ConfigMgr R2 - Mac OS Enrollment Issues

Hello everyone,
First, a few details on where I'm at:
Single ConfigMgr 2012 R2 Site w/ PKI 
Requisite roles are installed and HTTPS is enabled to allow 'internet and intranet' clients
Apple iMac with OSX 10.9
Mac is added to Active Directory
R2 Client is installed on Mac
Entered server name into Safari, installed Root Certificate and allowed it to 'Always Trust'
Ran 'Configuration Manager' tool in Preferences, go to enroll, enter credentials, and I get:
"Server is not trusted. Do you want to continue?"  I choose yes and get the following:
"Error: Enrollment error (0x8018002a)"
If I look in the System Keychain on the Mac I see the 'SCCM' public and private keys.  Running 'CMDiagnostic' doesn't show me any blatant errors.
If I take the Mac and connect to the Internet outside of our Domain I simply get 'Unable to contact the server for this request.'  If I type in the FQDN of the server into Safari at that point it does not resolve.  If I do an NSLOOKUP with the
trailing '.' or do a DIG of the address outside of the Domain, I do get it to resolve.
Any ideas?  Next steps?

What guide are you following?  Installing the certificate through Safari isn't related to client enrollment.
What do you see for errors on enrollment point that is trying to issue the certificate?
http://technet.microsoft.com/en-us/library/hh427342.aspx#BKMK_CertificateEnrollment
I hope that helps,
Nash
Nash Pherson, Senior Systems Consultant
Now Micro -
My Blog Posts
If you found a bug or want the product to work differently,
share your feedback.
<-- If this post was helpful, please click the up arrow or propose as answer.
I have to be honest, I had a consultant here to help with this last week and he never got it working so I'm now trying to go over everything he did to try and figure out what is going on.
Those logs you asked for, those look to be for the Certificate Registration Point but I don't have that role installed.  When I look at the Mac OS Enrollment instructions I only see the Enrollment Point and Enrollment Proxy Point which are installed.

Similar Messages

  • Mac Enrollment Issue on SCCM 2012 SP1

    Hi Guys,
    I am working on Mac enrollment(10.7) and facing issue during enrollment. Below is the error message when we try to run the enrollment command on Mac :
    “Server connection failed. HTTP Response code is 500 and reason is Internal Server Error"
    Below are Log info:
    Enrollsrv.log : No error message is highlighted.
    Enrollweb.log:
    No error message is highlighted.
    Enrollservice.log:
    [7, PID:7304][10/28/2013 16:40:03] :ConfigManager: ChainStatus error: RevocationStatusUnknown,The revocation function was unable to check revocation for the certificate.
    ;OfflineRevocation,The revocation function was unable to check revocation because the revocation server was offline.
       at Microsoft.ConfigurationManagement.Enrollment.ConfigManager.SplitCACertChain(String base64cert)
       at Microsoft.ConfigurationManagement.Enrollment.ConfigManager.setCAChain(EnrollmentServiceProfile profile, WindowsIdentity requester)
       at Microsoft.ConfigurationManagement.Enrollment.ConfigManager.RefreshCache(Int32 enrollmentProfileId, EnrollmentRecordType type, String template, WindowsIdentity requester)
       at Microsoft.ConfigurationManagement.Enrollment.RequestHandler.ProcessRequestSecurityToken(RequestSecurityTokenType request, WindowsIdentity caller, ActionEnum action)
       at Microsoft.ConfigurationManagement.Enrollment.RequestHandler.EnrollDevice(Message messageRequest)
       at Microsoft.ConfigurationManagement.Enrollment.DeviceEnrollmentService.RequestSecurityToken(Message messageRequest)
    [7, PID:7304][10/28/2013 16:40:03] :FaultCode is: EnrollmentServer and reason is: EnrollmentServerException InitializeFailed
    [13, PID:7304][10/28/2013 17:11:01] :EnrollmentService application stop ...
    [3, PID:956][10/28/2013 17:45:37] :EnrollmentService application start ...
    [3, PID:956][10/28/2013 18:06:38] :EnrollmentService application stop ...
    [3, PID:4700][10/28/2013 18:45:39] :EnrollmentService application start ...
    [7, PID:4700][10/28/2013 19:06:40] :EnrollmentService application stop ...
    [3, PID:5872][10/28/2013 19:45:42] :EnrollmentService application start ...
    [13, PID:5872][10/28/2013 20:06:42] :EnrollmentService application stop ...
    Can someone shed info on resolution of the above issue?
    Also, is there any means by which we can troubleshoot the Mac enrollment issue step by step? Also what entries needs to be checked in all logs for successful enrollment?

