash to AMT FW&amp;nbsp; so you can have cert CN domain name part matching any DHCP Option 15 you want. Note 1 - you still need&amp;nbsp;ntel AMT Wired built in LAN&amp;nbsp; &lt;BR /&gt;OR&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;set PKI DNS Suffix in Intel AMT FW to value of your&amp;nbsp;publicly registered domain name. Once it is set it will make AMT FW to validate AMT Provisioning certificate domain name vs PKI DNS Suffix instead of network interface DHCP Option 15&amp;nbsp; and it will work for BOTH AMT Wired and Wireless networks as well.&lt;BR /&gt;With Intel EMA AMT configuration to ACM will even work over&amp;nbsp; ANY network interface&amp;nbsp; including non Intel AMT docks, USB-LAN dongles etc.&lt;BR /&gt;Note 2 - Intel AMT remote management access still requires Intel AMT enabled LAN, AMT WLAN or AMT LAN in TBT4 dock with Intel 11th Core vPro notebooks or newer (and vPro over TBT4 must be enabled by OEM in Intel ME FW in factory).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;You can add your own CA root cert hash and /or set PKI DNS suffix&amp;nbsp; (you can do both&amp;nbsp; 2. and 3. above in one Pre-setup) via Intel MEBx manual interface or USB Pre-Provisioning which both require physical access and "touch" of each device.&lt;BR /&gt;OEM may do it for you in their factory but only for devices which are still in manufacturing mode and they usually charge approx $5-10 per device.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Fortunately there is pretty easy workaround for invalid internal domain names as long as your DHCP server is based on MS Windows service (or other solution that will support DHCP User classes and DHC Policies).&lt;BR /&gt;&lt;BR /&gt;you need to ask DHCP Admin to:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Create new User Class in DHCP server,&amp;nbsp;Name it ex. &lt;I&gt;AMT&lt;/I&gt; , you may also add description and Define its Class ID – ex. AMT&lt;BR /&gt;(enter Class ID&amp;nbsp; name in ASCII column).&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="New DHCP User Class.png" style="width: 253px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/31822iCF8D37E143C77CE1/image-dimensions/253x378?v=v2&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" width="253" height="378" role="button" title="New DHCP User Class.png" alt="New DHCP User Class.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="New DHCP User Class parameters.png" style="width: 301px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/31823i5D0F047646E9D8A3/image-dimensions/301x353?v=v2&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" width="301" height="353" role="button" title="New DHCP User Class parameters.png" alt="New DHCP User Class parameters.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Define new DHCP Policy, name it ex. &lt;I&gt;AM&lt;/I&gt;&lt;I&gt;T&lt;/I&gt;&lt;I&gt;, &lt;/I&gt;you may also add description,&amp;nbsp;&lt;STRONG&gt;Add &lt;/STRONG&gt;Condition for&amp;nbsp;&lt;STRONG&gt;User Class &lt;/STRONG&gt;= name you defined in New Class (select from the list),&amp;nbsp;&lt;STRONG&gt;Add&lt;/STRONG&gt; it&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="New DHCP Policy.png" style="width: 254px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/31824i4379BA8A9D47B14E/image-size/large?v=v2&amp;amp;px=999&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="New DHCP Policy.png" alt="New DHCP Policy.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="New DHCP Policy name.png" style="width: 278px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/31825i54C8B322D4B62F94/image-dimensions/278x57?v=v2&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" width="278" height="57" role="button" title="New DHCP Policy name.png" alt="New DHCP Policy name.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="New DHCP Policy condition.png" style="width: 339px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/31826iDC089AD75F4CD6E1/image-size/large?v=v2&amp;amp;px=999&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="New DHCP Policy condition.png" alt="New DHCP Policy condition.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;In &lt;STRONG&gt;DHCP Standard Options&lt;/STRONG&gt;&amp;nbsp; for this new Policy scroll down to Option &lt;STRONG&gt;015 DNS Domain Name,&amp;nbsp;&lt;BR /&gt;&lt;/STRONG&gt;Select it and provide your &lt;STRONG&gt;company publicly registered domain name&lt;/STRONG&gt; (ex. your &lt;SPAN&gt;site.net.au&lt;/SPAN&gt;), Review settings and &lt;STRONG&gt;Finish&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="New DHCP Policy Option 15.png" style="width: 354px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/31827iCEF777769E679C10/image-dimensions/354x198?v=v2&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" width="354" height="198" role="button" title="New DHCP Policy Option 15.png" alt="New DHCP Policy Option 15.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/STRONG&gt;New Policy is added to DHCP server&lt;STRONG&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="New DHCP Policy done.png" style="width: 580px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/31828i5F9024B28306EFCA/image-dimensions/580x94?v=v2&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" width="580" height="94" role="button" title="New DHCP Policy done.png" alt="New DHCP Policy done.