SiteCode: 001 ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) 6/15/2017 9:50:35 GET 'HTTPS://winsccm.testlab.com/CCM_Client/ccmsetup.cab Opens a new window' RegTask: Failed to get certificate. "Check configuration settings of the CMG service is up to date" has an error of "Configuration version of the CMG service should be 2. Is only one https client or all the client has this issue? If I use a Client certificate instead, the PFX I used to create the CMG, it has a failure on two steps. MPs: ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) LocationServices 8/9/2019 11:00:29 AM 212 (0x00D4), 0 internet MP errors in the last 10 minutes, threshold is 5. MSI log file: C:\Windows\ccmsetup\Logs\client.msi.logccmsetup01/03/2019 16:38:072612 (0x0A34) FromAD: command line = SMSSITECODE=101 CCMFIRSTCERT=1 CCMCERTSTORE=MYccmsetup01/03/2019 16:38:072612 (0x0A34) Command line: "C:\Windows\ccmsetup\ccmsetup.exe" /runservice No AAD tenants information found. Uninstall of Symantec Management Agent removed most of the Trusted Certs. (0x0C94) AM 2680 (0x0A78) State message with TopicType 800 and TopicId {3B6AC48B-0F6B-4103-9784-390783104C38} has been sent to the FSPFSPStateMessage01/03/2019 16:38:072612 (0x0A34) Error 0x80004005 ccmsetup 6/16/2017 9:09:51 PM 432 (0x01B0)GetADInstallParams failed with 0x80004005 ccmsetup 6/16/2017 9:09:51 PM 432 (0x01B0)Couldn't find an MP source through AD. Error 0x80004005 ccmsetup01/03/2019 16:38:072612 (0x0A34) Failed to get directory list from 'HTTPS://site server name/CCM_Client'. 02:27 PM. OS is not Win10RS3+, ENDOK. It has been sent. I'm not great with ConfigMgr logs but ADALOperationProvider.log on the endpoint comes up with "Getting AAD (device) token" with the client ID, ResourceURL, and AccountID every so often but I don't see any errors. CCMHTTPSCERTNAME: ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) of certificates present in 'MY' store of 'Local Computer'. Can you share with us a screenshot of your: I think the issue might be resolved but I do have a question can you have overlaping boundaries and boundary groups with mutiple SCCM standalone servers. 0x87d00215, it means "Item not found". Yes server has full control in system management container. If there is any other assistance we can provide, please feel free to let us know, we will do our best to help you. Your certificate does not contain a FQDN: Completed validation of Certificate [Thumbprint 259ECEA46C3DAC33F0B5838C5B82E36B1BD872E3] issued to 'ptw01ciswb001.-> Domain XXX.XXX', Unable to find any Certificate based on Certificate Issuers, Configuration Manager (Current Branch) Site and Client Deployment, Begin searching client certificates based on Certificate Issuers, Certificate Issuer 1 [CN=domainname Root CA; OU=IS; O=domainname Co., Inc.; L=Richfield; S=MN; C=US], Certificate Issuer 2 [CN=domainname Enterprise Root 01i001], Certificate Issuer 3 [CN=domainname Enterprise Root 01i002; O=domainname Inc.; L=Richfield; S=Minnesota; C=US], Based on Certificate Issuer 'domainname Enterprise Root 01i002' found Certificate [Thumbprint E570B76528BE092F69297AEFB668FDC80DD28CBB] issued to 'PTW01CISWB001. The SCCM client installation fails with below error shown in ccmsetup.log file. HTTPS://winsccm.testlab.com/ccm_system/request, HTTPS://winsccm.testlab.com/CCM_Client/ccmsetup.cab. 2,Please make sure you have added the boundary to your boundary groups and associated your DPs and MPs to the boundary groups. Finding certificate by issuer chain returned error 80092004ccmsetup01/03/2019 16:38:072612 (0x0A34) Thank you very much for your feedback and sharing. not exist. Actually you're right, I get the same error when using the Go http client to make the request so Chrome knows the CA but not Go so it looks like the CA is not loaded properly as you said. For example we have one SCCM 2012 that just does Windows 7 PCs and we built another one that will just be doing Windows 10. Uninstall Symantec Management Agent, refresh client in Microsoft Endpoint Configuration Manager console and the client immediately goes offline. Failed to connect to machine policy namespace. Client OS Version 6.2 Service Pack 0.0 ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) 3. Get our latest recommendations, advice and offers direct to your inbox. Ignoring MP error during post-rotation flush period of 20 seconds. For more information, see SmsAdminUI.log. Deployment status for the update Group/collection was in unknown. force to run a cycle from the client workstation and it will say compliant. The 'Certificate Selection Criteria' was not specified, counting number FromAD: FSP = SCCM-Server-Dan.cork.localccmsetup01/03/2019 16:38:072612 (0x0A34) CCMSETUP bootstrap from Internet: 0 AllowFallbackToUnprotectedDP = 0 Failed to get DP locations as the