Get our latest recommendations, advice and offers direct to your inbox. ccmsetup 6/15/2017 9:50:35 PM 2320 (0x0910) Failed to get client certificate for transportation. Correct server? Spice (1) flag Report. Command line parameters for ccmsetup have been specified. If it's Windows 11 22H2, please upgrade to the latest SCCM version 2207 or 2211 to have a try. Ok cool, so we know its not https then, If you look to the bottom of the log. The management point returned the following error: 'Unauthorized'. Client installation fails with error GetSSLCertificateContext failed with error 0x87d00281 8592413b-911f-400f-a94e-bd9e619ff91e archived TechNet Products IT Resources Downloads Training Support Products Windows Windows Server System Center Microsoft Edge Office Office 365 Exchange Server SQL Server SharePoint Products Skype for Business Failed to get site version from AD with error 0x87d00215 ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) Failed to get DP locations as the expected version from MP 'http://server1.techuisitive.com'. When looking on the client in control panel I see it has no certificate and the connection type is unknown 2. It is obvious that later versions/fixes of configuration manager have not solved this problem. Do you have enough disk space on the remote DP? 'ccmsetup01/03/2019 16:38:072612 (0x0A34) 6/15/2017 9:50:35 PM 3220 (0x0C94) ', Completed validation of Certificate [Thumbprint E570B76528BE092F69297AEFB668FDC80DD28CBB] issued to 'PTW01CISWB001. Get the device ID using "dsregcmd /status" to verify against your AAD information. I had also faced issue in upgrading SCCM Site server from 1806 to 1810 but not the same error which you received , however I checked above 2 log files and got the root cause. 01:44 PM. I realized I messed up when I went to rejoin the domain I have a system with me which has dual boot os installed. CCMHTTPSPORT: 443ccmsetup01/03/2019 16:38:072612 (0x0A34) Thank you for your message. ccmsetup01/03/2019 16:38:072612 (0x0A34) Retry time: 10 minute(s)ccmsetup01/03/2019 16:38:072612 (0x0A34) ', Based on Certificate Issuer 'domainname Enterprise Root 01i001' found Certificate [Thumbprint 6A5230A9641239E4489CA42559685F7358C8A0BB] issued to 'PTW01CISWB001. Completed searching client certificates based on Certificate Issuersccmsetup01/03/2019 16:38:072612 (0x0A34) ', Completed searching client certificates based on Certificate Issuers, instance of CCM_ServiceHost_CertRetrieval_Status. Error (87D00215) ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) 6/15/2017 9:50:35 08:15 AM I have created sample windows 10 update and deploy that to my testing collection. not exist. It is unclear if the problem is 1806 related or just a one-off for this client. You can post now and register later. Updated security on object C:\Windows\ccmsetup\. IsSslClientAuthEnabled - Determining provisioning mode state failed with 80070002. Failed to connect to machine policy namespace. SOLVED FAILED TO GET TARGETED UPDATE ERROR = 0X87D00215. Error 0x80004005 ccmsetup 6/16/2017 9:09:51 PM 432 (0x01B0)GetADInstallParams failed with 0x80004005 ccmsetup 6/16/2017 9:09:51 PM 432 (0x01B0)Couldn't find an MP source through AD. ", The step "Testing the CMG channel for management point: 'thenameoftheMP'" gives me a new error, "Failed to refresh MP location. Command line parameters for ccmsetup have been specified. - edited Looking at registry settings from other clients that use HTTPS and are working I can see the following Dword. None ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) The MP name retrieved is 'SCCM-Server-Dan.cork.local' with version '8740' and capabilities ''ccmsetup01/03/2019 \\winsccm.testlab.com\SMSClient ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) Just in time for "work from home". Successfully refresh bootstrap information from AD. It did not work and still