Proper certificate that matches the pre loaded certificate was not found in the user certificate store. PKI configuration failed.

Article:TECH156530  |  Created: 2011-03-25  |  Updated: 2011-06-22  |  Article URL http://www.symantec.com/docs/TECH156530
Article Type
Technical Solution


Issue



After installing the Intel AMT Provisioning certificate in the "Current User" store and "Local Computer" the following error keeps appearing during provisioning attempts.

"Proper certificate that matches the pre loaded certificate was not found in the user certificate store. PKI configuration failed." 


Error



Proper certificate that matches the pre loaded certificate was not found in the user certificate store. PKI configuration failed.


Environment



Symantec Management Platform 7.1 MP1

Out Of Band Management Component 7.1

Microsoft Windows Server 2008 R2

Intel SCS 5.0.4


Cause



The root certificate authority thumbprint (Fingerprint) does match what is expected by the Intel AMT firmware.


Solution



The Intel AMT provisioning certificate must be signed by a certificate certificate authority having a Thumbprint trusted by the Intel AMT firmware.

The following Intel web site contains a list of trusted root certificate authorities and their thumbprints when this article was written:

http://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/DOCS/Implementation%20and%20Reference%20Guide/default.htm?turl=WordDocuments%2Frootcertificatehashes.htm

If the root certificate in the Intel AMT provisioning certificate does not have the expected Thumbprint, then the certificate must be re-keyed or re-issued by the certificate vendor.




Article URL http://www.symantec.com/docs/TECH156530


Terms of use for this information are found in Legal Notices