    the following links may give you some hints:
    http://social.technet.microsoft.com/Forums/en-US/48bc7fcc-3d84-4042-abac-67f30d701121/mac-enrollment-issue?forum=configmanagerdeployment
    http://www.windows-noob.com/forums/index.php?/topic/7391-mac-enrollment-issue/

  • Mac Client Enrollment Not Working

    I'm trying to enroll a MAC OSX 10.9.2 client.  My environment is Server 2012 R2 and Configuration Manager 2012 R2.  I get the following error when running the CMEnroll command:
    SSL Connection failed.  HTTP Response code is 500 and reason is Internal Server Error
    Server returned:  CertificateRequest Error
    These are the errors from the EnrollmentService.log
    [3, PID:3596][03/07/2014 12:23:52] :CALayer: Sending CA failure status - ENROLLSRVMSG_CA_FAILURE
    [3, PID:3596][03/07/2014 12:23:52] :CALayer: SubmitRequest CA: cauthority.ctl.intranet\CTL Prod Issuing CA Errormessage: Denied by Policy Module 2 ErrorCode: 2
    [3, PID:3596][03/07/2014 12:23:52] :Only one CA is specified in profile. Failed to enroll with the specified CA: cauthority.ctl.intranet\CTL Prod Issuing CA
    [3, PID:3596][03/07/2014 12:23:52] :EnrollmentRequestController: Enrollment exception Error Code:FailedToIssueCert Message: Submitting cert request and issuing cert failed
    [3, PID:3596][03/07/2014 12:23:52] :Microsoft.ConfigurationManagement.Enrollment.EnrollmentServerException: Submitting cert request and issuing cert failed
    [3, PID:3596][03/07/2014 12:23:52] :FaultCode is: CertificateRequest and reason is: Failed certificate operations FailedToIssueCert
    Does anyone know what's going on?

    Hi,
    The failed requests on the CA might give you some useful information. And here is a similar thread with yours:
    http://social.technet.microsoft.com/Forums/en-US/142fc77d-4eed-4f3a-a57c-dcacf8cbbf63/sccm-2012-sp1-mac-client-enroll-problem?forum=configmanagergeneral
    Best Regards,
    Joyce Li
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • I have an 6 year old mac mini having issues. I can turn it on, get the apple logo and blue screen and nothing else.....help!!

    i have an 6 year old mac mini with issues that started two weeks ago. I can turn it on , get blue screen and turning circle and nothing else......help !

    Hi,
    Have you tried some of these? http://support.apple.com/kb/ht1533
    The first things I would try would be to press shift during start up, this will boot into safe mode.
    I think you'll need to purchase a copy of Snow Leopard to re-install the OS.
    There's another couple of suggestions here; http://support.apple.com/kb/TS1417 where you can boot into single user mode and look at repairing disk permissions if that's the problem.
    I would hope that if you could boot into safe mode or single user mode, then that may automatically rectify your current issue. If not, then I'm pretty certain that a fresh install will be the ultimate answer.

  • BT Cloud App for Mac - Upload freeze issues?

    Anyone experiencing freeze issues during upload sessions? 
    I just downloaded the app yesterday and kicked off an upload of 20K (ish) files.  It progressed nicely through the day, but clearly froze at some point during the night.  Following a reboot I've seen a further freeze in the last couple of hours and resorted to closing/re--opening the app. 

    Hi there, 
    Thanks for replying.  I have had issues with this continually throughout the upload.  I've managed to back-up just over 8Gb since Saturday afternoon, but not without a bit of coaxing (closing and re-starting the app every time it appears to freeze.).  In fact my upload has just finished within the last few minutes.  I've left it on after I've gone to bed on two evenings, but it's clear by morning that the app froze at a much earlier point.  I'm not on Infinity yet, but I do get a rock solid 1Mb upload so whilst the upload rate isn't wild, it would be adequate if not for the reliability issue.  
    Basically the client seems to freeze after a certain time, but there doesn't seem to be any particular pattern in terms of when it happens. 
    I'm really excited about using BT Cloud, having had problems with several other similar services.  I love the fact that it doesn't mess with your local file copy, and that it doesn't expect the user to work 'in the cloud', and that it iteratively looks for changes and just deals with them.  
    The iPad app seems pretty good, other than the wildly random way the sub folders in my Documents folder display.  I have a lot of sub folders.  I know there's a search bar, but still, a simple alphabet order approach would be better. 
    Happy to provide any further input wrt the Mac app stability issue. 
    OS X (10.8.5) 
    Safari 6.0.5 

