Intel vPro® Platform
Intel Manageability Forum for Intel® EMA, AMT, SCS & Manageability Commander
2920 Discussions

Intel AMT - Register PKI DNS Suffix and Root CA on unprovisioned devices

Horgster
New Contributor I
3,163 Views

Hi!

Is there anyone who has an tip on how we can register "PKI DNS Suffix" and Root CA thumbprint for devices that is not yet provisioned programmatic?

We need to have an tool that can set this programmatically without doing it manually by IT-personnel.

Scenario for this usage is during SCCM OS Deployment to prepare the Intel AMT device for provisioning with Intel EMA.

Any one has an idea on how this can be carried out without the need to enter the Intel MBEx BIOS manually?

Thanks
Best Regards
Horgster

0 Kudos
4 Replies
MarcinW
Beginner
3,058 Views

Hello I have the same question . Any ideas? 

0 Kudos
Zieri__Sascha
Beginner
2,922 Views

Hi

You can use the USBFile.exe to make a BIN file. If placed on an USB Stick and activated in Bios you can configure Digest Password, Certificate or PKI DNS Suffix with booting from the USB Stick.

This was part of AMT_SDK_12.0.0.9 - I don't know where you can get it now but attached it with the sample BAT.

Greetings

Sascha

 

 

0 Kudos
Zieri__Sascha
Beginner
2,917 Views

Sorry - Recognized that finally a new Version of the USBFile.exe is available with the Version 15 SDK probably better download that and use it.

Intel® Active Management Technology SDK

Greetings

Sascha

0 Kudos
MarcinW
Beginner
2,873 Views

thank you for the info. I will try it. 

0 Kudos
Reply