Home

After SCCM CU 1810 update 4488598, in PKI enviroment, PXE, Windows PE cannot get auth tokens

%3CLINGO-SUB%20id%3D%22lingo-sub-452135%22%20slang%3D%22en-US%22%3EAfter%20SCCM%20CU%201810%20update%204488598%2C%20in%20PKI%20enviroment%2C%20PXE%2C%20Windows%20PE%20cannot%20get%20auth%20tokens%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-452135%22%20slang%3D%22en-US%22%3E%3CP%3EInstalled%20update%204488598%20last%20week%20and%20now%20our%20pxe%20booting%20is%20failing.%20Release%20notes%20says%20that%20this%26nbsp%3B%5BUnable%20to%20get%20the%20DP%20auth%20token%20from%20MP%5D%20issue%20was%20resolded%20on%26nbsp%3Bupdate%20%234488598%2C%20but%20it%20actualy%20appears%20after%20this%20update.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDoes%20anyone%20knows%20if%20there%20any%20workarounds%20for%20this%20problem%2C%20like%20tweaking%20IIS%20or%20so%20or%20do%20we%20just%20have%20to%20wait%20next%20sccm%20update%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPetri%20Asikainen%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-452135%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECM%20current%20branch%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-480984%22%20slang%3D%22en-US%22%3ERe%3A%20After%20SCCM%20CU%201810%20update%204488598%2C%20in%20PKI%20enviroment%2C%20PXE%2C%20Windows%20PE%20cannot%20get%20auth%20tokens%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-480984%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3ETurns%20out%20that%20this%20was%20not%20related%20to%20PKi%20auth%20or%20update%204488596.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3ESome%20content%20that%20tasksequence%20was%20using%20was%20not%20replicated%20to%20distribution%20points%2C%20even%20that%20monitoring%20content%20status%20shows%20green%20on%20all%20DPs.%20After%20redistributing%20problematic%20package%20task%20sequence%20runs%20fine.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20was%20following%20entries%20in%20smsts.log%3C%2FP%3E%3CP%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
petriasikainen
New Contributor

Installed update 4488598 last week and now our pxe booting is failing. Release notes says that this [Unable to get the DP auth token from MP] issue was resolded on update #4488598, but it actualy appears after this update.

 

Does anyone knows if there any workarounds for this problem, like tweaking IIS or so or do we just have to wait next sccm update?

 

 

Regards,

 

Petri Asikainen

 

<![LOG[Retrieving DP Auth token from MP.]LOG]!><time="14:49:27.220-180" date="04-12-2019" component="TSPxe" context="" type="1" thread="1436" file="utils.cpp:6840">
<![LOG[ Setting URL = https://SKAOAS17.corpdomain.local, Ports = 80,443, CRL = false]LOG]!><time="14:49:27.220-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="utils.cpp:7062">
<![LOG[ Setting Server Certificates.]LOG]!><time="14:49:27.220-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="utils.cpp:7090">
<![LOG[ Setting Authenticator.]LOG]!><time="14:49:27.220-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="utils.cpp:7097">
<![LOG[Sending Peer Token Request]LOG]!><time="14:49:27.220-180" date="04-12-2019" component="TSPxe" context="" type="1" thread="1436" file="libsmsmessaging.cpp:4929">
<![LOG[Setting the authenticator.]LOG]!><time="14:49:27.251-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="libsmsmessaging.cpp:1527">
<![LOG[CLibSMSMessageWinHttpTransport::Send: WinHttpOpenRequest - URL: SKAOAS17.corpdomain.local:443 CCM_POST /ccm_system_AltAuth/request]LOG]!><time="14:49:27.251-180" date="04-12-2019" component="TSPxe" context="" type="1" thread="1436" file="libsmsmessaging.cpp:9946">
<![LOG[SSL - using authenticator in request.]LOG]!><time="14:49:27.251-180" date="04-12-2019" component="TSPxe" context="" type="1" thread="1436" file="libsmsmessaging.cpp:10081">
<![LOG[In SSL, but with no client cert]LOG]!><time="14:49:27.251-180" date="04-12-2019" component="TSPxe" context="" type="1" thread="1436" file="libsmsmessaging.cpp:10102">
<![LOG[In SSL, but with no media cert]LOG]!><time="14:49:27.251-180" date="04-12-2019" component="TSPxe" context="" type="1" thread="1436" file="libsmsmessaging.cpp:10108">
<![LOG[Request was successful.]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="libsmsmessaging.cpp:10303">
<![LOG[::DecompressBuffer(65536)]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="ccmzlib.cpp:739">
<![LOG[Decompression (zlib) succeeded: original size 2545, uncompressed size 6858.]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="ccmzlib.cpp:651">
<![LOG[ Setting URL = https://SKAOAS17.corpdomain.local, Ports = 80,443, CRL = false]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="utils.cpp:7062">
<![LOG[ Setting Server Certificates.]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="utils.cpp:7090">
<![LOG[ Setting Authenticator.]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="utils.cpp:7097">
<![LOG[hCertStore != NULL, HRESULT=80070490 (..\resolvesource.cpp,2086)]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="resolvesource.cpp:2086">
<![LOG[No cert available for decoding.]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="3" thread="1436" file="resolvesource.cpp:2086">
<![LOG[ParseTokenFromResponse() failed. 0x80070490]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="3" thread="1436" file="resolvesource.cpp:2099">
<![LOG[ParseTokenFromResponse (sReply.c_str(), sToken), HRESULT=80070490 (..\resolvesource.cpp,2143)]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="resolvesource.cpp:2143">
<![LOG[ParseTokenFromResponse() failed.]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="2" thread="1436" file="resolvesource.cpp:2143">
<![LOG[GetDPAuthDownloadToken() failed. 80070490]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="3" thread="1436" file="resolvesource.cpp:2147">
<![LOG[Unable to get the DP auth token from MP]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="2" thread="1436" file="utils.cpp:6843">
<![LOG[No content source files for selected task sequence.]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="1" thread="1436" file="tspolicy.cpp:3779">
<![LOG[Getting policy for CCM_SoftwareDistribution[AdvertID="C01201CC", PackageID="C0100002", ProgramID="*"]]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="tspolicy.cpp:2618">

1 Reply

 

Turns out that this was not related to PKi auth or update 4488596.

 

Some content that tasksequence was using was not replicated to distribution points, even that monitoring content status shows green on all DPs. After redistributing problematic package task sequence runs fine. 

 

There was following entries in smsts.log

<![LOG[Content location request for C0100333:1 failed. (Code 0x80040102)]LOG]!><time="14:49:29.609-180" date="04-12-2019" component="TSPxe" context="" type="3" thread="1436" file="tspolicy.cpp:2047">
<![LOG[hr, HRESULT=80040102 (..\tspolicy.cpp,2924)]LOG]!><time="14:49:29.609-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="tspolicy.cpp:2924">
<![LOG[Failed to resolve PackageID=C0100333]LOG]!><time="14:49:29.609-180" date="04-12-2019" component="TSPxe" context="" type="3" thread="1436" file="tspolicy.cpp:2924">

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies