Intel vPro® Platform
Intel Manageability Forum for Intel® EMA, AMT, SCS & Manageability Commander
2834 Discussions

Open AMT with vPro | Provisioning certificate doesn't match

miguelanruiz
Novice
948 Views

Hello everyone,

 

I am trying to lift Intel AMT using the Open-amt-toolkit, but something happens with the certificate. Although the IIS-based guide has a very clear indication and my results are exactly as expected, when I load this .pfx certificate, it seems that something is corrupted or that only a SHA1 hash is generated.

How can I manually validate if the RPC is generating the same Intel trusted HASH?

Could it be a client bug?

 

miguelanruiz_0-1645124392527.png

 

0 Kudos
1 Solution
miguelanruiz
Novice
866 Views

Hello,

 

Thank you very much for your interest, I managed to solve the problem and it happens that the guides published in:

 

https://open-amt-cloud-toolkit.github.io/

 

They do not mention how to generate the full chain file and it was something that was not being taken into account in the installation. After making this correction, the platform is ready.

 

This full chain information is available in the Intel SCS documentation.

 

Best regards,

View solution in original post

0 Kudos
6 Replies
SergioS_Intel
Moderator
930 Views

Hello miguelanruiz,


Thank you for contacting Intel Customer Support.

 

I understand that the Open AMT with vPro | Provisioning certificate doesn't match.


I will be more than glad to help you today.


Can you please let us know on how many systems are you getting this error and what version of AMT are you running?


Looking forward to your updates.


Best regards,

Sergio S.

Intel Customer Support Technician

For firmware updates and troubleshooting tips, visit :https://intel.com/support/serverbios


0 Kudos
miguelanruiz
Novice
920 Views

Hello Sergio,

 

I am trying to do a deployment for more than 1000 Intel NUC11TNHv5 devices.

 

But this seems to be more of an OpenAMT issue and not a device issue.

 

I have the impression that this is oriented towards the OpenAMT documentation to define the certificate requirements and its mounting process on the server.

 

This is complete up to the validation of the certificate, with its key in .pfx format.

 

miguelanruiz_0-1645328392754.png

Thank you so much 

0 Kudos
SergioS_Intel
Moderator
905 Views

Hello miguelanruiz,


We appreciate the additional information, please allow us to check it and we will get back to you.


Best regards,

Sergio S.

Intel Customer Support Technician

For firmware updates and troubleshooting tips, visit :https://intel.com/support/serverbios


0 Kudos
SergioS_Intel
Moderator
891 Views

Hello miguelanruiz,


Thank you for waiting for our updates.


It seems that the certificate vendor is GoDaddy, if this is the case, please follow the guide How To Purchase and Install GoDaddy* Certificates for Intel® AMT Remote Setup and Configuration https://www.intel.com/content/dam/support/us/en/documents/software/software-applications/how_to_purchase_and_install_godaddy_certificates_for_setup_and_configuration.pdf) also please check if you have the the proper OID (page 12 section 5).


Also, if possible, please send us pictures and the pictures of the certificate path tab.


Finally, please let us know what is the AMT version your Intel(R) NUCS have and if the certificate is SHA1, SHA2 or SHA256


Please do not hesitate to contact us again if you need further assistance.


Best regards,

Sergio S.

Intel Technical Support Technician

For firmware updates and troubleshooting tips, visit :https://intel.com/support/serverbios


0 Kudos
miguelanruiz
Novice
867 Views

Hello,

 

Thank you very much for your interest, I managed to solve the problem and it happens that the guides published in:

 

https://open-amt-cloud-toolkit.github.io/

 

They do not mention how to generate the full chain file and it was something that was not being taken into account in the installation. After making this correction, the platform is ready.

 

This full chain information is available in the Intel SCS documentation.

 

Best regards,

0 Kudos
SergioS_Intel
Moderator
850 Views

Hello miguelanruiz,


We are glad to read that you were able to resolve your problem, since you marked the thread as closed, we will close it from our end.


In case you need more assistance, please contact us back.


Best regards,

Sergio S.

Intel Technical Support Technician

For firmware updates and troubleshooting tips, visit :https://intel.com/support/serverbios


0 Kudos
Reply