A client is trying to re-register with an administrator revoked certificate

HI All,
I have an Azure based server that will not register correctly in SCCM 2012, it is our IBCM server and has been working OK but our 3rd  party support team tried to uninstall the client
on this server a 5 other DP’s (I have fixed those and the clients has PKI certificate) but also uninstall the roles, which has been unsuccessful and now there are the site server and component server roles still installed.
I am unable to install the SCCM client successfully and the certificate says “None” rather than PKI which all my other servers have installed, I have tried the suggestions from
https://social.technet.microsoft.com/Forums/en-US/48d496ee-4869-4cef-8cd0-9dcab843e373/sccm-2012-r2-client-on-distribution-point-doesnt-complete-registration-solved?forum=configmanagerdeployment
and also from
https://social.technet.microsoft.com/Forums/systemcenter/en-US/08119f92-fba7-43b1-bdb1-1b4d72963ff7/sccm-clients-registration-rejected-by-management-point
which involved
The following are the sequence,
1) uninstall the client agent ccmsetup /uninstall
2) remove the entries of CCMsetup and SMS from registry HKLM
3) remove the Config mgr cert from computer personal store
4) remove the smscfg.ini from windows folder
5) restart the machine
Installion process
wait for the client pc to auto enroll config mgr client cert from CA
reinstall the client
The client registration successfully went through. I suspect is because the client no
matter how many times you reinstall it tries use the old GUID to register with MP without even knowing that client has been marked as absolete in the SCCM primary site server.
If you restart the and perform the above steps it will flush the cache and try to register
with a mp and get the new GUID from the MP and then it successfully registers it.
So at the moment my IBCM server is not working and I cannot get the client installed
MP_Registration.log is below, all other clients get installed OK.
Processing Registration request from Client 'GUID:8EC3C75A-AA8D-4421-8725-446FF891EF02'           
MP_RegistrationManager         
11/13/2014 5:13:27 AM          
10172 (0x27BC)
Begin validation of Certificate [Thumbprint AF0D7B12263DC9EF764750519884992CAA53FBE0] issued to 'SMS'           
MP_RegistrationManager         
11/13/2014 5:13:27 AM          
10172 (0x27BC)
Completed validation of Certificate [Thumbprint AF0D7B12263DC9EF764750519884992CAA53FBE0] issued to 'SMS'           
MP_RegistrationManager         
11/13/2014 5:13:27 AM          
10172 (0x27BC)
A client is trying to re-register with an administrator revoked certificate: SMSID='GUID:8EC3C75A-AA8D-4421-8725-446FF891EF02'.          
MP_RegistrationManager         
11/13/2014 5:13:27 AM          
10172 (0x27BC)
Any ideas?? A support call is needed I think…
many thanks

Hi Jason,
thank you for the response, I called support and it turns out that SCCM was actively revoking certs, so when a new one was created it automatically revoked it for this server for some reason, all other clients on the network installed OK, it was particular
to this server, so we had to delete from the DB all revoked certs even though in the SQL view there were no certificates or SMSGUIDS related to the server itself.
So running
select
*fromclientkeydatawhereisrevoked='1'
Update
clientkeydatasetisrevoked=0
whereisrevoked=1
resolved the issue and the client installed correctly.
Hope this helps anyone else who experiences this issue.
many thanks

Similar Messages

  • Some clients migrated from 2007 is presented with the self signed certificate in 2013

    I have migrated from 2007 to 2013. I did a couple of test migrations and on the ones with domain member computers Outlook is giving a certificate warning. The certificate they are presented with is the default self signed certificate on the 2013 server.
    Even though I have added a trusted public certificate to Exchange and checked of to use With IIS.
    I see that the default certificate is also checked of to use With IIS and it cant be removed in ECS. Shouldnt this be removed from IIS all together when adding a New certificate? And why does some Clients gets presented With the self signed and some With
    the Public? For instance owa is presented With the Public cert. Also and Outlook I tested from outside the domain.
    Regards

    Only the UCC certificate should be bound to IIS.
    Are any clients using POP or IMAP, which also use SMTP?  In this case clients can be presented with the "wrong" certificate as well.
    Ed Crowley MVP "There are seldom good technological solutions to behavioral problems."

