Comments on: How To Configure PKI for Microsoft SCCM to Use HTTPS/SSL Instead of HTTP https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http Just Another SCCM Blogger Wed, 14 Aug 2024 10:36:10 +0000 hourly 1 https://wordpress.org/?v=6.7.1 By: Shaig Jihan https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-9657 Wed, 14 Aug 2024 10:36:10 +0000 http://setupconfigmgr.com/?p=27805#comment-9657 Selam Herkese,
Videodakileri harfiyen yaptim lakin
http://servername/SMS_MP/.sms_aut?MPLIST
This XML file does not appear to have any style information associated with it. The document tree is shown below.

ERROR

500 Internal Server Error

hatasi aliyorum. yardimci ola bilecek biri varmi?

SCCM 2403
SQLSRV2019

]]>
By: unkown231 https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-6691 Fri, 19 May 2023 20:30:27 +0000 http://setupconfigmgr.com/?p=27805#comment-6691 kindly let me know if any difference between trusted root certificate and sccm client certificate
deployment trusted root certificate and sccm client certificate will be the same
how to create trusted root certificate and sccm client certificate
sccm webserver certficate has to go only IIS (SCCM site role + primary site server)

]]>
By: Clive https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-6044 Wed, 28 Sep 2022 20:10:25 +0000 http://setupconfigmgr.com/?p=27805#comment-6044 Hello Justin Great tutorial. Just one question if I’m using Enhanced HTTP communication which certificate do I export the private key for OSD clients? Or do I need to go full https PKI for DPs to PXE-Boot?

]]>
By: Silver Rodriguez Lopez https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-5582 Mon, 20 Jun 2022 00:21:37 +0000 http://setupconfigmgr.com/?p=27805#comment-5582 In reply to majid.

Tengo el mismo caso, mi wsus esta en un servidor principal, cual seria el proceso. Tenemos que exportar el certificado IIS con el dns del servidor principal?? o con del servidor WSUS

]]>
By: Brian Hastings https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-5067 Mon, 07 Mar 2022 16:13:28 +0000 http://setupconfigmgr.com/?p=27805#comment-5067 One thing that is missing from this video is the requirement to add the Trusted Root CA into the, now named, Communication Security tab of the Primary Site.

Without this machines will not be able PXE boot. Took a lot of digging to find out why that wasn’t working.

Excellent video though, incredibly helpful!

]]>
By: Jake https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-4548 Mon, 08 Nov 2021 09:18:47 +0000 http://setupconfigmgr.com/?p=27805#comment-4548 Hi Justin,

I’m a little confused with the DP cert.

We have 9 DP’s, 6 of which are PXE enabled.
For the OSDCert, do I need to export one individually from each DP and them import it to each DP in the console?
I’m a bit concerned how it might screw up OSD.

Many thanks,

]]>
By: Andrew https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-3739 Thu, 05 Aug 2021 10:56:46 +0000 http://setupconfigmgr.com/?p=27805#comment-3739 Great video guide Justin. Thanks again for your series of videos!

One question, if your Site Server and SQL are on separate boxes what do you need to do cert-wise on the SQL box which is the Site Database Server and Reporting Services Point?

Thanks

]]>
By: Justin Chalfant https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-3285 Mon, 10 May 2021 10:56:25 +0000 http://setupconfigmgr.com/?p=27805#comment-3285 In reply to Craig Bonvechio.

It’s just compatibility with ConfigMgr client, not sure why this is the case, but it’s a MSFT issue with newer I assume.

]]>
By: Craig Bonvechio https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-3211 Fri, 30 Apr 2021 12:52:10 +0000 http://setupconfigmgr.com/?p=27805#comment-3211 My question is more curiosity. Why do i have to make compatibility for Server 2003 on the IIS template? All my servers, including SCCM, are at least 2016 and my clients are all Win 10. I followed the instructions just curious why we would choose this setting.

]]>
By: Justin Chalfant https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-1920 Tue, 01 Dec 2020 18:42:00 +0000 http://setupconfigmgr.com/?p=27805#comment-1920 In reply to Finn.

No, I don’t think this would work because the private key is needed during import.

]]>
By: Finn https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-1593 Tue, 27 Oct 2020 22:27:32 +0000 http://setupconfigmgr.com/?p=27805#comment-1593 Hi Justin,

My security team dont want to create a template for a cert that is exportable.
For the pfx file needed to the distribution point, could they just supply me a non exportable cert in pfx format and the password to use instead?
Of does the cert have to be exportable for it to work for OSD?

Thanks

]]>
By: Justin Chalfant https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-1161 Thu, 02 Apr 2020 13:53:25 +0000 http://setupconfigmgr.com/?p=27805#comment-1161 In reply to Lawrence.

