Intel vPro with wired 802.1x issue with domain name

Hello guys,
this issue is may not related to SCCM directly, but intel forums are really poor so i´d like to ask here...
The Case: We are currently provisioning our vPro chips with SCCM SP2 R3 and almost everthing worked as expected (Provisioning OK, OOB Console OK, PowerControl OK even TLS and Kerberos are working. But there is an issue with the 802.1x authentication. It
seems the vPro chips are not using the correct domain name. Lets say our DNS domain name is
vpro.com and the NETBIOS Name is coprvro . There are no child or other domains. vPro chips are presenting now
vpro\COMPUTERNAME$iME instead of vpro.com oder corpvro
so the Radius Server (Windows Server 2008 R2 - NPS) is saying ReasonCode 7 "...domain is not existing...". AuthenticationType and EAP Type are correct. Usually user- and computeraccounts are using
corpvro as domain name.

Hi Dan,
thank you for your reply. I've already done this in the second place using the SDK and winrm ($8021XProfileInstance.GetProperty("Domain")). I've no idea were SCCM is getting this domain name from. Its cutting off the top level domain extension,
may be SCCM is assuming that this equals the NETBIOS domain name but that is not the case. This is only a guess, in detail I need to know in fact on what basis SCCM is choosing the domain name, then i can fix this...
Intels SCS putting the correct NETBIOS domain name in the amt config, used certificates are the same...

Similar Messages

  • Windows 8.1 will not issue a Domain Name Request.

    I have a windows 8.1 system that will not issue a Domain Name Request to resolve a simple query such as www.microsoft.com.  It works OK in my Windows 7 system on the same computer.  I know this is happening because I run the Wireshark packet
    trace on each system. Windows 7 issues the request; Windows 8 does not.  I can flush the DNS cache with "ipconfig /flushdns, net stop dnscache, net start dnscache".  When I try to do email,  Thunderbird can't find the server; when
    I try to browse the internet, the browser(Opera, Chrome, Mozilla) can't resolver  the name.  ipconfig /all looks normal.  The Domain Name Server is hardwired (8.8.8.8, 8.8.4.4, or 208.67.222.222, 208.67.220.220).  Any ideas?

    Hi,
    If you ping  the server with its IP address, could it work? If so, it should be your Windows 8.1 DNS components problem.
    When this problem occures? If this problem just occures recently, it would be better to make system restore to revert your system to a former normal time point.
    In not, firstly, try to reinstall NIC driver for test. Also check Event Viewer if it identify the problem.
    As you said, you run Wireshark Packet. In my opinion, it would be better to run this tool to capture you network communication trace in Windows 8.1. This maybe could help you find the reason of the problem.
    In addition, Network Monitor also a good choice to captuer network trace.
    Roger Lu
    TechNet Community Support

  • OEAP600 with Wired 802.1X

    Hello everybody,
    I'm trying to find out if the Wired 802.1X capabilities associated with the OEAP-600 extend so far as including the dynamic assignment of attributes to the User's session? VLAN assignment would probably be the most useful, but QoS, Rate Limiting and ACL would also be handy.  These features all work on a standard switch and on a normal WLAN, but I can't find anything that discusses how the OEAP600 fits in to this?
    Any pointers greatly appreciated!
    Rich

    Hi Dan,
    thank you for your reply. I've already done this in the second place using the SDK and winrm ($8021XProfileInstance.GetProperty("Domain")). I've no idea were SCCM is getting this domain name from. Its cutting off the top level domain extension,
    may be SCCM is assuming that this equals the NETBIOS domain name but that is not the case. This is only a guess, in detail I need to know in fact on what basis SCCM is choosing the domain name, then i can fix this...
    Intels SCS putting the correct NETBIOS domain name in the amt config, used certificates are the same...