  • Post Moved Mac Port Forwarding Issues

    Post Moved to Other BB Queries http://community.bt.com/t5/Other-BB-Queries/Mac-Port-Forwarding-issues/td-p/550779
    If you want to say thanks for a helpful answer,please click on the Ratings star on the left-hand side If the reply answers your question then please mark as ’Mark as Accepted Solution’

    Does this help...?
    http://community.bt.com/t5/Other-BB-Queries/Port-forwarding-and-Loopback-DO-work-YMMV/m-p/538328

  • Mac/forfox/ebay issue

    I am having a problem with ebay.de on firefox running on a mac.
    It started when you developed and launched the 4.0. It doesn't show the ended button. only when I reload it appears for a split second. If I open it in a external window its working and even the button is shown. But not in the main window.
    It seems to be a Mac/Firefox/Ebay issue
    Best regards
    Brian

    This is what Im talking about

  • Mac Alert systems issue

    Hello I just got an Mac Alert systems issue security warning on my screen. I tried getting apple to help me out but they directed with firefox when the problem is Safari. I unistalled Safari and then redownloaded but it still shows up. What do I do

    Hello
    I tried to relaunch while holding down shift key and it didnt do anything to solve the issue.

  • Mac Pro Display Issue

    Mac Pro Display Issue - Unexpectedly Sleeps and Freezes
    Just since a couple of days my Mac Pro desktop has been having display issues. Unexpectedly the screens go into sleep mode, it turns black and freezes, the computer doesnot respond to the keyboard or mouse.
    At first I thought this was related to Chrome, and switched to Firefox, but the computer is still having the same issue. I have to shut down and restart each time it gets stuck.
    I even went into preferences and changed the energy saver settings to "Never" allow display or harddrive to sleep. But this problem is stil happening.
    Does anyone have the same problems? Or a solution?

    I cleaned out my mac with compressed air, it was dusty, but the display flickering happened again.
    So I followed your advice and installed:
    Temperature Monitor
    http://www.bresink.de/osx/TemperatureMonitor.html
    Which showed that my memory module 1B and 2B were 70 - 75'C(160 -167'F). There was no reading for the graphic card so I couldn't tell if that was over heating.
    Then I installed:
    smc fan controller
    http://www.macupdate.com/app/mac/23049/smcfancontrol
    and increased the memory_cpu fan speed which lowered the temperature of the ram to 60'C (143'F).
    I even changed this ram's placement and put it in different slots.This ram was the same temperature in the new placements.
    Also this is the kingston 2gb ram without heatsinks. Ive used it for 1.5 yrs, and this is the first time its giving me these problems.
    Do you know how I can check if the graphic card is over heating? or is the problem just with the ram?
    Thank you for all your help!

  • Cannot log into facetime for mac - says network issues - anybody help?

    cannot log into facetime for mac - says network issues - anybody help?

    cannot log into facetime for mac - says network issues - anybody help?

  • Mac mini having issues with system preferences retaining settings

    Mac mini having issues with system preferences retaining settings; this was present with Mavericks and now Yosemite after installation.  Did try removing com.apple.systemprefs.plist file (library/preferences folder) to trash, but couldn't find it in trash in order to empty it.  Upon reboot the file is still missing.  Please don't suggest reloading Yosemite, have very slow internet connection, Yosemite took 7-8 hours to D/L.
    Any troubleshooting suggestions out there?  thanks

    Well, I'd open Font Book, it's included with OSX, & see what it says for Validate & Duplicates.
    I would also like to add I am new to Apple computers and I'm doing my best to stay up to par with whats what and understanding!
    No problem, we were all new to everything once, do let us know if you need more help or clatification.

  • Mac mini having issues with video and sound

    all of the sudden my mac is having issues playing video or sound. videos or songs will start but only play for a second or two before freezing. This happens with videos on my mac, Youtube, spotify... pretty much across the board!

    Well, I'd open Font Book, it's included with OSX, & see what it says for Validate & Duplicates.
    I would also like to add I am new to Apple computers and I'm doing my best to stay up to par with whats what and understanding!
    No problem, we were all new to everything once, do let us know if you need more help or clatification.

