Intel vPro® Platform
Intel Manageability Forum (Intel® EMA, AMT & Manageability Commander)
Announcements
The Intel sign-in experience has changed to support enhanced security controls. If you sign in, click here for more information.
2678 Discussions

EMA PKI certificate

Testing123
Novice
2,089 Views

Hello all,

This is my first server setup so I'm learning as I go. I received a certificate from my sys admin and a CA bundle, both of which I've imported successfully. When I login to the EMA webpage, its states its secure.

I've imported those certificates on the Settings page on my EMA site.

However, I don't have the option of PKI provisioning with my endpoints. Do I need a separate certificate for provisioning the endpoints?

Thank you for your help in advance. 

0 Kudos
1 Solution
IntelSupport
Community Manager
2,071 Views

Hello Testing123,


The option to PKI provision endpoints in Intel® EMA can be accessed by:


1. Login as a Tenant Admin

2. Endpoint Groups

3. Click on the “3-dot ellipses” to the right of the endpoint group to manage

4. Select View Configuration

5. Click on Intel AMT Auto setup

6. PKI or Certificate Provisioning is an option in the Activation Method pull-down


In addition, the Intel® vPro AMT provisioning certificate is different than the SSL certificate to secure the webpage. When importing a provisioning certificate into the Settings page, it should show as “PKI Certificate”. If there are no provisioning certificates imported, the PKI/Certificate Provisioning option displayed above will not be available.


If a provisioning certificate is needed, vendors and instructions are available at the bottom of this page: https://www.intel.com/content/www/us/en/architecture-and-technology/implementation-of-intel-active-management-technology.html.


Wanner G.

Intel Server Specialist


View solution in original post

6 Replies
IntelSupport
Community Manager
2,080 Views

Hello Testing123,


Thank you for posting your question on this Intel® Community.


We will review the information provided and update this thread soon.


Regards,


Wanner G.

Intel Server Specialist


IntelSupport
Community Manager
2,072 Views

Hello Testing123,


The option to PKI provision endpoints in Intel® EMA can be accessed by:


1. Login as a Tenant Admin

2. Endpoint Groups

3. Click on the “3-dot ellipses” to the right of the endpoint group to manage

4. Select View Configuration

5. Click on Intel AMT Auto setup

6. PKI or Certificate Provisioning is an option in the Activation Method pull-down


In addition, the Intel® vPro AMT provisioning certificate is different than the SSL certificate to secure the webpage. When importing a provisioning certificate into the Settings page, it should show as “PKI Certificate”. If there are no provisioning certificates imported, the PKI/Certificate Provisioning option displayed above will not be available.


If a provisioning certificate is needed, vendors and instructions are available at the bottom of this page: https://www.intel.com/content/www/us/en/architecture-and-technology/implementation-of-intel-active-management-technology.html.


Wanner G.

Intel Server Specialist


IntelSupport
Community Manager
2,051 Views

Hello Testing123,


I hope you found the information provided helpful. 


If you have further questions, please do not hesitate to update this thread, and we will be glad to help you.


Wanner G.

Intel Server Specialist


IntelSupport
Community Manager
2,018 Views

Hello Testing123,


Were you able to review the information provided?


Kindly let us know if we have addressed all your questions.


Wanner G.

Intel Server Specialist


Testing123
Novice
2,008 Views

Thank you! This helped clarify things. 

IntelSupport
Community Manager
2,005 Views

Hello Testing123,


Thank you for your feedback. It is highly appreciated.


I am glad to know that you found the information provided helpful. I will proceed to close this thread.


Regards,


Wanner G.

Intel Server Specialist


Reply