Problems with installing Certificate Services and SCCM 2007 client installation on Windows Server 2008.
so installed windows server 2008 after installed active directory domain services, dhcp server, dns server, file services (i don't remember why), network policy , access services, print services, iis.
i wanted install sccm 2007 , required sql server, installed sql server 2008 r2. configured run domain account.
after had install active directory certificate services. started installation , followed guide:
http://technet.microsoft.com/en-us/library/cc772393(ws.10).aspx
at point able create certificate sccm 2007 installation continue (i wanted run in native mode). after stopped going through guide successful , other stuff in guide giving errors.
i installed sccm 2007. installed sp1, sp 2, r2. installed forefront security , when tried distribute computers added in dc failed. computers can seen in systems none of them have clients. clicked on 1 (pc1) , ran install client. nothing happened, went computer (pc1), navigate log file: c:\windows\system32\ccminstall\ccminstall.log
here output of file:
<![log[updated security on object c:\windows\system32\ccmsetup\.]log]!><time="19:59:46.568+-120" date="11-06-2012" component="ccmsetup" context="" type="0" thread="4204" file="ccmsetup.cpp:8849"> <![log[sending fallback status point message, stateid='100'.]log]!><time="19:59:46.568+-120" date="11-06-2012" component="ccmsetup" context="" type="1" thread="4204" file="ccmsetup.cpp:9326"> <![log[state message topictype 800 , topicid {b3119322-1521-4c96-a4c3-88206b90a50f} has been sent fsp]log]!><time="19:59:47.239+-120" date="11-06-2012" component="fspstatemessage" context="" type="1" thread="4204" file="fsputillib.cpp:730"> <![log[running user "system"]log]!><time="19:59:47.242+-120" date="11-06-2012" component="ccmsetup" context="" type="1" thread="4300" file="ccmsetup.cpp:2690"> <![log[detected 23742 mb free disk space on system drive.]log]!><time="19:59:47.242+-120" date="11-06-2012" component="ccmsetup" context="" type="1" thread="4300" file="ccmsetup.cpp:463"> <![log[detectwindowsembeddedfbwf() detecting os version]log]!><time="19:59:47.242+-120" date="11-06-2012" component="ccmsetup" context="" type="1" thread="4300" file="ccmsetup.cpp:509"> <![log[client os version 6.1, service pack version 1]log]!><time="19:59:47.242+-120" date="11-06-2012" component="ccmsetup" context="" type="1" thread="4300" file="ccmsetup.cpp:533"> <![log[client os not supported windows embedded platform]log]!><time="19:59:47.242+-120" date="11-06-2012" component="ccmsetup" context="" type="1" thread="4300" file="ccmsetup.cpp:535"> <![log[ccmsetup being restarted due administrative action. installation files reset , downloaded again.]log]!><time="19:59:47.243+-120" date="11-06-2012" component="ccmsetup" context="" type="1" thread="4300" file="ccmsetup.cpp:2774"> <![log[successfully ran bits check.]log]!><time="19:59:47.358+-120" date="11-06-2012" component="ccmsetup" context="" type="1" thread="4300" file="ccmsetup.cpp:7105"> <![log[the 'certificate store' empty in registry, using default store name 'my'.]log]!><time="19:59:47.358+-120" date="11-06-2012" component="ccmsetup" context="" type="1" thread="4300" file="ccmcert.cpp:204"> <![log[the 'certificate selection criteria' not specified, counting number of certificates present in 'my' store of 'local computer'.]log]!><time="19:59:47.360+-120" date="11-06-2012" component="ccmsetup" context="" type="0" thread="4300" file="ccmcert.cpp:3518"> <![log[1 certificate(s) found in 'my' certificate store.]log]!><time="19:59:47.360+-120" date="11-06-2012" component="ccmsetup" context="" type="0" thread="4300" file="ccmcert.cpp:3547"> <![log[only 1 certificate present in certificate store.]log]!><time="19:59:47.360+-120" date="11-06-2012" component="ccmsetup" context="" type="0" thread="4300" file="ccmcert.cpp:3555"> <![log[ssl registry key software\microsoft\ccm not found, assuming client ssl disabled.]log]!><time="19:59:47.360+-120" date="11-06-2012" component="ccmsetup" context="" type="2" thread="4300" file="ccmutillib.cpp:134"> <![log[the certificate issued 'localhost' doesn't have 'client authentication' capability.]log]!><time="19:59:47.370+-120" date="11-06-2012" component="ccmsetup" context="" type="0" thread="4300" file="ccmcert.cpp:449"> <![log[sending fallback status point message, stateid='315'.]log]!><time="19:59:47.370+-120" date="11-06-2012" component="ccmsetup" context="" type="1" thread="4300" file="ccmsetup.cpp:9326"> <![log[state message topictype 800 , topicid {90eaf712-abeb-4ffa-a2d8-d177b098bcfd} has been sent fsp]log]!><time="19:59:47.458+-120" date="11-06-2012" component="fspstatemessage" context="" type="1" thread="4300" file="fsputillib.cpp:730">
so thought problem certificate services. go far step 7: enrolling ocsp response signing certificate don't seem certificate. have changed step 6 allow enroll not autoenroll server.
also have recreated ca exchange certificate.
can please tell me should do?
correct - reason suggested posting question on security forum
hth
marcin
Windows Server > Directory Services
Comments
Post a Comment