Intel vPro® Platform
Intel Manageability Forum for Intel® EMA, AMT, SCS & Manageability Commander
2996 Discussions

INTEL-VPRO & INTEL EMA

dazeusgr
Beginner
812 Views

Hello Guys,

 

SO i managed to setup a lab EMA on a windows VM (sql express,win srv 2019 iis rewrite,iis)

 

I can use the intel EMA to auto provosion my dell vpro laptops BUT i cant figure out ACM.

The ema works as a single server setup with IP resolve for testing purposes

Manual's suggest a pki certificate to be bought. The question now is

 

We have a acme.local domain. How and what info should be inserted in the cert to work.

 

Also are there any other configurations required for the domain in order the admin control mode to work.

 

The goal is to configure the EMA platform to work on local domain,with sub domain's and subnets WITHOUT user consent so that why the ACM is required.

 

Thanks in advance!

0 Kudos
11 Replies
Suneesh
Employee
740 Views

Hello chrispng,


Good day.


For information on what details need to be inserted in the certificate for it to work, please refer to the link below:


https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/default.htm

(Navigate to: Setup and Configuration of Intel AMT > Setup and Configuration Methods > Remote Configuration > Setup and Configuration Using PKI (Remote Configuration) > PKI Certificate Verification Methods)


For steps on how to purchase and install the certificate, please refer to the articles below:


Regards,

Suneesh S

Intel Customer Support Technician


0 Kudos
dazeusgr
Beginner
716 Views

Hello Mr Suneesh,

 

I am a litle confused for the certificate request.

 

Since as i stated the EMA is on a VM on a local domain, on the certificate i must point the AD FQDN or the EMA VM FQDN?

 

Also after the retrival of the cert, it has to be installed on the IIS only or the EMA also?

 

Thanks in advance

0 Kudos
Suneesh
Employee
672 Views

Hello chrispng,

 

The certificate should generally match the FQDN of the server where EMA is installed to ensure proper validation and secure communication.

 

The certificate needs to be installed on both IIS and EMA to ensure secure communication and proper functioning.

 

Regards,

Suneesh S

Intel Customer Support Technician


0 Kudos
dazeusgr
Beginner
642 Views

Thanks mr sunesh.

 

Is there any possibility i have messed up the laptops AMT chipset?

 

from the AMT conf tool i get the following and no CIRA CONNECTED status from the EMA platform

 

Unable to communicate with the AMT device. Limited data will be retrieved.

Intel EMA Configuration Tool
Application Version: 1.1.0.183
Scan Date: 2/5/2025 11:54:04 πμ

*** Host Computer Information ***
Computer Name: DESKTOP-18APSA2
Manufacturer: Dell Inc.
Model: Latitude 5400
Processor: Intel(R) Core(TM) i5-8365U CPU @ 1.60GHz
Windows Version: Microsoft Windows 10 Pro
BIOS Version: Unknown
UUID: Unknown

*** SMBIOS Information ***
AMT Supported: True
AMT Enabled: True
SMBIOS ME SKU: Intel(R) Full AMT Manageability
SMBIOS ME Version: 12.0.96.2562
KVM Supported: True
SOL Supported: True
USB-R supported in BIOS: True
RSE Supported: True

*** ME Information ***
Version: Unknown
SKU: Unknown
State: None Detected
Control Mode: None
Driver Installed: False
PKI DNS Suffix: Not Found
LMS State: NotPresent

Exception in ME: Η τιμή δεν μπορεί να είναι null.
Όνομα παραμέτρου: value
Exception in ME: Η τιμή δεν μπορεί να είναι null.
Όνομα παραμέτρου: value
Pausing before ending process in 3 sec. The duration of this pause can be adjusted using the --delayterm option.

 

 

 

Just to point out, its the 3rd intel EMA server i am trying to configure for test purposes. From the first one i managed to get cire connected status from the second and this one, the third, i havent.

 

Thanks in advance

0 Kudos
dazeusgr
Beginner
636 Views

I enabled amt autoprovisioning and now i still get cira not connected but EMA shows provisioned.

 

is there any way to completely reset AMT chipset and start fresh?

 

 

0 Kudos
dazeusgr
Beginner
636 Views

Log uploaded on text

0 Kudos
dazeusgr
Beginner
624 Views

I managed to find a solution.

 

 

I had to open the back case of the laptop in orde to remove the cmos battery in order to completely reset the BIOS and AMT MPBEX Settings

 

 

After that CIRA was down even though laptop was auto provisioned because Firewall was enabled in both the EMA VM and the laptop.

After i disabled the windows firewall CIRA CONNECTED.

 

So since the documentention is not clear enough, what are the DEFAULT PORTS for the CIRA to connect?

 

Also are they the same for opening ports from the outside to the EMA machine?

 

Thanks in advance

0 Kudos
Suneesh
Employee
572 Views

Hello chrispng,


Greetings!


As per the ECT we see that the endpoint (DESKTOP-18APSA2) is trying to see the swarm server through a wired connection, however it is not connected.


Please make sure that the ports 8080 and 443 are opened for the CIRA connection. From the endpoint make sure the non-TLS ports are opened.


Regards,

Suneesh

Intel Customer Support Technician



0 Kudos
Suneesh
Employee
471 Views

Hello chrispng,


We are following up on this thread. If further assistance is necessary, please do not hesitate to reply.


Regards,

Suneesh S

Intel Customer Support


0 Kudos
Suneesh
Employee
414 Views

Hello chrispng,


We are following up on this thread. If further assistance is necessary, please do not hesitate to reply.


Regards,

Suneesh S

Intel Customer Support


0 Kudos
dazeusgr
Beginner
246 Views

Hello Mr Suneesh S,

 

I resolved the problem, i yet to test the PKI cert.

 

I will need also to test the deployment on two different Domains.

 

Is it supported i mean, 1 EMA for 2 domains?

0 Kudos
Reply