  • 802.1X Issues with Macbook Pro Core 2 Duo

    I've read a lot threads involving wireless issues with new Macbook Pros. I just received my MBP a week ago and have had issues with getting 802.1X to work consistently over 802.11g. It will authenticate and stay connected for an hour or so then the status will goto "Authenticating" and stick like that until I disconnect or restart the computer. The network I'm trying to connect to uses PEAP authentication through 802.1X. I have no problems with my wireless when I connect to an unsecured network. I've read about the driver fix for Macbook Pro wireless problems, but that does not apply to my Macbook since I'm using a later version of the Airport Card with 802.11N support. Does anyone have more information on this? Thanks
    Ryan

    Update: If I have no router password, "N" works.

  • Issue with create user and issue with Java Development tab

    I have two issues with EP,
    1. When i login with Super Admin user, i am unable to Create any user from User Admin tab. Do i have to change the settings of the Super Admin? or is there any criteria for creating the user?
    2. How to assign any user the Java Development tab. Though i login with a super admin user i am unable to see the Java Development role and when tried to assign the role, there were no searches for that Java....

    Hi Adi,
    by default the super administrater has got all permissions. Thus you should be able to create portal users when using a user assigned to the portal group Administrators.
    In order to help you with your first question we need more information. Please describe the malfunction in detail. Have a look into the log files and post related error messages.
    Regarding your second question: You will find the java development role in PCD
    pcd:portal_content/com.sap.pct/platform_add_ons/com.sap.pct.pdk/Roles/com.sap.pct.pdk.JavaDeveloper.
    If not, then you haven't installed the PDK business package in your portal.
    Go to service.sap.com, choose downloads and search the package (PDK should do it). Download the package, and deploy on your portal using SDM.
    Best regards,
    Martin

  • Issues with new Maverick Mail, issues with new Maverick Mail

    Everytime I use Mail a window opens asking me my password for my Icloud account.
    This started after I installed the new OS X Mavericks.

    Hi there,
    We have similar problems plus many more. We have spoken to repair company's who will not take the job on now as they know they cannot fix any issues with Mac updates.
    The lattest fix has not fixed my mail issues since the last update either!
    Its a shambles and all my settings are correct, we have checked them three times but nothing seems to work.
    Does anyone who of a reliable mail program for mac?  Im having to use my PC mail program now as Mac are so slow to repair there mistakes. Its costing our company thousands in downtime with the disruptive updates. Our Iphones dont work properly since thier last update either. One would have to ask whats going on with Mac? No preplys from there so called helplines.
    WHATS MAC GOING TO DO ABOUT IT???

  • Extremely Disappointed with iLife 11 - Third Issue with Software

    This is an open letter to software developers at Apple.
    I purchased iLife 11 on day 1. I've come to trust apple and their heretofore excellent work. I have to say I will think twice about buying your software again.
    My issues with software "that just works" because a closed environment...
    iPhoto was stuck in an upgrade loop for over 48 hours.
    iPhoto still won't put a book together.
    And today iMovie is stuck searching through iPhoto for a business drive even though I am home and have no way of connecting to the office drive. There's no option to cancel and open iMovie, just an error message that just keeps repeating, and repeating and repeating.
    Did you even Beta this software apple? OMG, this is the biggest p.o.s. experience I've ever had (and that includes windows software bugs). Seriously APPLE, I've converted about 50 individuals into appleheads. You need to issue an apology for this release, my experience has sucked hard.

    Hi
    a. Apple rarely reads this forum - use
    • www.apple.com/feedback/imovie.html
    b. free space on Your Start-up hard disk. How much ?
    c. Did You trash resp. programs pref files ?
    d. Repair permissions ?
    e. version of QuickTime (the heart of iMovie and FinalCut) ?
    Yours Bengt W

  • Problem with iWeb after associating a personal domain name with my MobileMe

    I think I did this by the book. I associated my personal domain name with my MobileMe account, then changed the CName pointer at GoDaddy to MobileMe (MM), then went back to MM and hit 'Done'. iWeb now lists my MM account as 'My account name (personal domain name). It took a little while for the DNS pointer to propogate, but now I can go to a browser, type in my personal domain name, and MM delivers my iWeb website as I wanted it to, apparently from my domain, not web.me.com. The problem is, as soon as the DNS propogated, MM delivers my MM site OK, but iWeb can't find the files for it anymore. All my pages immediately went red (unpublished) when I tried to update the site, and any attempt to Publish gives me this error "iWeb couldn’t connect to MobileMe. Make sure your Internet connection works and try again." I'm cable connected to an ADSL router, and Airport connected to a cable router, and neither service has dropped out. I've rebooted, and retried, and the website is up under my own domain, so GoDaddy and MM both got it right. What did I do wrong? Thanks, someone... anyone?

