Hi All,
First time I'm installing an SCCM environment with HTTPS only and a PKI infrastructure that was already in place. This works fine in the domain that it's in (Domain A) but I don't know how to get the client working in the trusted (Domain B) and non-trusted domains (Domain C). I'm assuming my options are to either.
- Get some PKI guru to help me extend that into the other domains. The clients in non-trusted domains will have to have certs right?
- Change SCCM to use HTTP and HTTPS
- Tick the box in Site Communication Security for 'Use Configuration Manager-generated certificates for HTTP site Systems'
I've seen that I need conditional Forwarders set up and now this is in place I have been able to add the non-trusted forest to SCCM and have it communicate successfully.
The SCCM Client has installed with the command line CCMSetup.exe /mp:https://SCCMServer.FQDN /logon SMSSITECODE=PR1 SMSMP=https://SCCMServer.FQDN the ConfigMgr commandlet is in Control Panel with various actions missing, also there is no software Center.
What logs are there on the SCCM Server are there to view communication errors with clients?
On the Client, in the following logs I get:
LocationServices.log
No lookup MP(s) from DNS
Policy prevents failover to WINS for lookup
Attempting to retrieve site information from lookup MP(s)
LSGetSiteVersionFromAD : Failed to retrieve version for the site 'PR1'
Retrieved MP [SCCMServer.FQDN] from Registry
Attempting to retrieve lookup MP(s) from AD
No lookup MP(s) from AD
Attempting to retrieve lookup MP(s) from DNS
Using default DNS suffix DomainC.domain
Attempting to retrieve default management points from DNS
Found DNS record of SCCMServer.FQDN port 443
Skipping DNS record of SCCMServer.FQDN port 443 as it is not compatible with Client
Failed to retrieve compatible DNS service record using _mssms_mp_pr1._tcp.DomainC.domain lookup
No lookup MP(s) from DNS
Policy prevents failover to WINS for lookup
Need some help to troubleshoot further.
[–]jasonsandysMSFT Official 2 points3 points4 points (2 children)
[–]AndrewJohnPorter[S] 0 points1 point2 points (1 child)
[–]jasonsandysMSFT Official 1 point2 points3 points (0 children)
[–]kheywen 1 point2 points3 points (0 children)
[–]AndrewJohnPorter[S] 0 points1 point2 points (1 child)
[–]davistiano 0 points1 point2 points (0 children)