Quantcast
Channel: Intel Communities: Message List - Intel® vPro™ Platform
Viewing all 1770 articles
Browse latest View live

Re: Certificate Problem with SCS 8.2

$
0
0

Hello Kyle,
thank's for your answer.

 

1. We purchased our provisioning certificate from Verisign. The OU Field is in the correct format and states
Intel(R) Client Setup Certificate.

2. We are not able to provision any system. I tried it with three Testclients but none of the worked.

 

3. Do you mean the AMT Provisioning Template or the Webserver Template? I checked the Webserver-Template, it had the 'Supply in request' setting. I changed the setting in the AMT Provisioning Template but that led to another error.

 

Failed to submit the certificate request to the Certification Authority. template-ConfigMgrAMTWebServerCertificate: Certificate request failed with error -2147024809- The parameter is incorrect..Intel(R) AMT Operation failed. (Request Certificate).

 

I changed it back to 'build from AD-User principal name' settings.

 

Now i get a new error.

 

Final status of Intel(R) AMT is unknown because a failure occurred when configuring the system. The RCS failed to validate the supplied One Time Password (OTP) for PKI configuration against the Intel(R) AMT system. Please make sure that the supplied OTP is the OTP that is configured in the Intel AMT system.


We have disabled the 'OTP required' setting in the SCS Console so i don't know why the system is looking for this password. The clients are standart machines without any special Bios settings.

 

4. The XML File is automaticly created by the ACM_Configure_SCCM Script we don't use it for provisioning. It seems more like a log file to me.

 

5. Here comes the error that is shown in the SCM_Configure_SCCM.bat cmd window at the moment.

 

Connected to the Intel(R) Management Engine Interface driver, version 5.2.0.1008

Activate Intel(R) AMT configuration: (0xc0000050) (Success. )
Waiting for FW to move to In-Provision state(0)...
The Start configuration operation completed successfully.
***** END StartConfigurationInt ******

RCSaddress=Testserver10.Testumgebung.Testingen.de, RCSMIUser=, RCSProfileName=
SCCM_AMT_PROFILE
Success. (0) ((ExecMethod WMI_GetNetworkSettings) Success. )
TestWS4275.Testumgebung.Testingen.de
RCSaddress=Testserver10.Testumgebung.Testingen.de, RCSMIUser=, UUID=6F3DB970-5
698-DE7B-5060-00199985160B, ConfigMode=2, PID=, RCSProfileName=SCCM_AMT_PROFILE,
AMTVersion=5.0.1, OldADOU=, Configure AMT Name= True. Configure AMT IPv4= True.
Source For AMT Name= Host Name- TestWS4275 Domain Name- Testumgebung.Testingen
.de . Default OS Name= Host Name- TestWS4275 Domain Name- Testumgebung.Testingen
n.de . Configure AMT IPv4 to DHCP mode= True. AMT IPv4= IPv4 Address- 10.37.135.
86 .
Final status of Intel(R) AMT is unknown because a failure occurred when configur
ing the system. (0xc000271b) ((ExecMethod WMI_ConfigAMT) Final status of Intel(R
) AMT is unknown because a failure occurred when configuring the system.  (0xc00
0271b). The RCS failed to validate the supplied One Time Password (OTP) for PKI
configuration against the Intel(R) AMT system. Please make sure that the supplie
d OTP is the OTP that is configured in the Intel AMT system.  (0xc00007db).  (0x
c000271b). )
***** END RemoteConfiguration ******


***********

Exit with code 75.
Details: Failed to complete remote configuration of this Intel(R) AMT device. Fi
nal status of Intel(R) AMT is unknown because a failure occurred when configurin
g the system.  (0xc000271b). The RCS failed to validate the supplied One Time Pa
ssword (OTP) for PKI configuration against the Intel(R) AMT system. Please make
sure that the supplied OTP is the OTP that is configured in the Intel AMT system
.  (0xc00007db). The RCS failed to process the request.

 

The certificate error from before hasn't appeared again cause it seems to get some problems with the OTP now. The only thing i tried between the two errors was the change in the certificate.


Re: El Servicio Intel RST no esta en ejecución

$
0
0


Tengo el mismo problema.

