<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://wmug.co.uk/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>.:: (MVP) Raphael ::. : ibcm, certificates</title><link>http://wmug.co.uk/wmug/b/dotraphael/archive/tags/ibcm/certificates/default.aspx</link><description>Tags: ibcm, certificates</description><dc:language>en-US</dc:language><generator>6.x Production</generator><item><title>SCCM &amp; NAT</title><link>http://wmug.co.uk/wmug/b/dotraphael/archive/2010/10/14/sccm-amp-nat.aspx</link><pubDate>Thu, 14 Oct 2010 13:11:00 GMT</pubDate><guid isPermaLink="false">10c3822e-6a55-4a1a-8d52-5181c69a645b:3564</guid><dc:creator>Raphael</dc:creator><slash:comments>0</slash:comments><comments>http://wmug.co.uk/wmug/b/dotraphael/archive/2010/10/14/sccm-amp-nat.aspx#comments</comments><description>&lt;p&gt;Hi All,&lt;br /&gt;&lt;br /&gt;installing a sccm client today and got the following errors on the ccmsetup.log&amp;nbsp;&lt;/p&gt;
&lt;p&gt;o	[CCMSETUP] AsyncCallback(): -----------------------------------------------------------------
&lt;br /&gt;o	[CCMSETUP] AsyncCallback(): WINHTTP_CALLBACK_STATUS_SECURE_FAILURE Encountered
&lt;br /&gt;o	[CCMSETUP]                : dwStatusInformationLength is 4
&lt;br /&gt;o	[CCMSETUP]                : *lpvStatusInformation is 0x9
o	[CCMSETUP]            : WINHTTP_CALLBACK_STATUS_FLAG_CERT_REV_FAILED is set
&lt;br /&gt;o	[CCMSETUP]            : WINHTTP_CALLBACK_STATUS_FLAG_INVALID_CA is set
&lt;br /&gt;o	[CCMSETUP] AsyncCallback(): -----------------------------------------------------------------
&lt;br /&gt;o	Failed to send HTTP request. (Error at WinHttpSendRequest: 12175)
o	DownloadFileByWinHTTP encountered an unrecoverable error.
&lt;br /&gt;o	Sending Fallback Status Point message, STATEID=&amp;#39;308&amp;#39;.
o	State message with TopicType 800 and TopicId {F29C31A1-173D-4DAC-88C4-D3C51F936655} has been sent to the FSP &lt;br /&gt;
&lt;br /&gt;At this point, as good sccm admin as I am, used the trace32 error lookup and found that 12175 means:&amp;nbsp;&amp;quot;A security error occurred&amp;quot;&lt;br /&gt;&lt;br /&gt;As this message is really good, searched over the internet and found the the MSDN have a more usefull message at&amp;nbsp;&lt;a target="_blank" href="http://msdn.microsoft.com/en-us/library/aa383770(VS.85).aspx"&gt;http://msdn.microsoft.com/en-us/library/aa383770(VS.85).aspx&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;br /&gt;One or more errors were found in the Secure Sockets Layer (SSL) certificate sent by the server. To determine what type of error was encountered, check for a WINHTTP_CALLBACK_STATUS_SECURE_FAILURE notification in a status callback function. For more information, see WINHTTP_STATUS_CALLBACK.&lt;br /&gt;&lt;br /&gt;At this point, i&amp;#39;m pretty sure that there is a problem with SSL as I&amp;#39;m installing a native mode client (I haven&amp;#39;t seen this issue in a mixed mode). As it wasn&amp;#39;t clear yet, I asked help from network/firewall guys and found that the client was in a NAT network...as this is not supported&amp;nbsp;(&lt;a target="_blank" href="http://technet.microsoft.com/en-us/library/dd547071.aspx"&gt;http://technet.microsoft.com/en-us/library/dd547071.aspx&lt;/a&gt;, see network adapter), we changed to be a routed network and voil&amp;agrave;, client installed :)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://wmug.co.uk/aggbug.aspx?PostID=3564&amp;AppID=113&amp;AppType=1&amp;ContentType=0" width="1" height="1"&gt;</description><category domain="http://wmug.co.uk/wmug/b/dotraphael/archive/tags/certificates/default.aspx">certificates</category><category domain="http://wmug.co.uk/wmug/b/dotraphael/archive/tags/ibcm/default.aspx">ibcm</category><category domain="http://wmug.co.uk/wmug/b/dotraphael/archive/tags/native+mode/default.aspx">native mode</category><category domain="http://wmug.co.uk/wmug/b/dotraphael/archive/tags/sccm/default.aspx">sccm</category><category domain="http://wmug.co.uk/wmug/b/dotraphael/archive/tags/systemcenter/default.aspx">systemcenter</category></item><item><title>[SCCM] SCCMNativeModeReadiness - Client is not ready</title><link>http://wmug.co.uk/wmug/b/dotraphael/archive/2010/10/14/sccm-sccmnativemodereadiness-client-is-not-ready.aspx</link><pubDate>Thu, 14 Oct 2010 12:50:00 GMT</pubDate><guid isPermaLink="false">10c3822e-6a55-4a1a-8d52-5181c69a645b:3563</guid><dc:creator>Raphael</dc:creator><slash:comments>1</slash:comments><comments>http://wmug.co.uk/wmug/b/dotraphael/archive/2010/10/14/sccm-sccmnativemodereadiness-client-is-not-ready.aspx#comments</comments><description>&lt;p&gt;Hi All,&lt;br /&gt;&lt;br /&gt;quick post to share my experience..&lt;br /&gt;&lt;br /&gt;i&amp;#39;m finishing one native mode/ibcm project and I came across the following issue today when running the SCCMNativeModeReadiness&lt;br /&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;Initializing ModeReadiness tool.&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;ModeReadiness&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;10/14/2010