  • Client Can't register with inContext

    I am having a frustrated client: [email protected] trying to register to edit there site.
    When i sent him the invitation he said he never got it. I deleted him, added him again and clicked on copy me on the invitation. I then forwarded him the invitation and he has had no luck registering. It is telling him that there is an account already with that email.
    Please help, i really don't like giving our clients the runaround on this, i also haven't received a confirmation email from adobe for his account.
    Thanks in advance! Marcus

    I have also verified that our client is getting the email verification from adobe. However, once it says congratulations, it is saying to login. Once he does that, it says you aren't a registered user.
    here is the email below........
    Hello,
    To verify your use of this e-mail address [email protected] with InContextEditing.com, please click on the below link.
    https://incontextediting.adobe.com/services/redirect.php?url=1ab2babf8bdd7daf71551ccf6c924 4dab17b21f9&ev=2J513FWQFJJB6AA44ZZK67K07R
    If you cannot access the link above, please copy and paste the link into your browser.
    If you are not currently registered with Adobe InContext Editing, please disregard this message.
    Sincerely,
    The Adobe InContext Editing team
    http://incontextediting.adobe.com

  • My Friend used my pc while it was on, and cheked his Facebook account, now my pc remembers his log in information including his password. I'm trying to register with Facebook, but my pc remembers his info. I'm trying to delete this mistake. Can you help?

    A friend used my pc to check his Facebook account, and used my account. Now, my pc thinks I am he whenever I try to register with Facebook. I didn't catch the mistake until recently and have been trying to delete the info but cannot. I tried to access all of my security settings and even tried to erase the history but I don't seem to be getting anywhere. I believe he mistakenly commanded my pc to remember his username and password. I am not currently registered with Facebook, but would like to be but I am having this problem. Is it significant or not? I don't want his info crossing with mine because of my ips numbers or something like that. He also, without my knowledge, accessed his e-mail, too. His username seems to pop up even if I try to "Like" something on Facebook. This is when I noticed the problem. Then, when I tried to Register with Facebook, I was mistaken for him. The registration boxes come already filled in with his info. I do NOT want to invade his privacy. His entire profile comes up complete with friends, pictures, etc...Please help! I cannot make a 'save' disk since I don't know exactly when this happened and I've loaded new programs, including security and related files.

    I am very happy to report that my server connection tech, which I called via landline, informed me to : 1. Open Tools 2. Scan down to Clear Recent History 3. Delete All. That was it! Unbelievable! Six hours of searching through the Windows catagories. I checked the results on an internet site, and viola! It was gone! Mozilla Firefox seems to remember the usernames and passwords irregardless of the option window that asks if you if want it to remember the user and password. I finally got in touch with my friend and he said he did not answer yes to the window, even though he was aware of it. No damage. I surely do appreciate everyones' concern in this, now what seems to be, a very simple solution. Cudos to Firefox! Thank-you! P.S. I now have to enter my information at the beginning of any password protected sites...no harm done! My friend is now condemned to the 'user account' site! lol...

  • Help. Trying use imessage and keep getting an error message that says the person is not registered with imessage

    I am trying to use imessage and everyone I am trying to send to I keep getting a message that they are not registered with imessage. They all have iphones and I know for a fact they are all registered. I have tried all the trouble shooting steps I have found so far. I made sure my imessage is turned on and set under my apple id and email, I'm connected to wifi. etc... I can use facetime but can not message anyone. Thanks in advance for you help

    Hi, reagans3.
    Thank you for visiting Apple Support Communities.
    I see you are experiencing issues with iMessage.  I am not sure what troubleshooting steps that you have processed; however, there are some additional steps in the article below that may help.
    iOS: Troubleshooting Messages
    http://support.apple.com/kb/ts2755
    Cheers,
    Jason H.

  • HT201269 I got a replacement Iphone5 from Apple. I went home and tried to synced it with ITunes but had to register as a new device to do update then I can restore old back up, now can't back up old phone info and can't activate my Apple ID for iMessage

    I got a replacement Iphone5 from Apple. I went home and tried to synced it with ITunes but said to register as a new device to do update then I can restore old back up, now can't back up old phone info and can't activate my Apple ID for iMessage

    Can you clarify your problem? Are you having trouble restoring your new iPhone from a previous phone's backup? Or are you having trouble logging into iMessage?