Yo tengo una Tarjeta Madre INTEL DP55WB y otra DH77EB

en ambas tengo el mismo problema que se menciona aquí..

 

Ambos equipos los tengo en configuración RAID1

y note que el problema se presento cuando cambie uno de los discos

desde entonces tengo el error: "El Servicio Intel RST no esta en ejecución"

 

en el registro de eventos de Windows recibió los siguientes errores:

1.-

IAStorDataMgrSvc

Internal program error:  missing resource string DM_1_0_7

 

2.-

Aplicación: IAStorDataMgrSvc.exe

Versión de Framework: v4.0.30319

Descripción: el proceso terminó debido a una excepción no controlada.

Información de la excepción: System.FormatException

Pila:

  en System.Text.StringBuilder.AppendFormat(System.IFormatProvider, System.String, System.Object[])

  en System.String.Format(System.IFormatProvider, System.String, System.Object[])

  en IAStorDataMgr.EventRelay.formatStrings(System.String, System.Object[])

  en IAStorDataMgr.EventRelay.translateEventType(IAStorUtil.Events.DiskEventArgs, IAStorUtil.LogLevel)

  en IAStorDataMgr.EventRelay.SDM_ComprehensiveHandler(System.Object, IAStorUtil.Events.ComprehensiveEventArgs)

  en IAStorUtil.SystemDataModelListener.ProcessSystemDataModelChanges()

  en IAStorUtil.SystemDataModelListener.LoadSavedSystemState()

  en IAStorDataMgr.EventRelay.<Start>b__0(System.Object)

  en System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)

  en System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)

  en System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)

  en System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()

  en System.Threading.ThreadPoolWorkQueue.Dispatch()

  en System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

 

Los dos equipos funcionan bien aun asi.

alguien a resuelto esto?

AMT meets bootloader pre-boot authentification requirements

$
0
0

Hello,

 

I'm struggling with the following problem for several days now.

 

The scenario is as follows: I have a server with a bootloader which requires me to enter a password before booting (This bootloader can not be configured to use a serial port for communication). I have to administer the server from remote so I need a technique to enter this password from remote and (this is important) do this automatically by a script.

 

I'm now thinking if the Intel AMT functionality would suit my needs (if so I would buy the appropriate hardware)

-As I understand it, I will not be able to use the Serial Over Lan (SOL) functionality, because the bootloader wouldn't work with SOL. Is this correct?

-So an alternative would be the KVM functionality. But would it be possible to just send the password via script with the KVM? (As script here I understand everything which enables me to send the password automatically without typing it in manually with the keyboard)

-I also saw the Intel AMT SDK. I'm able to program c++ and c# using this SDK, if it helps me with my problem.

 

So this are the three main points I found, but I still don't know if one of these can solve my problem.

 

Thank you for any help,

Alex

 

Re: AMT meets bootloader pre-boot authentification requirements

$
0
0

Alex,

It really depends on how the bootloader functions. It might be possible to use Serial Over LAN, as long as the bootloader doesn’t switch to a graphical mode or take control of the serial ports.

KVM will work, but it will be a more involved process than using SOL.

I would suggest asking your question in the Business Client Developer Community, as they will be able to give you a more detailed answer.

http://software.intel.com/en-us/business-client

Re: El Servicio Intel RST no esta en ejecución

$
0
0

¿Has intentado descargar e instalar el último paquete de controlador RST de la placa base?

Re: El Servicio Intel RST no esta en ejecución

$
0
0

Cuando fallo el disco duro tenía la versión:

12.5.0.1066    (descargado de Intel.com para la DH77EB)

Con esa versión se reconstruyo la RAID1

 

Pero cuando termino surgió el problema de “El Servicio Intel RST no esta en
ejecución”

 

Desinstale el RST y lo instale otra vez pero el error persiste.

 

Después de la página http://station-drivers.com/page/intel%20raid.htm
fui instalando versión por versión hasta la más reciente y el problema
persiste.

 

 

En la DP55WP también tenía la versión 12.5.0.1066 hice lo mismo que con la
DH77EB y no se soluciona el problema.

 

En el sitio de INTEL para la placa DP55WB me indica la versión 11.0.0.1032
pero si le pongo esa mí, Windows ya no arranca, tengo que darle restaurar para
que funcione.