expected version from MP 'HTTPS://VRPSCCMPR01.ad'. If it's Windows 11 22H2, please upgrade to the latest SCCM version 2207 or 2211 to have a try. The 'Certificate Selection Criteria' was not specified, counting number Launch from folder C:\Windows\ccmsetup\ccmsetup01/03/2019 16:38:071124 (0x0464) [CCMHTTP] ERROR INFO: StatusCode=200 StatusText=ccmsetup01/03/2019 16:38:072612 (0x0A34) MPs:ccmsetup01/03/2019 16:38:072612 (0x0A34) However a distribution point could not be located. CCMCERTISSUERS: CN=SCCM-Server-Dan.cork.localccmsetup01/03/2019 16:38:072612 (0x0A34) IsSslClientAuthEnabled - Determining provisioning mode state failed with 80070002. windows 11 deplyment is failed via sccm (sccm version:2111) and getting this error "Getupdate -failed to get targated update error= 0x87d00215 in updatedeployment.log. The text was updated successfully, but these errors were encountered: This is not an grpc issue. So, first interaction here, so if more is needed, or if I am doing something wrong, I am open to suggestions or guidance with forum ettiquette. I had installed adminconsole.msi which was failed during installation. Shutdown has been requested ccmsetup 6/15/2017 9:50:24 PM 4244 (0x1094) Source \\WINSCCM.TESTLAB.COM\SMSClient is inaccessible (67) ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) \\WINSCCM.TESTLAB.COM\SMSClient ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) Begin to select client certificate ccmsetup 6/15/2017 12:24:47 AM It may help others who have similar issue with you. And what are the pros and cons vs cloud based? I also know that there are a few switches I can try during installation: ccmsetup.exe /UsePKICert /NoCRLCheck CCMFIRSTCERT=1 SMSSITECODE=P01 CCMCERTID=MY;D29211C57353FB9FB8944AFF6C14770D9AD4D58C. Checking Write Filter Status. Oct 01 2020 This is the first site we have seen this issue on, but it is also the first 1806 environment in HTTPS only. I followed the instructions athttps://docs.microsoft.com/en-us/sccm/core/clients/manage/cmg/setup-cloud-management-gatewaywhich were pretty good and easy to follow. The same settings worked for windows 10 machine but I am not sure why this is not working for windows 7 system. ccmsetup.exe /SMSSITECODE = P01 Cause: The above error indicates that a new version of client installation source was required. CMPInfoFromADCache requests are throttled for 00:59:59ccmsetup01/03/2019 16:38:072612 (0x0A34) You can post now and register later. The MP name retrieved is 'SCCM-Server-Dan.cork.local' with version '8740' and capabilities ''ccmsetup01/03/2019 I know the certificate is valid, verified by running a simple Go http server: I couldn't really find any doc showing how to setup the client properly apart from https://chromium.googlesource.com/external/github.com/grpc/grpc-go/+show/refs/heads/master/Documentation/grpc-auth-support.md. Hopefully, you have as simple a fix. ccmsetup01/03/2019 16:38:072612 (0x0A34) I am running into almost the exact same issues down to a T. @pembertjYes! Error 0x87d00282. We are working every day to make sure our community is one of the best. Error 0x87d00215ccmsetup01/03/2019 16:38:072612 (0x0A34) Find out more about the Microsoft MVP Award Program. I did. Detected 52492 MB free disk space on system drive. I reinstall the SCCM agent and this issue still occurs. Certificate Issuer 1 [CN=SCCM-Server-Dan.cork.local]ccmsetup01/03/2019 16:38:072612 (0x0A34) Defaulting to state of 63.ccmsetup01/03/2019 16:38:072612 (0x0A34) Sending Fallback Status Point message to 'SCCM-Server-Dan.cork.local', STATEID='100'. Best practices and the latest news on Microsoft FastTrack, The employee experience platform to help people thrive at work, Expand your Azure partner-to-partner network, Bringing IT Pros together through In-Person & Virtual events. Finished checking Alternate Network ConfigurationLocationServices01/03/2019 16:38:072612 (0x0A34) I would try adding the client IP Subnet to your boundary list and then maybe the client will see the "source" to download all of the files it needs. ', Based on Certificate Issuer 'domainname Enterprise Root 01i001' found Certificate [Thumbprint 6A5230A9641239E4489CA42559685F7358C8A0BB] issued to 'PTW01CISWB001. GetDPLocations failed with error 0x87d00280 ccmsetup 6/15/2017 12:24:47 AM 2680 (0x0A78) This is what I am getting now. Failed to get client certificate for transportation. ccmsetup01/03/2019 16:38:072612 (0x0A34) Uninstall Symantec Management Agent, refresh client in Microsoft Endpoint Configuration Manager console and the client immediately goes offline. Failed to get client certificate for transportation. LocationServices 8/9/2019 10:44:28 AM 9416 (0x24C8), 1 internet MP errors in the last 10 minutes, threshold is 5. CCMCERTID (Tells SCCM to use a specific certificate based on thumbprint). I