  • Trying to register with ePrint and getting error code.Ajax submit failed: error = 403, Forbidden.

    Trying to register with ePrint and getting error code.Ajax submit failed: error = 403, Forbidden. I need help??

    To bypass this error attempt either a restart of your computer, or use an alernate broser such as firefox or chrome. If you already have another browser the latter may be the easier fix.
    Jon-W
    I work on behalf of HP
    Please click “Accept as Solution ” on the post that solves your issue to help others find the solution.
    Click the KUDOS STAR on the left to say “Thanks” for helping!

  • I am trying to register my macbook pro and every time i got a message telling me that this product is registered with different apple id, how it comes?

    I am trying to register my macbook pro and every time i got a message telling me that this product is registered with different apple id, how it comes?

    Sounds like you got a used computer and paid new for it, that's illegal.
    "Open box" is a return by a previosu customer and can't be sold as new, you should have gotten a discount or informed of such.
    Once obvious sign is it doesn't come with free iLife on it, as the drive was erased.

  • TS2755 when trying to send a message, I have an error message that a particular addressee is not registered with imessage.  How is this corrected?

    I just purchased the latest ipad.  When trying to send a message, the addressee indicates an error stating that it has not been registered with imessage and to remove it.  How can this be corrected.

    Using FaceTime http://support.apple.com/kb/ht4319
    Troubleshooting FaceTime http://support.apple.com/kb/TS3367
    The Complete Guide to FaceTime + iMessage: Setup, Use, and Troubleshooting
    http://tinyurl.com/a7odey8
    Troubleshooting FaceTime and iMessage activation
    http://support.apple.com/kb/TS4268
    iOS: About Messages
    http://support.apple.com/kb/HT3529
    Set up iMessage
    http://www.apple.com/ca/ios/messages/
    Troubleshooting Messages
    http://support.apple.com/kb/TS2755
    Setting Up Multiple iOS Devices for iMessage and Facetime
    http://macmost.com/setting-up-multiple-ios-devices-for-messages-and-facetime.htm l
    FaceTime and iMessage not accepting Apple ID password
    http://www.ilounge.com/index.php/articles/comments/facetime-and-imessage-not-acc epting-apple-id-password/
    Unable to use FaceTime and iMessage with my apple ID
    https://discussions.apple.com/thread/4649373?tstart=90
     Cheers, Tom

  • I had an issue when trying to register with the forums, but I am having problems speaking someone because I am not a "registered" member?

    Dear forum member(s), I was excited at the possibilities that Firefox offered. I have been looking forward to researching on the forums, but I made a blunder when registering.
    I changed my email password some time ago and forgot that I had done so. I also have a second email which is similar to my address I was registering and I think I was actually using my the second email information until I caught the mistake.
    Shortly thereafter I received an email with my user ID but no password. I had been assuming that I would receive a onetime computer generated password, but I wasn’t sure how things were supposed to go. After closely studying the language of the email, I was led to the conclusion that I would login with my original information I had provided.
    My final attempt to register failed and I can’t explain why. I am positive that I had the right user id and password and now I am in limbo. I registered with the "Add-ons" section in 15 minutes. I was never told I was banned, but I was never told I am now a member. Thanks for reading.
    Sincerely,
    reel4