    This is now sort of resolved, but not very satisfactorily. One of the trainers at my local Appple Store found an old support issue in the archives going back to 2008, which blamed security settings for update problems. Coincidental with associating MobileMe with my personal domain, I had checked the privacy box and added an ID and PW to the site. That was the problem, not the personal domain, that was preventing iWeb from finding my MM account. Uncheck that box and my site happily updates. Of course, now I have a site that I cannot make private. In this case, not a show-stopper, but disappointing. I have reported it as a bug in the latest version of iWeb. Thanks for your help.

  • Reverse Proxy issue for domain name

    Hi All,
    We are in process of implementing reverse proxy to the SAP Portal and web dispatcher.
    We given all rewrite rules accordingly, The public IP also resolves the domain name also.
    Our domain is etender-aai.aero.
    When we given rewrite rule with the public IP reverse proxy is working fine.
    But when we given etender-aai.aero in rewrite rule its not working.
    Please help me in this.
    Thanks & Regards,
    Sreekanth

    Hi,
    If you want help, you'll have to explain clearly what is your configuration and what you want to achieve.
    I'm sorry to tell you that I absolutely did not nderstand anything about your problem....
    Do you try to publish your SAP Portal externally on the internet ?
    Do you use the web dispatcher as a reverse proxy ? or do you add an other reverse proxy (like Apache) in front of the web dispatcher ?
    Regards,
    Olivier

  • 802.1x - Issue with command: authentication open

    The issue we are running into is that when we initially deployed 802.1x we had the command “authentication open” on all of our switch ports. We ran a CscoWorks job last week Thursday to remove that command from all of our ports. Since that time we have ran into a couple of weird issues where the device was powered up but the switch port would show notconnect when doing a show int status but the speed would show a-1000 and duplex would show a-full. There would be no mac address listed when doing a “show mac add int ‘interface’” and the device would be in the MAB running state. This is happening on devices that are supposed to be doing 802.1x and MAB authentication, if we put the command “authentication open” back onto the port it showed connected and mac address. Now we have over 1000 switches on the network with this command removed and so far have only ran into a couple of these odd ball problem ports so at this time it is not happening widespread but would like to take care of the issue or figure out why this happening before it does.

    On the 2960's we are running 12.2(55)SE5, on the 6500's we are running 15.1(1)SY
    We didn't use any kind of ACL because we start all of our switch ports into a black hole vlan. I have been watching sessions from Cisco Live 2012 and looks like Cisco is now recommending that you don't go closed mode unless absolutely necessary because it is hard to maintain and function.