have since tried the suggestion above setting: SMSSITECODE=101 CCMFIRSTCERT=1 CCMCERTSTORE=MY, Running on platform X64ccmsetup01/03/2019 16:38:071124 (0x0464) Source List: ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) https://www.prajwaldesai.com/sccm-1810-upgrade-guide - Maybe helpful. ', Completed validation of Certificate [Thumbprint BC0B3996CCDBED300F78A7A9A1EEFC32BCEA8EAE] issued to 'PTW01CISWB001. There was an error trying to send your message. Selected client certificate is not trusted by the CMG service. Have a question about this project? A possible reason for this failure is the CMG connection point failed to forward the message to the management point. Welcome to the Snap! LocationServices 8/9/2019 10:44:28 AM 9416 (0x24C8), 0 internet MP errors in the last 10 minutes, threshold is 5. ConfigMgr Client installation issues in HTTPS environment Updated security on object C:\Windows\ccmsetup\. Finding certificate by issuer chain returned error 80092004ccmsetup01/03/2019 16:38:072612 (0x0A34) ccmsetup01/03/2019 16:38:072612 (0x0A34) Status code is '401' and status description is 'CMGConnector_Unauthorized'. SslState value: 224ccmsetup01/03/2019 16:38:072612 (0x0A34) I used a third party certificate from a public and globally trusted certificate provider for the CMG server authentication certificate. LocationServices01/03/2019 16:38:072612 (0x0A34) I added a "LocalAdmin" -- but didn't set the type to admin. Updated security on object C:\Windows\ccmsetup\cache\. If you go to this location in the SCCM Console: Administration\Overview\Site Configuration\Sites. Folder 'Microsoft\Microsoft\Configuration Manager' not found. 2,Please make sure you have added the boundary to your boundary groups and associated your DPs and MPs to the boundary groups. ccmsetup01/03/2019 16:38:072612 (0x0A34) ccmsetup01/03/2019 16:38:071124 (0x0464) Ccmsetup command line: "C:\Windows\ccmsetup\ccmsetup.exe" /runservice /ignoreskipupgrade /config:MobileClient.tcfccmsetup01/03/2019 16:38:072612 (0x0A34) On the status in monitoring window of the SCCM console, the Distribution point says that i have successfully distributed content on the remote DP but there is an error saying Failed to create virtual directory? Site server properties are set SOLVED FAILED TO GET TARGETED UPDATE ERROR = 0X87D00215. Failed to get CMG service metadata. Client Push SCCM 1710 error 0x87d00215 Completed searching client certificates based on Certificate Issuers I just hope it doesn't take you a month or two to track it down like it took me! Start machine policy retrieval in configuration manager client control, WUserver is pointing in the sccm SUP and i have run the machine policy retrieval. CCMPKICERTOPTIONS: 1ccmsetup01/03/2019 16:38:072612 (0x0A34) May we know the current status of the question? Ok cool, so we know its not https then, If you look to the bottom of the log. OS is not Win10RS3+, ENDOK. I am currently testing software update deployment on my setup and upon checking to my testing client computer, the computer won't update. Performing AD query: An integrated solution for for managing large groups of personal computers and servers. ccmsetup 6/15/2017 Error 0x87d00215 Unable to retrieve AD site membership CCMSETUP bootstrap from Internet: 0 DHCP entry points already initialized. Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread. Determining source location ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) (0x0C94) I have a new built SCCM(MP,DP,SUP)(forestA), I have a remote DP on the other forest(forestB). Still having a problem with this after upgrading SCCM Manager to 1810. You may correct me but theDistribution Manager requires that IIS base components be installed on the local Configuration Manager Site Server in order to create the virtual directory? Completed searching client certificates based on Certificate Issuersccmsetup01/03/2019 16:38:072612 (0x0A34) Couldn't find DP locations. not exist. hint to find the issue ). Sorry to bother you with that. ccmsetup 6/15/2017 9:50:35 PM 2320 (0x0910) CcmSetup failed with error code 0x87d00454, Configuration Manager (Current Branch) Site and Client Deployment. 6/15/2017 12:24:47 AM 2680 (0x0A78) CCMFIRSTCERT (Tells SCCM to use the certificate with the longest validity period). I have created sample windows 10 update and deploy that to my testing collection. Years ago, we had put an IIS redirect to direct users to a "prettier" CNAME for the Application Catalog's URL.Once we removed the Application Catalog roles in favor of using only Software Center, we removed the IIS redirect and our CMG started working great. Possible cause can be the distribution Manager requires that IIS base components be installed on the local Configuration Manager Site Server in order to create the virtual directory.