getting same error. A possible reason for this failure is the CMG connection point failed to forward the message to the management point. Failed to get client version for sending state messages. Waiting for retry. More info about Internet Explorer and Microsoft Edge. Failed to read assigned site code from registry. [CCMHTTP] ERROR: URL=https://SCCM-Server-Dan.cork.local/ccm_system/request, Port=0, Options=63, Code=0, Text=CCM_E_NO_CLIENT_PKI_CERTccmsetup01/03/2019 16:38:072612 (0x0A34) I had installed adminconsole.msi which was failed during installation. Normally, ccmsetup service will stop automatically after the client installed successfully or completely failed, in your situation, the installation failed because of the client package is not distributed to DP, so it will keep retrying for 7 days unless we stop it manually. This topic has been locked by an administrator and is no longer open for commenting. GET 'HTTPS://winsccm.testlab.com/CCM_Client/ccmsetup.cab Opens a new window' Client OS Version 6.2 Service Pack 0.0 ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) OperationalXml '5.00.8740.1002636380443CN=SCCM-Server-Dan.cork.local11308202F7308201DFA0030201020210275CC6F4E67C3F91404EE5225EA21AE0300D06092A864886F70D01010B05003016311430120603550403130B53697465205365727665723020170D3139303132373139333132365A180F32313139303130343139333132365A3016311430120603550403130B536974652053657276657230820122300D06092A864886F70D01010105000382010F003082010A0282010100E26F32B3337690D603E7A2CEB9BA5E1ADFDB76AA7334A0C4206DE52DC8DD5B2EF7D0FA60D4215CE8E8983034AC592F25E9DFFC984D84C85F32638A013F3FE9E6537F0493BE931967887AAF806DB26CD45C87EAAEBAE2EDD30E4FD65B5768C93D9D08A8C196AD12F7621B7848F5CBC808834852C71290EA1C0B4333C6A7FA546952252536AD71DA04FFF1BDA7C1CDEDC0746BD3E05CC48CF5BE35260B6C6F2A89AE2CD14EBE72FE8FC032F5714B5D327381C57F8A761059BBF2426AEC1880F9A25FB860DB8D43A2BEA39B79A50109E32A683C9142DD7008E10C20BD54327BE60650B96F516EDC302FE9E71046733740EE2DCA5D2EBFFCD71218555AE64EAEE8250203010001A33F303D30250603551D11041E301C821A5343434D2D5365727665722D44616E2E636F726B2E6C6F63616C30140603551D25040D300B06092B060104018237650B300D06092A864886F70D01010B050003820101009FC359F58482A71001692B643EB9853523BFA47D0A25A16772A2E682A4A89929747F618799964778A1020E5253A25A20A6B8D448292934F6C4BA425F178B47F7F04A7F8725FF3DB3C73793034C51D67CE13B0CE8F3FAF9D4EB3BD67E72D2CC79504182ED78A480F27D097A8EFCE2FD2B527D23AAAC9F49FEE84DDE78E43A6F315318426358C37F4ED93969AEFB370ECFEE446A33EE1628490AE270EE82EA48F282C7408907A86CCE4DB1703FFD8F55B894C1B1FA90C9646F286C22E6001C76647ED984E39410F98D4DB7AB9CE7323678549C27D280BEFF20DE0121F28184422EFB304AE8A77332D12179C0C94BF4F2F5DA09E1DAF6796BEABB56BE688138340F101 0x8004100eccmsetup01/03/2019 16:38:072612 (0x0A34) The 'Certificate Selection Criteria' was not specified, counting number Please try again later. CCMHTTPSCERTNAME: ccmsetup01/03/2019 16:38:072612 (0x0A34) HTTPS://SCCM-Server-Dan.cork.localccmsetup01/03/2019 16:38:072612 (0x0A34) Site server properties are set If there is any other assistance we can provide, please feel free to let us know, we will do our best to help you. MapNLMCostDataToCCMCost() returning Cost 0x1ccmsetup01/03/2019 16:38:072612 (0x0A34) (0x0C94) I just completed a new SCCM Primary Site installation for a customer who has a requirement of HTTPS communication only. Error 0x87d00215ccmsetup01/03/2019 16:38:072612 (0x0A34) The same settings worked for windows 10 machine but I am not sure why this is not working for windows 7 system. ccmsetup 6/15/2017 12:24:47 AM 2680 (0x0A78) Begin to select client certificate ccmsetup 6/15/2017 12:24:47 AM After LastPass's breaches, my boss is looking into trying an on-prem password manager. MANAGEDINSTALLER: 0ccmsetup01/03/2019 16:38:072612 (0x0A34) Could you share the screenshot of the deployment status on your SUG and the WUAHandler.log file on the clients? Client