 

En ambos equipos tengo Windows 8 Pro x64 en modo UEFI.

 

Alguna solución para corregir el error?

Re: Using PC Alarm clock with SCCM

$
0
0

This issue has now been resolved.  With Alan's help, I was able to narrow the issue down to a Kerberos authentication issue, caused by the fact I never added the registry key - described in this article - to the machines.  This prevented me from connecting using the AMT WebGUI but also prevented the alarm clock from being set correctly.  Once the registry key had been added & PC rebooted, I was able to connect using WebGUI and PCE alarm clock was set without issue.

 

Thanks again for all the support Alan.

Using remotecontrol.exe

$
0
0


I have a network of mostly version 5 MebX and am using the remotecontrol.exe utility to power the PCs on and off.  However, on one Dell model in particular (960) the powerdown command is the equivalent of pulling the plug, so the PC cannot re-cycle it's power as it does during a normal shutdown.  Therefore the NIC doesn't stay live so I can't send a powerup command.  Is there any way in vPro to send a Windows shutdown command instead of poweroff?  Thank you.


Re: El Servicio Intel RST no esta en ejecución

$
0
0

Tengo el mismo problema mencionado, " El servicio intel RST no esta en ejecución"

 

Ya descargué los contraladores, cómo se instalan?

 

Mi Lao Top es Intel Core i3 M380 2.53GHz 4 Ram

 

Cuáles son los siguientes pasos?

Re: Using remotecontrol.exe

$
0
0

Communication with vPro is done on a hardware level, so issuing a graceful OS based shutdown command is not possible.

Re: Certificate Problem with SCS 8.2

$
0
0

Sorry for the delay.

  1. I don’t follow your post.   This is for the AMT TLS certificate NOT for the provisioning certificate.  In the beginning you had ‘supply in the request’ or ‘build from AD’ set? What is set now?
  2. OTP errors can be hard to fix.  They are valid for a certain amount of time, so waiting a day can make it work. Also doing an unconfigure operation from MEBX can work.  Do you get OTP errors on all your test clients?

Re: Certificate Problem with SCS 8.2

$
0
0

Hi Kyle,

 

1. To be sure i'm talking about the right certificate. The AMT TLS certificate is created from the Webserver Template, is that right? If that's the case the Subject Name is set to 'supply in the request' at the moment. It was set to 'Build from...DNS name' before but we changed it.

If the TLS certificate is created from another template please let me know.

Up to now we have the Verisign Server certificate for the first contact, the Webserver Template and the AMT Provisioning template. We build them after the instructions for SCCM 2007.

Are there any more certificates or templates we need?

Under SCCM 2007 it worked great with these templates. SCCM 2012 generated some unusual errors so we tried to provision the clients with SCS 8.2.


2. We get the OTP Error from two clients, the third seems to have had some problems with the unprovisioning under SCCM 2007 and gives us a Hash error cause the Servername and Certificate changed.

The OTP error stays even after some days of waiting.


Actually the provisioning seems to start cause the AD object is being generated and we find the proper data in the Mbex after the error occured. But managing the client afterwards is not possible because SCS counts the provisioning as an error.

Re: El Servicio Intel RST no esta en ejecución

$
0
0

Yo tengo el mismo problema  con Windows 8 x64 con un i5 placa z77

Re: Certificate Problem with SCS 8.2

$
0
0

Ok good.

You have it right: Verisign certificate for initial contact, then AMT's TLS certificate will use the WebServer template.

 

SCCM 2007 requires supply in the request. SCCM 2012 requires build from AD...so it makes sense you got errors.

 

Its strange that you're seeing OTP errors, but the system is provisioned. If you provisioned these systems, the MEBX password will remain set after unprovisioning, so you might have a false positive. The AD objects may have been left over from SCCM.  Verify the creation\modify dates and make sure they match.

 

I'll try to get you a better solution for OTP issues. In the meantime, forward me the RCS log segment matching the provisioning time.  Its located on the RCS server at Program Data\Intel_Corporation\RCSServer.

Intel MB with core i3, 2gb ddr3 ram, is getting delayed to start. 15mins delay.