    Not at all. I have never posted to the forums. The only thing I have written is what you see in this thread. I registered at add-ons section and things were fine. I wanted to use the forums, because I like to learn what I can. The problems began when I tried to register at the forms. At first, I thought my login from add-ons would work at the forums. It didn't. I honestly don't know if there is separate login and validation for each firefox/mozilla section.
    When I attempted to register with the forums, I messed up when trying to login because I made too many attempts. I was either using another password from a second email or I misread those weird words they use to make sure you are not a bot.
    I don't know what exactly was written but they basically wanted to take a look at things. I felt that was reasonable. After all - I felt like a moron for not being able to read those contorted word tests.
    Then they sent me my user id but with no new password so I assumed my current password was the same as the one I originally gave. Long story short, I tried to login again- all three times I failed. They never banned me or told me anything. I have not heard from anyone or thing. To It's like they have just walked away. I just don't understand what has happened and why no one will tell me anything. So... no - I am not banned. When I do bet blocked after I logoff, it has the same effect as a ban. I guess I have been ousted. I just wish this I could get this matter resolved. I changed my password and email so maybe that will keep around.
    It's a strange situation and I am at loss for words. I even wrote the forum people an apology letter describing the facts above in details and apologizing for the inconvenience. I actually apologized for being an idiot.
    One last thing - at the outset of the post - I told you they gave me one last opportunity to login and it failed. I know for a fact I had the information correct. I had even written my password somewhere else on the screen to where I could see each character to verify the pass word was correct and then cut and paste.
    James - who knows what the future holds but I must thank you my friend. At the very least, I could tell my story. It is all so strange.

  • Trying to send "Message" on iPad 2 and keep getting message that "x" is "not registered with iMessage." Never happened on previous iPad. What does it mean and how do I solve?

    Trying to send "Message" on iPad 2 and keep getting message that "x" is "not registered with iMessage." Never happened on previous iPad. What does it mean and how do I solve?

    Trying to send "Message" on iPad 2 and keep getting message that "x" is "not registered with iMessage." Never happened on previous iPad. What does it mean and how do I solve?

  • Tried to send iMessage from iPod touch (5th generation) but continuously says "contact not registered with iMessage". The contact IS registered with iMessage, but won't send any messages to anyone.

    I have an iPod touch 5th generation (7.1.2) that has not been sending iMessages to other iMessage users. At first my iPod would not let me sign in to use iMessage, but I searched on different discussion boards that helped me log in. Now the trouble is not being able to send messages at all. I tried to delete the contact I was trying to message and restart the conversation board, but that didn't help at all. The contact continues to say 'xxxxxx not registered with iMessage" when, in fact, they are. I need help to resolve this issue.
    Thanks

    Can you receive Message?
    If so can you reply?
    Have you tried when connect to another network?
    Also see:
    iOS: Troubleshooting Messages
    Using FaceTime and iMessage behind a firewall

  • Windows 2k Clients could not registered with CSAMC 5.0

    hi there,
    My w2k clients could not registered with CSAMC, WinXP registered o.k. I am running CSA 5.0.176.
    All clients in same TESTMODE group. Any idea ?
    Thanks
    ade

    The CSAgent-Install.log will show you if any of the shims failed to load during the install.
    The csalog.txt in the same directory will log communication problems. Look for an error code like one below (cut and pasted from the Networkers 2006 CSA Troubleshooting session slides):
    OKENA_STATUS_LICENSE_REACHED_LIMIT = 2030
    Number of registered hosts has exceeded the license count for that host type [desktop or server]
    Resolution: delete unused hosts; automatically in 30 days or use search
    OKENA_STATUS_REGISTRATION_NOT_ALLOWED = 2031
    Usually a certificate issue
    Resolution: Set agent to debug and triage using csalog.txt
    OKENA_STATUS_INVALID_LICENSE = 2035
    A license has expired or file format was not valid
    Resolution: Delete expired license files
    OKENA_STATUS_REGISTRATION_BACKOFF =2037
    A number of conditions can trigger this; all are uncommon and need attention
    Resolution: Set agent to debug and triage using csalog.txt

  • I am trying to send a text message from my iPad when I enter phone number I get error message phone number not registered with iMessages  from contacts

    When attempting to send text message from iPad I get error message "phone number not registered with iMessage REMOVE" the number is for iPhone an includes area code and country code. How do u register a number with iMessage?.

    TestnTag wrote:
    When attempting to send text message from iPad I get error message "phone number not registered with iMessage REMOVE" the number is for iPhone an includes area code and country code. How do u register a number with iMessage?.
    The iPad is not capable of sending an SMS message so texts, pictures, etc., must go through iMessage.  The destination device must be registered with the Apple servers by turning on iMessage.  Therefore, the user with the iPhone must enable it for iMessage.