re-install error Unable to find any Certificate based on Certificate Issuers Failed to get client certificate for transportation. I wanted to know if i can remote access this machine and switch between os or while rebooting the system I can select the specific os. ccmsetup 6/16/2017 9:09:51 PM 432 (0x01B0)Begin checking Alternate Network Configuration ccmsetup 6/16/2017 9:09:51 PM 432 (0x01B0)Finished checking Alternate Network Configuration ccmsetup 6/16/2017 9:09:51 PM 432 (0x01B0)Current AD forest name is testlab.com, domain name is testlab.com ccmsetup 6/16/2017 9:09:51 PM 432 (0x01B0)Domain joined client is in Intranet ccmsetup 6/16/2017 9:09:51 PM 432 (0x01B0)Current AD site of machine is Default-First-Site-Name ccmsetup 6/16/2017 9:09:51 PM 432 (0x01B0)Attempting to query AD for assigned site code ccmsetup 6/16/2017 9:09:51 PM 432 (0x01B0)Performing AD query: '(&(ObjectCategory=MSSMSRoamingBoundaryRange)(|(&(MSSMSRangedIPLow<=3232240486)(MSSMSRangedIPHigh>=3232240486))))' ccmsetup 6/16/2017 9:09:51 PM 432 (0x01B0)Performing AD query: '(&(ObjectCategory=mSSMSSite)(|(mSSMSRoamingBoundaries=192.168.19.0)(mSSMSRoamingBoundaries=Default-First-Site-Name)))' ccmsetup 6/16/2017 9:09:51 PM 432 (0x01B0)Failed to get assigned site from AD. CCMHTTPSPORT="443" CCMHTTPSSTATE="192" CCMFIRSTCERT="1" ccmsetup https://social.technet.microsoft.com/Forums/en-US/f660d3c6-72a6-4ad6-80e3-2b6a5583341a/clients-not-r Re: SCCM Software Updates not installing to endpoints, Site and site system prerequisites for Configuration Manager. No MPs were specified from commandline or the mobileclient.tcf. ccmsetup 6/15/2017 Thanks for your time. '(&(ObjectCategory=mSSMSManagementPoint)(mSSMSDefaultMP=TRUE)(mSSMSSiteCode=001))' If you have any questions in future, we welcome you to post in Microsoft Q&A forum again. No registry and it is saying that the client computer is compliant. Our community has been around for many years and pride ourselves on offering unbiased, critical discussion among people of all different backgrounds. FSP: ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) Looking at the logs I can see that the switches have been accepted and the client should be doing the right thing, but unfortunately, it still presents the same errors. State message with TopicType 800 and TopicId {ADEBF393-E5B7-487D-80B8-96EB1AFB7D59} has been sent to the FSPFSPStateMessage01/03/2019 16:38:072612 (0x0A34) The same certificate loads perfectly fine with the Go http server as per the screenshot above so it looks like the certificate is correct. but if I scroll up enough in the log I do find an error "Failed to get client certificate for transportation. Verify that IIS base components are installed on the local Configuration Manager Site Server, and IIS Web Services are installed on the Distribution Point Server. Service Pack (0.0). Running as user "SYSTEM"ccmsetup01/03/2019 16:38:072612 (0x0A34) My CMG connection point is installed on a 2012 R2 non-Azure AD Hybrid Joined server slated for upgrade to 2019 later this year. SCCM Software Updates not installing to endpoints, that SCCM site server computer account are in the Local. And what are the pros and cons vs cloud based? This setting is correct and has been for quite some time so I know that the client is ignoring this, or not getting the correct information. What version of Windows 11 you are deploying, Windows 11 21H2 or 22h2? The management point returned the following error: 'Unauthorized'. FromAD: command line = SMSSITECODE=101 CCMFIRSTCERT=1 CCMCERTSTORE=MYccmsetup01/03/2019 16:38:072612 (0x0A34) Error 0x87d00282. Thank you very much for your feedback and sharing. I used a third party certificate from a public and globally trusted certificate provider for the CMG server authentication certificate. Hi Team, Command line: "C:\Windows\ccmsetup\ccmsetup.exe" /runservice