Home

After SCCM CU 1810 update 4488598, in PKI enviroment, PXE, Windows PE cannot get auth tokens

%3CLINGO-SUB%20id%3D%22lingo-sub-452135%22%20slang%3D%22en-US%22%3EAfter%20SCCM%20CU%201810%20update%204488598%2C%20in%20PKI%20enviroment%2C%20PXE%2C%20Windows%20PE%20cannot%20get%20auth%20tokens%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-452135%22%20slang%3D%22en-US%22%3E%3CP%3EInstalled%20update%204488598%20last%20week%20and%20now%20our%20pxe%20booting%20is%20failing.%20Release%20notes%20says%20that%20this%26nbsp%3B%5BUnable%20to%20get%20the%20DP%20auth%20token%20from%20MP%5D%20issue%20was%20resolded%20on%26nbsp%3Bupdate%20%234488598%2C%20but%20it%20actualy%20appears%20after%20this%20update.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDoes%20anyone%20knows%20if%20there%20any%20workarounds%20for%20this%20problem%2C%20like%20tweaking%20IIS%20or%20so%20or%20do%20we%20just%20have%20to%20wait%20next%20sccm%20update%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPetri%20Asikainen%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-452135%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECM%20current%20branch%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-480984%22%20slang%3D%22en-US%22%3ERe%3A%20After%20SCCM%20CU%201810%20update%204488598%2C%20in%20PKI%20enviroment%2C%20PXE%2C%20Windows%20PE%20cannot%20get%20auth%20tokens%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-480984%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3ETurns%20out%20that%20this%20was%20not%20related%20to%20PKi%20auth%20or%20update%204488596.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3ESome%20content%20that%20tasksequence%20was%20using%20was%20not%20replicated%20to%20distribution%20points%2C%20even%20that%20monitoring%20content%20status%20shows%20green%20on%20all%20DPs.%20After%20redistributing%20problematic%20package%20task%20sequence%20runs%20fine.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20was%20following%20entries%20in%20smsts.log%3C%2FP%3E%3CP%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3CBR%20%2F%3E%3CTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FTIME%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
petriasikainen
New Contributor

Installed update 4488598 last week and now our pxe booting is failing. Release notes says that this [Unable to get the DP auth token from MP] issue was resolded on update #4488598, but it actualy appears after this update.

 

Does anyone knows if there any workarounds for this problem, like tweaking IIS or so or do we just have to wait next sccm update?

 

 

Regards,

 

Petri Asikainen

 

<![LOG[Retrieving DP Auth token from MP.]LOG]!><time="14:49:27.220-180" date="04-12-2019" component="TSPxe" context="" type="1" thread="1436" file="utils.cpp:6840">
<![LOG[ Setting URL = https://SKAOAS17.corpdomain.local, Ports = 80,443, CRL = false]LOG]!><time="14:49:27.220-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="utils.cpp:7062">
<![LOG[ Setting Server Certificates.]LOG]!><time="14:49:27.220-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="utils.cpp:7090">
<![LOG[ Setting Authenticator.]LOG]!><time="14:49:27.220-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="utils.cpp:7097">
<![LOG[Sending Peer Token Request]LOG]!><time="14:49:27.220-180" date="04-12-2019" component="TSPxe" context="" type="1" thread="1436" file="libsmsmessaging.cpp:4929">
<![LOG[Setting the authenticator.]LOG]!><time="14:49:27.251-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="libsmsmessaging.cpp:1527">
<![LOG[CLibSMSMessageWinHttpTransport::Send: WinHttpOpenRequest - URL: SKAOAS17.corpdomain.local:443 CCM_POST /ccm_system_AltAuth/request]LOG]!><time="14:49:27.251-180" date="04-12-2019" component="TSPxe" context="" type="1" thread="1436" file="libsmsmessaging.cpp:9946">
<![LOG[SSL - using authenticator in request.]LOG]!><time="14:49:27.251-180" date="04-12-2019" component="TSPxe" context="" type="1" thread="1436" file="libsmsmessaging.cpp:10081">
<![LOG[In SSL, but with no client cert]LOG]!><time="14:49:27.251-180" date="04-12-2019" component="TSPxe" context="" type="1" thread="1436" file="libsmsmessaging.cpp:10102">
<![LOG[In SSL, but with no media cert]LOG]!><time="14:49:27.251-180" date="04-12-2019" component="TSPxe" context="" type="1" thread="1436" file="libsmsmessaging.cpp:10108">
<![LOG[Request was successful.]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="libsmsmessaging.cpp:10303">
<![LOG[::DecompressBuffer(65536)]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="ccmzlib.cpp:739">
<![LOG[Decompression (zlib) succeeded: original size 2545, uncompressed size 6858.]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="ccmzlib.cpp:651">
<![LOG[ Setting URL = https://SKAOAS17.corpdomain.local, Ports = 80,443, CRL = false]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="utils.cpp:7062">
<![LOG[ Setting Server Certificates.]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="utils.cpp:7090">
<![LOG[ Setting Authenticator.]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="utils.cpp:7097">
<![LOG[hCertStore != NULL, HRESULT=80070490 (..\resolvesource.cpp,2086)]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="resolvesource.cpp:2086">
<![LOG[No cert available for decoding.]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="3" thread="1436" file="resolvesource.cpp:2086">
<![LOG[ParseTokenFromResponse() failed. 0x80070490]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="3" thread="1436" file="resolvesource.cpp:2099">
<![LOG[ParseTokenFromResponse (sReply.c_str(), sToken), HRESULT=80070490 (..\resolvesource.cpp,2143)]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="resolvesource.cpp:2143">
<![LOG[ParseTokenFromResponse() failed.]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="2" thread="1436" file="resolvesource.cpp:2143">
<![LOG[GetDPAuthDownloadToken() failed. 80070490]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="3" thread="1436" file="resolvesource.cpp:2147">
<![LOG[Unable to get the DP auth token from MP]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="2" thread="1436" file="utils.cpp:6843">
<![LOG[No content source files for selected task sequence.]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="1" thread="1436" file="tspolicy.cpp:3779">
<![LOG[Getting policy for CCM_SoftwareDistribution[AdvertID="C01201CC", PackageID="C0100002", ProgramID="*"]]LOG]!><time="14:49:27.282-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="tspolicy.cpp:2618">

1 Reply

 

Turns out that this was not related to PKi auth or update 4488596.

 

Some content that tasksequence was using was not replicated to distribution points, even that monitoring content status shows green on all DPs. After redistributing problematic package task sequence runs fine. 

 

There was following entries in smsts.log

<![LOG[Content location request for C0100333:1 failed. (Code 0x80040102)]LOG]!><time="14:49:29.609-180" date="04-12-2019" component="TSPxe" context="" type="3" thread="1436" file="tspolicy.cpp:2047">
<![LOG[hr, HRESULT=80040102 (..\tspolicy.cpp,2924)]LOG]!><time="14:49:29.609-180" date="04-12-2019" component="TSPxe" context="" type="0" thread="1436" file="tspolicy.cpp:2924">
<![LOG[Failed to resolve PackageID=C0100333]LOG]!><time="14:49:29.609-180" date="04-12-2019" component="TSPxe" context="" type="3" thread="1436" file="tspolicy.cpp:2924">

Related Conversations
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
28 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
2 Replies
Early preview of Microsoft Edge group policies
Sean Lyndersay in Discussions on
65 Replies
*Updated 9/3* Syncing in Microsoft Edge Preview Channels
Elliot Kirk in Articles on
205 Replies