  • Cisco 877 router - Cisco IP phone won't register with SIP provider

    Hi all,
    I'm having a problem with a Cisco SPA504G phone not registering with the SIP carrier over the Internet. We've recently rolled out a Cisco 877 router onto a new NBN business connection and can't get the pre-configured IP phone to register.
    When we tested the phone with the NBN-provided Netgear router, it worked fine, as it did with the previous Cisco 1841 router we were using on a different link.
    The way it's setup is using VLANs to define the internal subnets, which are then assigned to the physical interfaces (since the 887 doesn't allow IP assignments to the interfaces directly).
    VLAN 100 is the internal network and has a SBS2011 server – assigned to F0 – IP range is 192.168.1.0
    VLAN 200 is the guest network and has Internet access only – assigned to F1 – IP range is 10.1.1.0
    VLAN 500 is the WAN network and connects to the NBN upstream box – assigned to F3 – external IP address assigned by DHCP
    I've been playing around with access lists, nat rules, basically everything in my limited Cisco knowledge to try and figure this out, but to no avail. I have even configured what I believe is unrestricted access to IP, UDP and TCP outbound and inbound to all VLANs and still can't get it to register.
    Tried isolating the issue by creating a new VLAN and assigning it to the spare interface and basically allowing everything in and out, but still no luck.
    The problem has to be something on the router – probably some small line of config I haven’t removed or added.
    I am going to pull my hair out soon, so would really appreciate some assistance from the Cisco gurus out there.
    My client has just purchased about 10 of these handsets from their provider so I need to fix this ASAP. The guy who provided them wasn't very helpful, and basically said I'm on my own once we tested using the NBN-provided Netgear router.
    Happy to post my config as well.
    Please help!!!!