Detected 52492 MB free disk space on system drive. [DESKTOP-TM866AV] Running on 'Microsoft Windows 10 Pro' (10.0.10240). Yes server has full control in system management container. Level 9, 440 Collins Street Melbourne, VIC 3000ABN: 47 420 502 955, document.write(new Date().getFullYear()); Endpoint Focus Trust. Searching for DP locations from MP(s)ccmsetup01/03/2019 16:38:072612 (0x0A34) (0x0C94) It may help others who have similar issue with you. Checking the installed software update on the client computer it is not installed but it is still says compliant. Updating MDM_ConfigSetting.ClientDeploymentErrorCode with value 0ccmsetup01/03/2019 16:38:072612 (0x0A34) CcmSetup version: 5.0.8412.1004 ccmsetup 6/15/2017 9:50:35 PM 2320 (0x0910) Uninstall Symantec Management Agent, refresh client in Microsoft Endpoint Configuration Manager console and the client immediately goes offline. ccmsetup 6/16/2017 9:09:51 PM 432 (0x01B0) ccmsetup 6/16/2017 9:09:51 PM 432 (0x01B0)CcmSetup failed with error code 0x80004005 ccmsetup 6/16/2017 9:09:51 PM 432 (0x01B0). (10.0.14393). No registry lookup for command line parameters is required. Failed to get client version for sending state messages. Can you share with us a screenshot of your: I think the issue might be resolved but I do have a question can you have overlaping boundaries and boundary groups with mutiple SCCM standalone servers. MapNLMCostDataToCCMCost() returning Cost 0x1 ccmsetup 6/15/2017 12:24:47 AM 2680 (0x0A78) Error 0x8004100e ccmsetup 6/15/2017 12:24:47 AM 4480 (0x1180) Failed to get DP locations as the expected version from MP 'HTTPS://SCCM-Server-Dan.cork.local'. Only one MP HTTPS://SCCM-Server-Dan.cork.local is specified. SslState value: 224ccmsetup01/03/2019 16:38:072612 (0x0A34) conn, err := grpc.Dial(address, grpc.WithTransportCredentials(credentials.NewClientTLSFromCert(nil, ""))). HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CCM\Security\Select First Certificate = 1. Folder 'Microsoft\Microsoft\Configuration Manager' not found. Task does not exist. If you have an account, sign in now to post with your account. Failed to connect to policy namespace. ', Based on Certificate Issuer 'domainname Enterprise Root 01i002' found Certificate [Thumbprint B2400DEC508EBAACE84613AE21A33F4F59683BD0] issued to 'PTW01CISWB001. 04:25 AM, That's correct. Certificate Issuer 1 [CN=SCCM-Server-Dan.cork.local]ccmsetup01/03/2019 16:38:072612 (0x0A34) If the response is helpful, please click "Accept Answer" and upvote it. Error 0x87d00282 "go to client computer communication and set the "Action to take if multiple certificates match criteria" to "Select the certificate with the longest validity period", has been set, a long time ago, I also tried turning it off for a few hours and back on, no difference. 0x8004100e Folder 'Microsoft\Microsoft\Configuration Manager' not found. Installation files will be reset and downloaded again. @Kirk FrancisDid you ever get an answer to this? CcmSetup failed with error code 0x80004004 ccmsetup 6/15/2017 9:50:24 PM 4140 (0x102C) Defaulting to state of 63.ccmsetup01/03/2019 16:38:072612 (0x0A34) Completed searching client certificates based on Certificate Issuersccmsetup01/03/2019 16:38:072612 (0x0A34) Join the conversation. Launch from folder C:\Windows\ccmsetup\ccmsetup01/03/2019 16:38:071124 (0x0464) Conn.resetTransport failed to create client transport: connection error: desc = "transport: x509: certificate signed by unknown authority" with certificate generated by Let's encrypt, https://chromium.googlesource.com/external/github.com/grpc/grpc-go/+show/refs/heads/master/Documentation/grpc-auth-support.md, Error transport: x509: certificate signed by unknown authority. Deployment status for the update Group/collection was in unknown. ccmsetup01/03/2019 16:38:072612 (0x0A34) CcmSetup version: 5.0.8740.1024ccmsetup01/03/2019 16:38:071124 (0x0464) Failed to find DP locations from MP 'HTTPS://winsccm.testlab.com Opens a new window' with error 0x87d00280, status code 200. Please find the below Prajwal Desai link to upgrade SCCM 1810. https://www.prajwaldesai.com/sccm-1810-upgrade-guide - Maybe helpful. Failed to get client certificate for transportation. Error: Conn.resetTransport failed to create client transport: connection error: desc = "transport: x509: certificate signed by unknown authority". 