Clients can time some time to detect the MP port change. This would happen at the client location lookup.

]]>
By: Justin Chalfant https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-1155 Thu, 02 Apr 2020 13:48:52 +0000 http://setupconfigmgr.com/?p=27805#comment-1155 In reply to Vishal Kalal.

Existing clients should detect the sites HTTPs change in the next location lookups

]]>
By: Vishal Kalal https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-1130 Wed, 11 Mar 2020 19:04:57 +0000 http://setupconfigmgr.com/?p=27805#comment-1130 Hi Justin,

great article. One question, we would like to implement IBCM and/or CMG for clients system from external to connect to SCCM Server. as part of the process when we change the SCCM from http to https, do we need to redeploy the clients tools and/or what is the effect on the clients?

]]>
By: Lawrence https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-1074 Fri, 24 Jan 2020 01:08:21 +0000 http://setupconfigmgr.com/?p=27805#comment-1074 Hi Justin, thanks for putting out these SCCM resources!

I’m initially setting this in our lab to make sure it goes smoothly when we install in production. And following your videos, I was able to deploy SCCM 1902 and upgraded to 1910 successfully. I was able to deploy agents with no issue.

And from what I gather I need to implement HTTPS/PKI in order to use MBAM. I followed your procedure which I think I setup correctly. However, my client computers stopped communicating with the SCCM server after I switch it to HTTPS.

Here’s the error I’m getting from the client’s CcmMessaging.log.

“Post to http://sccm-server.domain.com/ccm_system/request failed with 0x87d00231.”

mpcontrol.log seems to show that MP is working.

“Call to HttpSendRequestSync succeeded for port 443 with status code 200, text: OK”

TIA

]]>
By: Aaron https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-1047 Thu, 12 Dec 2019 16:02:34 +0000 http://setupconfigmgr.com/?p=27805#comment-1047 In reply to Aaron.

Finally got it after editing the host file and adding and SNI

]]>
By: Aaron https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-1045 Tue, 10 Dec 2019 14:24:42 +0000 http://setupconfigmgr.com/?p=27805#comment-1045 In reply to Justin Chalfant.

This only happens on the SCCM server itself, all other computers get the correct cert.

]]>
By: Justin Chalfant https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-1043 Sun, 08 Dec 2019 22:26:48 +0000 http://setupconfigmgr.com/?p=27805#comment-1043 In reply to Aaron.

You need to configure the correct cert in IIS

]]>
By: Aaron https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-1040 Fri, 06 Dec 2019 20:56:09 +0000 http://setupconfigmgr.com/?p=27805#comment-1040 In reply to Aaron.

Additional info, when I open a browser on the server and go to https://SCCM the browser tries to use the “ConfigMgr SQL Server Identification Certificate” instead of the one I created with your tutorial.

]]>
By: Aaron https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-1039 Fri, 06 Dec 2019 14:08:51 +0000 http://setupconfigmgr.com/?p=27805#comment-1039 I implemented you PKI setup guide but now I am getting errors in the multicast site service role. What I did notice is, on the SCCM server, when I go to https://SCCM/ I get an untrusted certificate but when I use the FQDN no certificate error. On a workstation both addresses work.

Here is the message from the multicast site service.

MCS Control Manager detected MCS is not responding to HTTP requests. The http status code and text is 12029

]]>
By: Justin Chalfant https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-1030 Thu, 28 Nov 2019 19:29:58 +0000 http://setupconfigmgr.com/?p=27805#comment-1030 In reply to wim.

Switching PKI would be out of my wheelhouse.

]]>
By: wim https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-1022 Wed, 20 Nov 2019 13:33:06 +0000 http://setupconfigmgr.com/?p=27805#comment-1022 Hi Justin. Thank you so much for putting al this info out there.

Could you please also create a guide on how to switch to another PKI in the same domain? So how to replase all certificates on the server side and on the client side in case you have a new PKI.

Thanks

]]>
By: Justin Chalfant https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-765 Thu, 18 Apr 2019 22:15:43 +0000 http://setupconfigmgr.com/?p=27805#comment-765 In reply to Sean.

Import the PFX into the personal store using certlm.msc

]]>
By: Sean https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-764 Thu, 18 Apr 2019 21:54:36 +0000 http://setupconfigmgr.com/?p=27805#comment-764 In reply to Justin Chalfant.

pfx

]]>
By: Sean https://setupconfigmgr.com/how-to-configure-pki-for-microsoft-sccm-to-use-https-ssl-instead-of-http#comment-763 Thu, 18 Apr 2019 21:49:44 +0000 http://setupconfigmgr.com/?p=27805#comment-763 In reply to Justin Chalfant.

pfx

]]>