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;then you have to deploy this new DHCP Policy for Intel AMT configuration time and purpose only:&lt;BR /&gt;in your EMAAgent.exe deployment script include in following order:&lt;BR /&gt;&lt;STRONG&gt;ipconfig /setclassid Ethernet AMT&lt;BR /&gt;&lt;/STRONG&gt;where AMT shall be replaced by class ID you configured in first step. It will request from DHCP server to assign IP address within this&amp;nbsp; New DHCP Policy with public domain name in Option 15.&lt;BR /&gt;&lt;STRONG&gt;&lt;I&gt;EMAAgent.exe –&lt;/I&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;I&gt;fullinstall&lt;/I&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;I&gt;&lt;BR /&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;I&gt;TIMEOUT /T&lt;/I&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;I&gt; 180 &lt;/I&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;I&gt;/&lt;/I&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;I&gt;Nobreak&lt;/I&gt;&lt;/STRONG&gt;&lt;BR /&gt;it will deploy EMAAgent which will register endpoint and start configuring Intel AMT automatically.&lt;BR /&gt;AMT configuration to ACM may take some time to complete so hence T&lt;EM&gt;imeout /T 180 /Nobreak&lt;/EM&gt;&amp;nbsp; command.&lt;BR /&gt;You may adjust time to be longer than those 3 min.&lt;BR /&gt;This is quick and not perfect example of giving Intel EMA time to complete AMT configuration to ACM mode.&lt;BR /&gt;other way is to query&amp;nbsp; AMT&amp;nbsp; configuration status to reach ACM&amp;nbsp; with&amp;nbsp;&lt;STRONG style="color: inherit; font-family: inherit; font-size: 48px;"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;A title="Intel® EMA Configuration Tool" href="https://www.intel.com/content/www/us/en/download/19805/intel-endpoint-management-assistant-configuration-tool-intel-ema-configuration-tool.html" target="_self"&gt;Intel® EMA Configuration Tool&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;on 30-60 sec interval within script.&lt;/FONT&gt;&lt;BR /&gt;and than&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;ipconfig /setclassid Ethernet&lt;/STRONG&gt;&lt;BR /&gt;which will revert back to default DHCP Policy (with your internal .local domain name in ?Option 15).&lt;BR /&gt;&lt;BR /&gt;so your EMA Agent deployment script will look like:&lt;BR /&gt;
&lt;P&gt;&lt;I&gt;ipconfig /setclassid Ethernet &lt;/I&gt;&lt;STRONG&gt;&lt;I&gt;AMT&lt;/I&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;EMAAgent.exe –&lt;/I&gt;&lt;I&gt;fullinstall&lt;/I&gt;&lt;I&gt;&lt;BR /&gt;TIMEOUT /T &lt;/I&gt;&lt;STRONG&gt;&lt;I&gt;180&lt;/I&gt;&lt;/STRONG&gt;&lt;I&gt; /&lt;/I&gt;&lt;I&gt;Nobreak&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;ipconfig /setclassid Ethernet&lt;/I&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kudos to my team peer Josh Copeland for figuring out this "trick" - I am just sharing it &lt;LI-EMOJI id="lia_slightly-smiling-face" title=":slightly_smiling_face:"&gt;&lt;/LI-EMOJI&gt;&lt;BR /&gt;rgds&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mr_vPro_0-1658402515829.png" style="width: 158px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/31829i4A00E7C1F498422A/image-dimensions/158x67?v=v2&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" width="158" height="67" role="button" title="Mr_vPro_0-1658402515829.png" alt="Mr_vPro_0-1658402515829.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Dariusz Wittek&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Biz Client Technical Sales Specialist&amp;nbsp; |&amp;nbsp; Intel EMEA CCG Technical Sales&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 11:27:00 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1402216#M9252</guid>
      <dc:creator>Mr_vPro</dc:creator>
      <dc:date>2022-07-21T11:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Intel AMT Provisioning Certificate with a .local domain</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1402359#M9254</link>
      <description>&lt;P&gt;Hi Mr_vPro,&lt;BR /&gt;&lt;BR /&gt;Thank you (&amp;amp; to Josh) for this detailed post - exactly what I am after.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This looks like it will work for my set up - great info!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Once I start the works I will report the outcome.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 22:55:30 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1402359#M9254</guid>
      <dc:creator>S4m</dc:creator>
      <dc:date>2022-07-21T22:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: Intel AMT Provisioning Certificate with a .local domain</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1404624#M9275</link>
      <description>&lt;P&gt;I'm having a similar problem. Anyone can look at the issue on my post?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.intel.com/t5/Intel-vPro-Platform/AMT-not-provisioning-as-ACM/m-p/1404602" target="_blank"&gt;AMT not provisioning as ACM - Intel Communities&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure why it got blacklisted, i may not be able to post new threads since I'm a new member.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 16:00:15 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-AMT-Provisioning-Certificate-with-a-local-domain/m-p/1404624#M9275</guid>
      <dc:creator>Fernando4</dc:creator>
      <dc:date>2022-07-29T16:00:15Z</dc:date>
    </item>
  </channel>
</rss>