  • Mac Enrollment Issue

    Hello,
    Having some trouble enrolling my first Mac device with SCCM 2012 SP1.
    I have installed the client and am trying to use the CMEnroll Tool with no success.
    Command I am using is this:
    CMEnroll -s fqdn.siteserver -ignorecertchainvalidation -u "domain\username"
    and on the client I recieve the error:
    Server connection failed. http response code is 500 and reason is internal server error.
    On the server in the EnrollmentServer.log I recieve this error:
    [6, PID:5748][02/01/2013 13:48:35] :WindowsIdentity is created for domain: domain user: username
    [6, PID:5748][02/01/2013 13:48:35] :validated user credentials
    [6, PID:5748][02/01/2013 13:48:35] :Handling RequestSecurityToken
    [6, PID:5748][02/01/2013 13:48:35] :claim identity name: domain\username
    [6, PID:5748][02/01/2013 13:48:35] :ConfigManager: RefreshCache: Creating Enrollment Profile 16777220
    [6, PID:5748][02/01/2013 13:48:35] :EnrollmentServiceProfile: GetDBCAs retrieved Template information:  
    [6, PID:5748][02/01/2013 13:48:35] :Template: ConfigMgrMacClientCertificate
    [6, PID:5748][02/01/2013 13:48:35] :CA: System.Collections.Generic.List`1[System.String]
    [6, PID:5748][02/01/2013 13:48:35] :The CA server.domain is in forest cac.local
    [6, PID:5748][02/01/2013 13:48:35] :Impersonating caller: domain\username
    [6, PID:5748][02/01/2013 13:48:35] :Revert back to self: NT AUTHORITY\NETWORK SERVICE
    [6, PID:5748][02/01/2013 13:48:35] :ConfigManager: Sending CA Success Status - ENROLLSRVMSG_CA_SUCCESS
    [6, PID:5748][02/01/2013 13:48:50] :ConfigManager: CA Chains count: 2
    [6, PID:5748][02/01/2013 13:48:50] :ConfigManager: ChainStatus error: RevocationStatusUnknown,Unknown error.;
    [6, PID:5748][02/01/2013 13:48:50] :ConfigManager: ChainStatus error: RevocationStatusUnknown,Unknown error.;OfflineRevocation,Unknown error.;
    [6, PID:5748][02/01/2013 13:48:50] :Microsoft.ConfigurationManagement.Enrollment.EnrollmentServerException: RevocationStatusUnknown,Unknown error.;OfflineRevocation,Unknown error.;
       at Microsoft.ConfigurationManagement.Enrollment.ConfigManager.SplitCACertChain(String base64cert)
       at Microsoft.ConfigurationManagement.Enrollment.ConfigManager.setCAChain(EnrollmentServiceProfile profile, WindowsIdentity requester)
       at Microsoft.ConfigurationManagement.Enrollment.ConfigManager.RefreshCache(Int32 enrollmentProfileId, EnrollmentRecordType type, String template, WindowsIdentity requester)
       at Microsoft.ConfigurationManagement.Enrollment.RequestHandler.ProcessRequestSecurityToken(RequestSecurityTokenType request, WindowsIdentity caller, ActionEnum action)
       at Microsoft.ConfigurationManagement.Enrollment.RequestHandler.EnrollDevice(Message messageRequest)
       at Microsoft.ConfigurationManagement.Enrollment.DeviceEnrollmentService.RequestSecurityToken(Message messageRequest)
    [6, PID:5748][02/01/2013 13:48:50] :FaultCode is: EnrollmentServer and reason is: EnrollmentServerException InitializeFailed
    Any ideas?

    Have you followed the instructions on these links fully?<o:p></o:p>
    Create the Cert Template:<o:p></o:p>
    http://technet.microsoft.com/en-us/library/gg682023.aspx#BKMK_client2008_cm2012<o:p></o:p>
    Go to Deploying the Client Certificate for Mac Computers 
    Setup SCCM and install client:
          http://www.jamesbannanit.com/2012/10/enrol-mac-os-x-clients-in-configuration-manager-2012-sp1/

  • Mac users having issues with my Site

    I just recently had a Mac user complain to me that my website wasn't working for him http://woodsshop.com/index.htm
    I'm wondering if the fact I edit my site using CS3 might be his problem?, but that's a wild guess on my part.
    he said
    " when I enter your web site...under "creative builders"  when I click on "kits", "plans" "japanese" "about us" or "contact us"  my computer freezes...in other words, it just see there, waiting for the site to come up and it never does.  No drop down windows or anything, its just that your site does not move from one area to the next smoothly.  Now this is on my 6 month new apple computer....and as I said, everwhere else I go, no problems....."
    I contacted my Host, they recommended he clear his cache, didn't help him.
    So I went and posted a question on the Mac Safari forum, asking if other Mac users were having issues, some of them are, some not, but enough are, and that has me concerne, how many others can't even access my site?
    Here's that discussion
    https://discussions.apple.com/thread/3880515
    I went and looked at my AW Stats and Mac users are just a small part of my traffic it looks like.
    [IMG]http://i11.photobucket.com/albums/a173/JoeWood_/Misc/AW-Stats.jpg[/IMG]
    So I'm Hoping someone here has some insight :-)

