[Webinar] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 991
  • Last Modified:

SCCM - Native Mode Cert Selection Criteria

Having some issues with a few of our undeployed clients. The error in the ccmsetup.log files is stating that there are X number of certificates that match and then the one chosen fails.

I have read numerous articles and seen some peoples suggestions to change the radio button from "Fail selection and send error message" to "Select any certificate that matches". This helped a few but I read that this method has SCCM default to choosing the Cert with the longest validity period. Well the SCCM Client Authentication one isn't always the longest valid cert.

So in short, I have found that I prob need to specify certain criteria for SCCM to select the appropriate client certificate.

Now comes the problem. This microsoft technet article HERE shows the supported attribute values. However, to me, these look like AD schema values. Not all of them can be seen in the Certificate. I have searched all over the web and it seems that no one has a great write up on how to pick a pretty solid, best practice, attribute to distinguish with and how to apply that. I don't know why it wouldn't be as easy as telling SCCM to look for the certificate that came from the original template that Microsoft walks you through creating. This would be a failsafe way of SCCM picking the correct one every time.

I also saw there is a way to deploy the certs to different cert store and then having SCCM look there but for now it seems that the selection criteria is easier.

Can anyone help me out to get this problem resolved?
0
ExproDustinEstes
Asked:
ExproDustinEstes
  • 3
1 Solution
 
ExproDustinEstesAuthor Commented:
Anyone have any help on this matter?
0
 
weaze1Commented:
Hi,
We have the following settings defined for cert selection & since have no problems.
Certificate Criteria = "Subject String Contains"
then ".our.domin.com" dont forget leading dot
finally "select any certificate that matches"

If you check client logs you should see the certificate selection process listing any that don't apply & finally selecting corrct cert.
0
 
ExproDustinEstesAuthor Commented:
This didn' resolve my issue. Had some consultancy and there doesn't seem to be a decent answer for this anywhere. Hopefully 2012 adds some more decent selection functionality and compatiblity
0
 
ExproDustinEstesAuthor Commented:
Didn't fix my issue but thank you for helping.
0

Featured Post

Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now