9:57:21 AM&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;2680 (0x0A78)&lt;/p&gt;
&lt;p class="MsoNormal"&gt;Setting default logging component for process.&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;ModeReadiness&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;10/14/2010 9:57:21 AM&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;2680
(0x0A78)&lt;/p&gt;
&lt;p class="MsoNormal"&gt;The &amp;#39;Certificate Store&amp;#39; is empty in the registry, using
default store name &amp;#39;MY&amp;#39;.&lt;span&gt;&amp;nbsp; &lt;/span&gt;ModeReadiness&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;10/14/2010 9:57:21 AM&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;2680 (0x0A78)&lt;/p&gt;
&lt;p class="MsoNormal"&gt;Failed to load default certificate selection criteria.
(0x80004005)&lt;span&gt; &lt;/span&gt;ModeReadiness&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;10/14/2010 9:57:21 AM&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;2680 (0x0A78)&lt;/p&gt;
&lt;p class="MsoNormal"&gt;ModeReadiness initializiation succeeded.&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;ModeReadiness&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;10/14/2010 9:57:21 AM&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;2680
(0x0A78)&lt;/p&gt;
&lt;p class="MsoNormal"&gt;Client SSL is enabled. The current state is 0x127.&lt;span&gt;&amp;nbsp; &lt;/span&gt;ModeReadiness&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;10/14/2010
9:57:21 AM&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;2680 (0x0A78)&lt;/p&gt;
&lt;p class="MsoNormal"&gt;Certificate issued to &amp;#39;&lt;strong&gt;FQDN&lt;/strong&gt;&amp;#39;
doesn&amp;#39;t have private key.&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;ModeReadiness&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;10/14/2010 9:57:34 AM&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;2680 (0x0A78)&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;strong&gt;Client is NOT ready
for native mode&lt;/strong&gt;.&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;ModeReadiness&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;10/14/2010 9:57:34 AM&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;2680 (0x0A78)&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;/p&gt;
&lt;p&gt;
Sending state message.&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;ModeReadiness&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;10/14/2010 9:57:34 AM&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;2680 (0x0A78)&amp;nbsp;&lt;br /&gt;&lt;br /&gt;Looking at the log lines, it&amp;#39;s easy to think that the certificate doesn&amp;#39;t have private key...but when i open the MMC, I found that the certificate has it:&lt;br /&gt;&lt;img src="http://wmug.co.uk/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-00-07-metablogapi/nativemode02.png" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;to fix the issue,I had to:&lt;/p&gt;
&lt;p&gt;- Deleted all certificates from machine using MMC&lt;br /&gt;- revoked all certificates issued to the
computer&lt;br /&gt;- Stopped the Crypto Service&lt;br /&gt;- Stopped the Cryptographic Services (net stop CryptSvc)&lt;br /&gt;- Renamed the folders under the Crypto Folder (C:\Documents and Settings\All
Users\Application Data\Microsoft\Crypto)&lt;br /&gt;- Rebooted machine&lt;br /&gt;- All the machine is domain member, it got a new certificate by the autoenrollment&amp;nbsp;&lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://wmug.co.uk/aggbug.aspx?PostID=3563&amp;AppID=113&amp;AppType=1&amp;ContentType=0" width="1" height="1"&gt;</description><category domain="http://wmug.co.uk/wmug/b/dotraphael/archive/tags/certificates/default.aspx">certificates</category><category domain="http://wmug.co.uk/wmug/b/dotraphael/archive/tags/ibcm/default.aspx">ibcm</category><category domain="http://wmug.co.uk/wmug/b/dotraphael/archive/tags/native+mode/default.aspx">native mode</category><category domain="http://wmug.co.uk/wmug/b/dotraphael/archive/tags/sccm/default.aspx">sccm</category><category domain="http://wmug.co.uk/wmug/b/dotraphael/archive/tags/systemcenter/default.aspx">systemcenter</category></item></channel></rss>