SCCM PKI - SMSPXE IN SSL , NO CLIENT CERT

D1enonly 46 Reputation points
2020-10-07T20:09:07.97+00:00

Hi, i did remove and requested a new cert for the DP and exported it on the DP https settings. the cert is applied and put it the password.
i also checked if there are any certificates being blocked by SCCM but there is none.

30785-30586-nossl.png
30784-30606-nossl2.png

Microsoft Configuration Manager Deployment
Microsoft Configuration Manager Deployment
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Deployment: The process of delivering, assembling, and maintaining a particular version of a software system at a site.
990 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Fiona Yan-MSFT 2,311 Reputation points
    2020-10-08T06:26:13.717+00:00

    @D1enonly

    Thank you for posting in Microsoft Q&A forum.

    30837-no-availavle-computer.png

    Could we know that our task sequence is deployed to known or unknow clients? If we are deploying to unknown client, please help check have we enabled unknown computer support on our DP's settings ? And have we deployed a task sequence to the unknown computers collection?
    30728-unknown-computer-support.png

    I know it sounds simple and was probably already ruled out for some reason, but I haven't seen you mention it.

    Have a nice day!


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.
    0 comments No comments

  2. D1enonly 46 Reputation points
    2020-10-08T12:30:23.35+00:00

    HI, The task sequence is deployed to all Unknown computers.

    and the unknown computer is ticked on that

    30936-p1.png
    30988-p2.png
    30963-p3.png
    31001-p4.png
    30829-p5.png

    0 comments No comments

  3. Fiona Yan-MSFT 2,311 Reputation points
    2020-10-09T09:40:12.353+00:00

    @D1enonly

    I reviewed this case again. As you mentioned before, you have removed the certificate and added a new one. Could we consider this certificate is ok and then have a try?
    1.Generally speaking, our DP has two certificates. When communicating with the client to be deployed, this client will obtain the certificate from our DP. Another certificate is used for site server and MP.

    2.Have we chosen use HTTPS option? If we choose it, the server must have a valid PKI web server certificate.
    Here are some helpful article for you to refer to:
    configure client pki certificates
    deploy-pki-certificates-for-sccm-2012-r2
    Note: This is non-official Microsoft article just for your reference.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.