  • MAB and 802.1x issues with IP-phone

    I'm trying to use 802.1x to authenticate clients on my network with dynamic VLAN assignment from RADIUS. We have IP-Phones(powered by PoE) that only supports EAP-MD5, and we would rather use MAB(it also uses LLDP-MED for some settings) to authenticate the phones using the MAC-range from the phones vendor. The following scenario works perfect:
    Connect the phone and let it boot up(takes a while) and authenticate with MAB.
    Connect a computer in the phones data-port and let it authenticate with 802.1x(or fail and reach guest-vlan)
    However, the following scenario doesn't work:
    The computer is already connected to the phone
    The phone is then connected to the switch
    What happends now is that the computer is authenticated using 802.1x before the phone boots up and get's authenticated with MAB. When the phone is ready, it's authenticated with MAB and everything works. However, after a short period(let's say a minute), using `debug authentication all`, we see a "NEW LL MAC: phones mac" message(which is weird since the mac has already been MAB-authenticated), and then we are unable to contact the phone using ping. When I check `show mac address-table` it has now moved the mac from `Port Gi 0/12` to `Port Drop`. However, if I check `show mab interface Gi 0/12` or `show authentication sessions` it lists the phones-mac as `mab auth sucess `.
    Can anyone explain why the first scenario works, and not the second?
    The switch is a 3560E PoE 24p with IOS 12.2.58SE2. Sample of the switch-config:
    network-policy profile 1
    voice vlan 90
    interface GigabitEthernet0/12
    switchport mode access
    network-policy 1
    authentication control-direction in
    authentication event fail retry 1 action authorize vlan 60
    authentication event server dead action authorize vlan 60
    authentication event no-response action authorize vlan 60
    authentication event server alive action reinitialize
    authentication host-mode multi-domain
    authentication order mab dot1x
    authentication priority mab dot1x
    authentication port-control auto
    authentication periodic
    authentication violation replace
    mab
    dot1x pae authenticator
    dot1x timeout tx-period 5
    dot1x max-reauth-req 1
    spanning-tree portfast
    Btw, when we tried authenticating the phones using 802.1x too (EAP-MD5), there are NO problems in any of the scenarios. However, we want to use MAB instead of 802.1x to avoid the requirement of configuring the phones with a username and password. The RADIUS response was the same when using 802.1x as it is with MAB for the phones (including device-traffic-class=voice AV-pair).

    Hey. Yes, as specified in the last sentence in my post, the phone is placed in the Voice Domain, and both RADIUS and LLDP-MED (network policy profile 1) specifies voice vlan as 90.
    The weird thing is that everything works fine if both use 802.1x, and that there is only a problem when phone(using MAB) already has the computer connected to it, when the phone is turned on(connected to PoE-switch). It must be because the computer boots up and authenticates first I think.
    The phones are Snom 821.

  • Issue with ovi support page. issue with bought app...

    first if all i cannot fill inn support  form just becasue when im choosing issue tipe page is redirecting and i cant chose the issue tipe! email on [email protected] is also fails
    i ve got some problems with ovi store. some apps which were bought while ago (they are showed in my content bookmark in phone ovi store), but when i try to redonload them it tells me that i must buy them again! i ve got all confirmation emails with  numbers of my apps.
    strangeness lies in the fact that all the apps which i try to redownload are newer versions than i had. but i repeat ALL this apps are showed in my content, and they were bought by me. 

    Have the same problem.
    reset my phone and now i can't download previously bought apps