$
0
0

Intel MB with core i3, 2gb ddr3 ram, is getting delayed to start. Minimum of 15mins delay. As soon as the power is switched on a light glows in the MBoard but the system doesnt startup while pressing the power button. First the LAN light glows as soon as we press the power button later after 15 to 20 mins if we press the power button then the system starts.


Re: how to restore the ATM8 local MEBX password to the default “admin”

$
0
0

Hi,

 

Probably cause of this behaviour is due the fact that during this process keyboard is in default UK mode.

for azerty keyboards you will have to type " qd,in "

Re: Intel vPro Activator LiveCD @ IDF

$
0
0

I'm trying to find the vPro activator to no avail. I believe my laptop OEM disabled vPro/AMT. I clicked on the LiveCD download link, but it now points to a 404 on a car parts website.

Re: Intel vPro Activator LiveCD @ IDF

$
0
0

Andrew,

 

Activator is and old product, please use ACUWizard. You can find ACUWizard inside the Intel SCS folder which can be downloaded here.

Download Center

Re: Certificate Problem with SCS 8.2

$
0
0


Sorry for the late answer, i was away for some days.


After the weekend i tried to configure the clients again to have a fresh RCS-Log.

Surprisingly it worked on two of my clients and they are now shown with the status configured in the SCS console. Perhaps the OTP Error really needed some time to resolve.

Now i only have to get SCCM 2012 to recognize the clients to manage them.

On the other clients i found that the unprovisioning under SCCM 2007 must have gone wrong and they are partly provisioned with an old certificate from a Server that dosen't exist anymore. The ACM_Unconfigure_SCCM Task isn't working either.
Do you probably know a way to reset the Clients without logging manually into the MEBX? I fear that there are some more around.

Problems setting up Intel AMT

$
0
0

I am trying to configure Intel AMT for remote KVM access on a SuperMicro MBD-X9SCV-Q-O motherboard with an Intel Core i5-2520M processor, both of which claim to support Intel vPro.

 

The BIOS provides three settings that seem related to AMT/ME:

  1. AMT: ENABLE/disable
  2. Unconfigure AMT/ME: enable/DISABLE
  3. Set ME to disable Mode: enable/DISABLE

(the capitalized option is the one I have chosen currently, but I've tried going through all combinations with no real difference in resultacu)

 

I've tried several approaches:

 

  • Enter MEBx tool during POST using Ctrl-P:
    The tool does not prompt me for a (new) password, when it opens as I would expect and provides only the following menu structure:
    • Intel(R) ME General Settings
      • FW Update Settings
        • Local FW Update: disabled/ENABLED/password protected
      • Set PRTC
      • Power Control
        • Intel(R) ME ON in Host Sleep States: mobile: on in s0/MOBILE: ON IN S0, ME WAKE IN S4, S4-5 (AC ONLY)
        • Idle Timeout: 65535
    • Exit

    No mention of AMT anywhere or a Supported Features setting.

    The version of the tool is "Intel(R) Management Engine BIOS Extension v7.0.0053/Intel(R) ME v7.1.40.1161

    • Use the Intel ACU Wizard:
      The tool loads correctly and shows the following system information:

    Intel(R) AMT State

    Intel AMT on this system:       Supported

    System configuration state:     Not configured

    Intel(R) AMT Information:

    Release:                                7.1.40

    UUID:                                    000000000-0000-0000-0000-0025907CEF18

    Client Control Mode:               Supported

    The tool allows me to enter all configuration settings, but when I click "Configure", it fails with this error message:

    Failed to complete the Setup operation on this Intel(R) AMT device. Unknown error 1Intel(R) AMT configuration failed. The caller is unauthorized. Valid password for the default admin user not found. Verify the password. AMT Status code - Invalid AMT mode. The SKU version is not supported.

    • Attempt to provision the server form a USB drive:
      If I boot with the USB stick inserted, the MEBx tool prompts me with "Found USB Key for provisioning. Continue with Auto Provisioning (Y/N)?"
      If I answer "Y", it displays the following error message:

    Intel(R) AMT is disabled and USB data missing Manageability Feature Selection

    Network and provisioning settings will not be applied.

    Configuration Settings from the USB file were successfully applied

    Press any key to continue with system boot...

     

    Any ideas what I might be missing?

    Viewing all 1770 articles
    Browse latest View live


    <script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>