Intel vPro® Platform
Intel Manageability Forum for Intel® EMA, AMT, SCS & Manageability Commander
2837 Discussions

Failed PKI provisioning

mrant-k
Novice
13,723 Views

We are trying to adopt EMA in addition to our existing endpoint management solutions and running into some serious issues. We acquired PKI cert with valid OID from GoDaddy. The leaf cert (in the form of pfx), GoDaddy G2 Root CA, and Intermediate cert are added into the server. The first 2 devices were successfully provisioned, but then any new devices we attempt to add are failing. 

- Windows Server 2019 Datacenter (US-English) (EMA server)

- Succeeded client laptop has AMT 14.1.67

- Failed Client laptops have AMT 11 and lower, and AMT 15 and above

- Verified DHCP option 15 is set with correct DNS suffix, which is also in the GoDaddy Deluxe cert

- Correct OID is verified

- Exported EMAAgent files and run -fullinstall on client

- We can see the client in EMA console as power on and connected (but unprovisioned)

- We then attempt to provision the client and it fails provisioning and we see these 2 msgs in the Failed Intel AMT SetupAdmin activation and Failed PKI provisioning

- On the client we see the Intel ME software repeated switching states from "Configured" to "Unconfigured"

-  The clients are connected to LAN via USB-C ethernet dongle since these newer laptops don't come with ethernet port anymore

- We've tried searching and following many threads in this forum and other places to no avail

Any help is greatly appreciated. 

60 Replies
MIGUEL_C_Intel
Employee
5,437 Views

Hello, mrant-k,


Thank you for sharing the outcome while trying to get the correct certificate.  Please allow me to review the case with the engineering department.  I will return with you soon.


Regards,

Miguel C.

Intel Customer Support Technician


0 Kudos
MIGUEL_C_Intel
Employee
5,436 Views

Hello, mrant-k,


Prior to work with the engineering team, please provide the information below:

1- Intel® EMA software version

2- Windows Server version and location (physical or virtual)

3- SQL version and location (physical or virtual)

4- Are EMA server and database in the same location?

5- Do you mind sending me the EMA server log, the path is the following:

[System drive]\Program File(x86)\Intel\Platform Manager\EmaLogs


Look forward to your response


Regards,

Miguel C.

Intel Customer Support Technician



0 Kudos
mrant-k
Novice
5,409 Views

Sure.

  1. ema version = 1.10.1.0.1
  2. Virtual WinServer2019 DataCenter
  3. SQL Express 2019
  4. DB and EMA server are in the same location
  5. EMA server logs folder contain a bunch of log files. Were you looking for a specific file?mrantk_0-1685628246794.png

     

0 Kudos
MIGUEL_C_Intel
Employee
5,402 Views

Hello, mrant-k,


Please send me the files without the date, called:

EMAlog-Webserver.txt

EMAlog-Swarmserver.txt

EMAlog-Ajaxserver.txt

EMAlog-Recoveryserver.txt

EMAlog-Manageabilityserver.txt


They are the latest logs. Look forward to your response


Regards,

Miguel C.

Intel Customer Support Technician


0 Kudos
MIGUEL_C_Intel
Employee
5,395 Views

Hello, mrant-k,


Adding to my previous post, please send me a picture from IIS.


1- Go to the EMA server

2- Open Manage Computer Certificates

3- Right-click over the personal folder

4- Select Find Certificates

5- In the contains box, type the certificate name

6- In Look in field: Select Issues to

7- Then, Hit Find now.


Please do the same for

In the contains box, type root

In the Look in field: Select “Issues to” Please do the same for “SHA1 Hash”


Excuse me for the extra steps.


Regards,

Miguel C.

Intel Customer Support Technician


0 Kudos
mrant-k
Novice
5,368 Views

Hi Miguel,

 

Here are the logs you asked. Since our last communication, I rekeyed our cert using Starfield CA to see if that'd make any difference, which hasn't been the case. 

 

0 Kudos
MIGUEL_C_Intel
Employee
5,353 Views

Hello, mrant-k,


Please send me the pictures with the instructions below:

1-Do you mind opening the columns: Issued By, Intended Purposes, and Friendly Name for the picture called 1.png

From picture 2.png please open the columns Issued To, Issued By, and Intended Purpose


2-By any chance, did you filter by SHA1? If not, try using Starfield (Contains) and SHA1 (Look in field).


Please do not dispose of the GoDaddy certificate.


I am wondering if we can set a web-meeting next week, so we can expedite the resolution of the issue.  If you agree, I will send a private message with the invite.  Include a range of hours (Time Zone) and days available.


Look forward to your response.


Regards,

Miguel C.