    Alright, this clears the air somewhat.
    Do one thing, if you have created the course, you must be aware about the answers, enroll yourself as a user and --
    Appear for the course, make sure, you answer all (or enough questions to score 85% marks.) Not just the quiz you have to make sure you view 50% of the slides completely. So that means, if the slide dureact for each slide is say 1minute and there are 40 slides, view a minimum of 20 slides completely to their 1 minute duration.
    Only then you would recieve a completed result.
    Please try the above scenario and verify you get a completion on your LMS. If you do, then check again your User reports and you will certainly find that your users had failed ne or the other criteria (Slide Views/ Quiz Score)
    Alternately, if you want to be linient enough to just mark completetion on Quiz Result, you can uncheck the Slide views option from Success/Completion Criteria, under Reporting.
    Good Luck!
    Anjaneai

  • Read posts but still can't resolve my mac/pc networking issues :(

    Hi everyone,
    I'll get right to it. I have a G4 10.4.7 imac which I've had hooked up to Westell Wirespeed dsl modem (allows up to 253 users when networked, Verizon provided modem and dsl service) via ethernet. Yesterday, I bought new a Toshiba Satellite A105-S4074 Notebook. 802.11 a/b/g enabled. Today, I bought a Lynksis Wireless-G broadband router in order to set up a little network.
    Problem - I connected the Lynksis to the Westell modem and my imac to the to one of the four ethernet ports on the back of the Lynksis. I turned on my notebook, for the first time, did the set up wizard for the notebook. Then I did the Lynksis set up wizard for wireless connection to the internet (notebook wireless button was switched to the "on" position). I'm able to get signal on the notebook but I'm not able to completely connect (can't access the internet or web pages).
    AND
    My imac won't connect at all while set up as I described above.
    The Lynksis does describe specifically PC compatibility but not Mac. I didn't think that would matter as I'm connecting the imac via ethernet cable to the Lynksis.
    My limited connection on the notebook also is not a secure connection. I'm limited on my PC knowledge and even though I haven't looked into this issue, I think that should be easy to make secure but I would also appreciate your input on correcting the security of the connection (just in case it's not as easy as I think). The Lynksis has a one touch "secure easy set-up" button on the front of it, but I'm obviously missing something(s) because I don't have a secure connection.
    I'd appreciate your help guy's.
    Thanks.
    Vanessa

    From your description is that you've got both the Westell and the LinkSys acting as a NAT device.
    Since the Westell modem allows you to have up to 253 devices on it's 'internal' network it's clear that it's using NAT (Network Address Translation) to share a single IP address from your ISP amongst those 253 devices.
    Now what you've done is added a LinkSys router into the loop using one of those 253 addresses. The default setup for the LinkSys is to do the same thing - take a single IP address from an upstream device (in this case the Westell modem) and share it amongst another 253 devices using NAT. That's likely to be your problem.
    You would be far better off configuring the LinkSys as a simple bridge rather than a router - that way it simply links the wireless network (including the Toshiba laptop) with the wired network (which includes the Westell, the iMac, and any other devices on the network).
    In this setup the Westell will continue to use NAT and essentially control the network, and everything should work much better.
    Check the LinkSys documentation for details on how to turn on its bridging mode.

Maybe you are looking for

  • How to unlock my iPhone 4?

    I purchased an iPhone 4 from Vodafone, staff told me I could unlock the phone for use on any carrier network via iTunes, but can't see how to do it. Am currently overseas and need this phone unlocked so that I can use various SIMs and networks wherev

  • Macbook Pro won't SD card :(

    I have tried absolutely everything! I don't know what happened as this has always worked for me, I am using Sandisk Ultra 32GB Micro SD card with an adapter and the Mac doesn't recognise it anywhere, even Disk Utility. I have tried connecting my came

  • Express doesn't show in Airport

    So I've got one of those Aiport Express.. which is good and all but I simply just can't get it to work. I've got a third-part access point delivering wireless internet in my house, and I'm trying to "put" my Airport Express on that network, so I can

  • I don't have my search field anymore, only the url field. I know I can seach in it, but I want my separate search field back. How do I do that?

    Not sure when it happened and I am sure it is just a setting or something, but I can't find where I get the search field back. I see it when I open the customize the tool bar, but it disappears when I close it. I want to search from Google and the UR

  • Photoshop Elements 12 Back-up Freezing on Catalog Size Calculation

    My Photoshop Elements 12 reminds me that, given number of new images added, catalog should be backed-up. At point in steps where file size being calculated (for both a full or incremental back-up) the percentage reported reaches 56% then stops. Syste