0x87d00215, it means "Item not found". SOLVED Application installing but failing on any detection method added, uninstall works fine with no errors Welcome to the Snap! This is the first site we have seen this issue on, but it is also the first 1806 environment in HTTPS only. Yes i have enough disk space and no maintenance windows on the device collection. If I use the Cloud management Gateway connection analyzer with an Azure AD user sign in, it fails on the "Testing the CMG channel for management point: 'thenameoftheMP'" step with the following error: Failed to get ConfigMgr token with Azure AD token. Failed to send status 100. CCMPKICERTOPTIONS: 1ccmsetup01/03/2019 16:38:072612 (0x0A34) IsSslClientAuthEnabled - Determining provisioning mode state failed with 80070002. tnmff@microsoft.com. Source List:ccmsetup01/03/2019 16:38:072612 (0x0A34) Product Type = 18 ccmsetup 6/15/2017 9:50:35 PM 2320 (0x0910) Client is set to use webproxy if available. Ignoring MP error during post-rotation flush period of 20 seconds. Client re-install error ccmsetup01/03/2019 16:38:072612 (0x0A34) Everything looks good at that front. Selected client certificate is not trusted by the CMG service. If you go to this location in the SCCM Console: Administration\Overview\Site Configuration\Sites. MSI log file: C:\Windows\ccmsetup\Logs\client.msi.log ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) Performing AD query: Completed searching client certificates based on Certificate Issuersccmsetup01/03/2019 16:38:072612 (0x0A34) Ran sccm client repair tool and it fixed the issue. Begin searching client certificates based on Certificate Issuersccmsetup01/03/2019 16:38:072612 (0x0A34) Please find the below Prajwal Desai link to upgrade SCCM 1810. SMSSITECODE=101 CCMFIRSTCERT=1 CCMCERTSTORE=MY SCCM-Server-Dan.cork.local Retrieved 0 MP records from AD for site '001' ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) CCMCERTSTORE: MYccmsetup01/03/2019 16:38:072612 (0x0A34) RegTask: Failed to get certificate. ', Begin validation of Certificate [Thumbprint B2400DEC508EBAACE84613AE21A33F4F59683BD0] issued to 'PTW01CISWB001. However, we had an error in some of the logs, that we couldn't really pinpoint Failed to get AAD token. CcmSetup failed with error code 0x87d00454, Configuration Manager (Current Branch) Site and Client Deployment. Your daily dose of tech news, in brief. Is it a factor also for the updates not deploying to client computer? 1,Anything useful in wuahandler.log? Best practices and the latest news on Microsoft FastTrack, The employee experience platform to help people thrive at work, Expand your Azure partner-to-partner network, Bringing IT Pros together through In-Person & Virtual events. We're glad that the question is solved now. ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) WUAhandler.log has no error but in the Updatedeployment.log error is GetUpdateInfo: Failed to get targeted update error = 0x87d00215. I am not an expert here. force to run a cycle from the client workstation and it will say compliant. However a distribution point could not be located. Have a question about this project? GetDirectoryList failed with a non-recoverable failure, 0x87d00454 ) Similar thread for your reference, the issue is due to access privileges. Source \\winsccm.testlab.com\SMSClient is inaccessible (67) ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) ', Based