  • How Verizon WIreless Deals With A Customer's Issues With A Flawed Device

    (link removed)
    Let me start at the beginning…
    I have had a bad history with phones during my 6 years I been with Verizon Wireless(VZW). All the phones I had with them always have some manufacturer issues. I either had to pay a deductible or was allowed to exchange it for free due to it still being under warranty.  I had to go through this 14 times in under 6 years. For the most part, Verizon Wireless has been very helpful with these issues & the amazing service they provided as kept me a very loyal customer. These qualities even lead me to sign up for Verizon FiOS over Comcast when I moved into my new apartment.
    On February 17th, 2014, I received my tax refund. Most of it was going to repairs for my car, but for a birthday gift to me, I wanted to upgrade my phone. At the time, VZW had a deal to trade in your old phone & upgrade to a new phone. Your trade in got $100 taken off the cost of your new phone. I thought that was a sweet deal since the phone I had, The Motorola Razr Maxx HD was my 4th replacement to replace my original phone from when I first upgrade my phone with a new contract 2 years ago, The Motorola Droid 3. The Razr Maxx HD was a good phone but not what I wanted, It did what it needed to do & the technology was steller. Just not my first choice in a phone.
    Since the Droid 3 was no longer in production, i always had to get a replacement phone VZW saw fit for me to get. Now with my contract up & my opportunity to get a new phone, I knew what I wanted   I wanted the Samsung Galaxy Note 3 now. It has so many amazing features, apps & it is the perfect phone for someone my size. I can easily text with it, I do not feel I will crush the phone holding on to it & all of the hardware in it is like nothing on the market at that time. I been researching the phone months before it came out & I knew once I had the money, this is the phone I wanted.
    So I went to the VZW Store ready to make the exchange and have a phone I wanted finally for once in nearly 2 years. I got there to be helped my a gentleman named Teddy. He was eager to help me. I told him why I was there & instantly got the ball rolling. My phone I wanted was in stock, I was able to get $100 from the trade-in promotion. HE also informed me I could get a free tablet by just paying the taxes for it, A mere $15 & The Note 3 was on sale. I could walk out this day with a new phone AND a tablet for $172! So I agreed to it & all I had to do was pay. Then the problems started…
    I was told I could not pay with my debit card. This was due to an issue of a returned payment. An issue I had with VZW due to their company in October 2013 in which they took 9 days to process my monthly bill payment to only return it when the funds was still available to complete it. So I had to leave the store to find an ATM to withdrawal the cash so I could purchase the phone & tablet. Once I came back, we tried to finish the sale. Now I was told I could not trade in my phone due to the fact VZW did not allow me to make debit payments because of their own error. I was told i could pay full price for the phone and I could not get the tablet. I declined & left the store.
    Very upset, I called VZW’s customer service line to formally complain. They could do nothing to help me since no one, not even a supervisor could fix these restrictions to my account. This made me more upset, so I went above their head & reported my situation to The Better Business Bureau(BBB). Within 7 days, a Manager From VZW’s Home Headquarters, named Brian (removed), finally called me to resolve my issues. HE apologized, removed my account restrictions & was sending me A Galaxy Note 3 for my troubles free of charge. I wanted the tablet too but did not care at this point. I just wanted a phone I wanted for once & I can do without a tablet. I never went out of my way to get one before & I was not planning to now.
    On February 25, I received my new phone. I instantly fell in love. The phone was the perfect size for me & it worked just like every review I read online said it would. Then on February 27th, the phone began to have charging issues. The factory charging cable that came the the phone began to have issues charging the phone, then not recognizing the charger at all. I called customer service to make a complaint. This is when I learned for the first time that The Samsung Galaxy Note 3 has a defect with it’s charging cable & charging the device. They told me I could either mail the cable for a replacement or try to get the replacement at a store. So I decided to go to the same VZW store to get the replacement.
    Once I got there, I had to wait in line for 30 minutes to finally speak to someone. Once I did, I was told they had no chargers in store. All that could be done was call Samsung & have a replacement phone sent to me. I asked what would I do for a charger until then & they said I could use the micro USB charger from my last phone to charge it.
    So I mailed the charger to Samsung, who said it would take 8-10 days to get my replacement. During this time, the phone began to now stop holding a long charge. So I again called customer service. I was again told to go to the VZW store to get a replacement charger. I went back to the store again to be told they could do nothing for me since I did not have to original charger. All I the could do was sell me a mobile charger for 50% off. Since i need my phone, I had no choice. I had to spend $30 now on a device to help my faulty one.
    March 6th, my replacement charger arrived. I was happy because now I can charge my phone with the proper charger & get a full battery life from it. That same day the charger had the same issues again. So i instantly took it to the Verizon Store to be told I need to call customer service for a replacement phone. So I return home to see in my mailbox is my VZW bill. The statement says my bill is $400! Verizon Wireless & Brian (removed) had charged me full price for my phone despite what he told me when he called me.
    I instantly called his office to only get his answering machine. I left a very angry yet respectful message explaining my disgust with what he & VZW have done since I got this phone. I said I refuse to pay anything until this issue is fully resolved. I then proceeded to file another complaint to The BBB. This time I would get no response from VZW. Instead i had to call and chat online with their customer service lines for over a month to have a REFURBISHED device, a replacement battery & a generic charging cable sent to me. My phone still has charging issues & I must travel around DAILY with my mobile charger to make it a whole day to be able to use my device.
    Verizon Wireless and Brian (removed) will not resolve this issue for me. Instead they have suspended services to my phone and are forcing me to pay the full price for the phone or having my service “permanently discontinued”.
    I am left with no choice but to pay this by next month. I need my phone for personal, business & emergency reasons just like everyone else. I can not pay this AND an early termination fee. Verizon Wireless has done nothing to help me & now I am stuck in a contract for the next 16 months with a company that has done this to me during the last 2+ months. I have a improper working phone and they get $400 for it and Brian (removed) gets his commission.
    Before I pay this bill, I am making one last complaint to The BBB & I am spreading my story across social media like wildfire, I am hoping someone at Verizon Wireless sees this. MAYBE they will do the right thing. Then again, they had the chance to & have not….
    Mr. Brian (removed) & Verizon Wireless,
    My Name IS Reginald (removed). Due to months of complaints you should very well know who I am. Since you will NOT help me, I have no choice but to play by your rules and pay you ridiculous cost for a phone despite the act of what I was verbally told. You & your company you work for have had countess times to make this right & you have not. I might have to be stuck in a situation like this, but the entire internet will now learn of your actions & how you treat people. Maybe this will teach you all how to properly treat your paying customers. Someone can still make this right. You have my number, but you would have to reactivate it to contact me though.
    Regards,
    Reginald (removed)
    Edited as required by the Verizon Wireless Terms of Service
    Message was edited by: Admin Moderator