    Current configuration : 4912 bytes
    version 15.1
    no service pad
    service timestamps debug datetime msec
    service timestamps log datetime msec
    no service password-encryption
    hostname Router1
    boot-start-marker
    boot-end-marker
    no aaa new-model
    memory-size iomem 10
    crypto pki token default removal timeout 0
    no ip source-route
    ip dhcp excluded-address 10.1.1.1
    ip dhcp pool GUEST
     network 10.1.1.0 255.255.255.0
     dns-server 10.1.1.1 203.50.2.71 139.130.4.4
     default-router 10.1.1.1
    ip cef
    no ip domain lookup
    ip domain name network.local
    ip name-server 192.168.1.123
    ip name-server 203.23.53.12
    ip name-server 197.12.32.86
    ip name-server 8.8.8.8
    no ipv6 cef
    license udi pid CISCO887VA-K9 sn FGL171220XY
    username admin privilege 15 secret 5 $1$aNsm$N1BCQYkoi8gnURyvloYEX/
    controller VDSL 0
    interface Ethernet0
     no ip address
     shutdown
    interface ATM0
     no ip address
     no atm ilmi-keepalive
     bridge-group 10
     pvc 8/35
    interface FastEthernet0
     description NAC - Internal network
     switchport access vlan 100
     no ip address
    interface FastEthernet1
     description NAC - Guest network
     switchport access vlan 200
     no ip address
    interface FastEthernet2
     no ip address
     shutdown
    interface FastEthernet3
     description **** WAN Port ****
     switchport access vlan 500
     no ip address
    interface Vlan1
     no ip address
     bridge-group 10
     hold-queue 100 out
    interface Vlan100
     description NAC - Internal Vlan
     ip address 192.168.1.1 255.255.255.0
     ip access-group IN-100 in
     ip access-group OUT-100 out
     ip nat inside
     ip virtual-reassembly in
    interface Vlan200
     description NAC - Guest Vlan
     ip address 10.1.1.1 255.255.255.0
     ip access-group IN-200 in
     ip access-group OUT-200 out
     ip nat inside
     ip virtual-reassembly in
    interface Vlan500
     description **** WAN Vlan ****
     ip address dhcp
     ip nat outside
     no ip virtual-reassembly in
    no ip forward-protocol nd
    ip http server
    ip http access-class 23
    ip http secure-server
    ip dns server
    ip nat inside source list NAT-100 interface Vlan500 overload
    ip nat inside source list NAT-200 interface Vlan500 overload
    ip nat inside source static tcp 192.168.1.123 25 interface Vlan500 25
    ip nat inside source static tcp 192.168.1.123 443 interface Vlan500 443
    ip nat inside source static tcp 192.168.1.123 3389 interface Vlan500 3399
    ip nat inside source static tcp 192.168.1.123 80 interface Vlan500 80
    ip nat inside source static tcp 192.168.1.123 4125 interface Vlan500 4125
    ip nat inside source static tcp 192.168.1.124 3389 interface Vlan500 3390
    ip nat inside source static tcp 192.168.1.123 987 interface Vlan500 987
    ip nat inside source static tcp 192.168.1.123 1723 interface Vlan500 1723
    ip route 0.0.0.0 0.0.0.0 55.234.52.43
    ip access-list extended IN-100
     permit udp any any range bootps bootpc
     deny   ip 10.1.1.0 0.0.0.255 any
     permit ip 192.168.1.0 0.0.0.255 any
    ip access-list extended IN-200
     permit udp any any range bootps bootpc
     permit ip 10.1.1.0 0.0.0.255 any
    ip access-list extended NAT-100
     deny   ip 192.168.0.0 0.0.255.255 192.168.0.0 0.0.255.255
     permit ip 192.168.1.0 0.0.0.255 any
    ip access-list extended NAT-200
     deny   ip 10.1.0.0 0.0.255.255 10.1.0.0 0.0.255.255
     permit ip 10.1.1.0 0.0.0.255 any
    ip access-list extended OUT-100
     permit udp any range bootps bootpc any
     deny   ip 10.1.1.0 0.0.0.255 any
     permit ip any 192.168.1.0 0.0.0.255
    ip access-list extended OUT-200
     permit udp any range bootps bootpc any
     deny   ip 10.1.1.0 0.0.0.255 192.168.1.0 0.0.0.255
     permit ip any 10.1.1.0 0.0.0.255
    access-list 23 permit 59.23.164.52
    access-list 23 permit 192.168.1.0 0.0.0.255
    access-list 23 permit 10.1.1.0 0.0.0.255
    access-list 23 permit 120.146.0.0 0.0.255.255
    access-list 23 permit 149.185.12.0 0.0.0.255
    access-list 23 permit 110.44.28.0 0.0.0.255
    access-list 23 permit 110.44.26.0 0.0.0.255
    access-list 23 permit 103.25.212.0 0.0.0.255
    access-list 23 permit any
    bridge 10 protocol ieee
    banner motd ^C
    *      Authorized personnel only!       *
    ^C
    line con 0
     login local
     no modem enable
    line aux 0
    line vty 0 4
     password password01
     login local
     transport input all
    end

Maybe you are looking for

  • Ipod no longer syncs video. Why?

    On the 20th July 2011 I updated to itunes 10.4, ever since then I have been unable to sync videos to my ipod. the program I use to convert videos has not changed. The video format has not changed. Aside from total size and length the videos are ident

  • The following code is used to run a report in tom cat. When I run this code

    Hi When I try to run the following SQL code doesn't work. Can someone pls tell me why? SELECT SR.ID AS SRID, -- SR.DATECREATED AS SR_DATE_CREATED, -- JOB_END.JOB_END_DT AS SR_FIELD_WORK_COMP, AQ.OBJECTID AS SH_ID, CASE WHEN Q.ID IN (30750, 30730, 307

  • Ipod Classic with Itunes 12.1 - Warning

    First off, Known issues - immediately after 12 dropped, pretty much all functionality involving Ipod classics was broken. Mac OS recieved a patch that fixed this, Windows has not, and there has been no addressing this issue thus far. My stuff: Ipod c

  • 2 SQL Servers in one host - Urgent

    Hi, I have both SQL2000 and SQL2005 on one machine. I would like to migrate the SQL2005 instances to oracle, thus i have installed sql developer. When i try to link the Developer to SQL Server, i use windows authentication, hostname='DEV' and Port=14

  • Grand totals in Pivot table in OBIEE

    Hi, I have a pivot table in which i want both row and column level totals. when i say summation-->after for both row and column i can see the totals but the column level totals are showing results(the row level totals are correct.) Any idea what mist