Intel Customer Support Technician


0 Kudos
mrant-k
Novice
5,348 Views

Sure thing. 

 

0 Kudos
MIGUEL_C_Intel
Employee
5,335 Views

Hello, mrant-k,


Do you mind sending me a new picture; this time please expand the columns completely. It is very important for validation.


Please let me know if you get any results while sorting by SHA1 (Look in field).  If yes, please share the picture, and name it SHA1.


Regards,

Miguel C.

Intel Customer Support Technician


0 Kudos
mrant-k
Novice
5,255 Views

Hi Miguel, 

These are the best I can expand. Please let me know if it doesn't work. 

0 Kudos
JeroenW
Beginner
5,286 Views

Hello @MIGUEL_C_Intel ,

 

Very happy I came across this thread.

I'm experiencing the exact same issues as @mrant-k .

I'm trying Lan-Less deployments with 3 test devices to test for a new solution we would like to implement.

Desktop client connected via LAN, NOT WIFI or adapters

PKI DNS is set in BIOS of the devices

  • Can't provision Intel AMT v12, v15 or v16
  • GoDaddy certificate is the vPRO one, but shows the 4 lines in the certificate chain with the Class 2 SHA1 as line 1.

Can I also share the requested screenshots from the certificates with you for investigation?

 

1- Intel® EMA software version - EMA v1.10.1.0

2- Windows Server version and location (physical or virtual) - virtual Azure template - 2019

3- SQL version and location (physical or virtual) - virtual SQL Express

4- Are EMA server and database in the same location? Yes, same server

5- Do you mind sending me the EMA server log, the path is the following:

[System drive]\Program File(x86)\Intel\Platform Manager\EmaLogs

 

0 Kudos
mrant-k
Novice
5,251 Views

Thanks for joining. I'm glad I'm not alone.

0 Kudos
Mike_Modality
Beginner
5,240 Views

I have another thread going on with basically the exact same issue. I didn't have a system to test until recently that was between vpro 11-15.

 

AMT 11 and lower - It would actually provision in admin control mode but CIRA won't connect (But that turns out just to be an issue with the age of the system and the latest vpro server version)

AMT 16+ - It would not provision, and have a cert_verify_error when trying to provision it into admin control mode.

AMT 14 - Provisioned perfectly with full admin control access.

I'm currently working to resolve it so systems like the AMT 16 system I have provision correctly, and to confirm where the error is with the certificate so I can try to get my vpro cert provider to correct the issue. 

 

I've had the same problems with certificate support staff where they had no idea and ran basic troubleshooting, and had incorrect information trying to say my cert was wrong, then issue me the exact same cert that was the "correct" cert, and then just ignore the tickets hoping I''d leave them alone I assume.

0 Kudos
MIGUEL_C_Intel
Employee
5,229 Views

Hello, mrant-k and JeroenW,


We are doing a review of pictures and logs. An update will be shared soon.


Regards,

Miguel C.

Intel Customer Support Technician



0 Kudos
mrant-k
Novice
5,179 Views

Hi Miguel,

Thanks. Please keep us posted. As of right now, our vPro initiative has stalled awaiting your input.

0 Kudos
MIGUEL_C_Intel
Employee
5,154 Views

Hello, mrant-k,


We appreciate your comprehension.  An update will be provided soon.


Regards,

Miguel C.

Intel Customer Support Technician


0 Kudos
mrant-k
Novice
5,095 Views

Hi Miguel,

I'm not sure if you received my response to your private message. Please let me know if we're still on for the meeting today. 

0 Kudos
MIGUEL_C_Intel
Employee
5,072 Views

Hello, mrant-k,


It was our pleasure to meet with you today.


Please keep us updated with the results of the new Certificate request. 


Remember to select GoDaddy-SHA2 from the Request Algorithm option.

And check the vPro option.


I look forward to hearing from you.


Regards,

Miguel C.

Intel Customer Support Technician


0 Kudos
mrant-k
Novice
5,069 Views

Hi Miguel,

It was pleasure talking to you guys. I confirm the GoDaddy SHA-2 is the default option (no SHA1 option there, so it wasn't the case for sure). I just reinstalled EMA and will try to provision a device soon. 

0 Kudos
MIGUEL_C_Intel
Employee
5,024 Views

Hello, mrant-k,


Thank you for your confirmation.


Please keep us posted with the results of the Intel® EMA reinstallation.


Regards,

Miguel C.

Intel Customer Support Technician


0 Kudos
mrant-k
Novice
4,769 Views

Hi Miguel,

I now have a working certificate and can successfully provision in admin control mode. However, the 'hardware manageability' tab won't load, and remote desktop doesn't work either. Client logs show these:

mrantk_0-1686678047815.png

 

0 Kudos
Reply