        Reginald, We absolutely want to make this a better experience. Would it be possible for us to work together in direct message. Please follow us and we can get started.
    Sheritah_vzw
    Follow us on Twitter
    @VZWSupport

  • Discovery issues with airport extreme and issues with airport utility

    I lost about 3 hours with connection issues while trying to add a second airport express. The airport Utility couldn't find any of the units anymore. After aging a couple of years and checking lots of forums (many suffered the same problems) I found this link
    http://support.apple.com/kb/HT1406#
    Which seemed to help me reset the units and find them again. Though I can't be certain if it was just luck, the airport utility and detection and resetting of the express and extreme seemed solved.
    I would add that this is an area that should be looked at by apple. It is not the first time that I have problems with the airport utility or the extreme.

    Check the cabling to the Base Station - make sure the modem is plugged into the Base Station's ethernet WAN port (ie the port labelled with the "circle of dots" icon).
    With the modem cabled to the Base Station - pull power to both for five minutes or so. Then plug the modem into power and wait a minute. Then plug the Base Station into power and wait a minute. Then try internet access again.
    If that still doesn't work:
    - on the Mac which can successfully connect to the internet when cabled directly to the modem, tell us what settings are found in System Preferences->Network->Show ethernet built in->PPPoE tab, and under the TCP/IP tab.
    - from either a PC or the Mac connected to the Base Station, run the Airport Admin Utility, select the name of your base station, click Configure, click on the Internet tab. Tell us what settings are found under that tab.

  • Solution for loss of DHCP with Win7 Home Group issues with FIOS Router

    Apparently the FIOS Router (Westell 9100 in my case) doesn't like the IPv6 that Homegroup uses.  I lost DHCP service on all three computers that have Win7 installed.  I could manually set the IPv4 addresses in the Network Connector options on my computer and every thing worked fine. If I tried to use DHCP for IPv4 I wound up with a private network address (169.xxx.xxx.xxx).
    DHCP for IPv4 worked fine adfter I disable IPv6 and the associated topology services.  I also removed the HomeGroup option from our network setup.
    If you want to use home group be prepared to manually set the IPv4 addresses in your network devices.
    Good luck

    Interesting, thanks for posting.
    Are these Windows 7 PCs that you installed 7 onto yourself, or ones that came with it? I have an HP laptop that came with Windows 7 already installed, no issues at all about IPv6 that I know of. IPv6 is still activated, works just fine on my FiOS Actiontec router, but maybe the Westell is just enough different to be sensitive to that.
    Strange.
    Justin
    Verizon FiOS TV, Internet, and phone
    QIP6416-P1, IMG 1.7C, Build 09.83
    Keller, TX 76248

Maybe you are looking for