on Certificate Issuer 'domainname Enterprise Root 01i001' found Certificate [Thumbprint 4E67BDA515464DE0C651562D0ABBAE688F7B7510] issued to 'PTW01CISWB001. GetDPLocations failed with error 0x87d00280 ccmsetup 6/15/2017 12:24:47 AM 2680 (0x0A78) I'm excited to be here, and hope to be able to contribute. \\WINSCCM.TESTLAB.COM\SMSClient ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) https://social.technet.microsoft.com/Forums/exchange/en-US/ed8763fb-5b97-4a29-8b5c-82865aed9828/upgraded-to-1806-from-1802-and-now-i-am-receiving-quotccmsetup-failed-with-error-code. Determining source location ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) JavaScript is disabled. Years ago, we had put an IIS redirect to direct users to a "prettier" CNAME for the Application Catalog's URL.Once we removed the Application Catalog roles in favor of using only Software Center, we removed the IIS redirect and our CMG started working great. Ccmsetup is being restarted due to an administrative action. ccmsetup01/03/2019 16:38:072612 (0x0A34) Software Center loads with a blank window. Best practices and the latest news on Microsoft FastTrack, The employee experience platform to help people thrive at work, Expand your Azure partner-to-partner network, Bringing IT Pros together through In-Person & Virtual events. Shutdown has been requested ccmsetup 6/15/2017 9:50:24 PM 4244 (0x1094) CcmSetup failed with error code 0x87d00280 ccmsetup 6/15/2017 12:24:47 AM 4480 (0x1180), Looks like an issue with using https for your client communication verify your clinet has the correct certs. - edited group on the server where DP role is to be installed? installed. Failed to get DP locations as the expected version from MP 'http://server1.techuisitive.com'. There are at least 2 certificates valid for ConfigMgr usage that meet the selection criteria. Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support. If it's an ip range, make sure it falls within the range. Folder 'Microsoft\Microsoft\Configuration Manager' not found. LocationServices 8/9/2019 10:44:28 AM 9416 (0x24C8), 0 internet MP errors in the last 10 minutes, threshold is 5. 6/15/2017 12:24:47 AM 2680 (0x0A78) We are working every day to make sure our community is one of the best. LocationServices 8/9/2019 11:00:28 AM 4744 (0x1288), 2 internet MP errors in the last 10 minutes, threshold is 5. Finding certificate by issuer chain returned error 80092004ccmsetup01/03/2019 16:38:072612 (0x0A34) 'ccmsetup01/03/2019 16:38:072612 (0x0A34) ccmsetup01/03/2019 16:38:072612 (0x0A34) windows 11 deplyment is failed via sccm (sccm version:2111) and getting this error "Getupdate -failed to get targated update error= 0x87d00215 in updatedeployment.log. There are no certificates in the 'MY' store. \\SCCM-Server-Dan.cork.local\SMSClientccmsetup01/03/2019 16:38:072612 (0x0A34) Check if your boundaries and boundary groups are correctly configured. CCMFIRSTCERT: 1 ccmsetup 6/15/2017 9:50:35 PM 3220 (0x0C94) Failed to get client certificate for transportation. I'm glad you may have found the root cause! Client OS Version 6.2 Service Pack 0.0ccmsetup01/03/2019 16:38:072612 (0x0A34) Checking Write Filter Status. Task does not exist. Ccmsetup is being restarted due to an administrative action. I have checked the forums and googled for a definitive answer to this but nothing seems to work. It has been sent. Find out more about the Microsoft MVP Award Program. Actually you're right, I get the same error when using the Go http client to make the request so Chrome knows the CA but not Go so it looks like the CA is not loaded properly as you said. 9:50:35 PM 3220 (0x0C94) LocationServices 8/9/2019 11:00:29 AM 212 (0x00D4), 0 internet MP errors in the last 10 minutes, threshold is 5. Hopefully, you have as simple a fix. SeeSite and site system prerequisites for Configuration Managerfor details.