Issues deploying Secondary Site

What is the best way to roll back a failed Secondary Site install?  When I originally installed it, it failed with a time out issue, and now when try to retry deploying it fails saying that the SQL version is unsupported, even though the Version of
SQL express was deployed from the primary server.
I assume I just select the site and select delete, but I want to make sure that it will roll back any changes made to the secondary site server. There isn't anything on the server I need to do so I can attempt another secondary site install?

Hi,
There is a part of a blog could help you.
 If the secondary site installation has failed, you will need to manually clean up the following before you attempt to reinstall.  To do this:
Delete the SMS registry key on the secondary site machine - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SMS
Delete the database created on the secondary site machine
to ensure the data files are removed.
(update 7/5/2013) If the database is a SQL Express version, uninstall the "Microsoft SQL Server 2012 (64-bit)" from Add/Remove Programs (ARP).
For more information:
http://blogs.technet.com/b/configmgrteam/archive/2013/07/02/known-issue-secondary-site-installation-failure-with-cumulative-update-2.aspx
Best Regards,
Joyce
We
are trying to better understand customer views on social support experience, so your participation in this
interview project would be greatly appreciated if you have time.
Thanks for helping make community forums a great place.

Similar Messages

  • Application deployment slow response at Secondary Site

    Hello All
    My company has 2 major locations around the country.  Each location has servers and workstations which are all on the same domain and connected by a rather fast WAN.
    What I Need Help With  - I'm having difficulty deploying software, OS, and updates to sites remote from my primary SCCM server.  Deployment takes extremely slow to install - almost one day to deploy on single machine.  Below is what I have set
    up in terms of SCCM Site Configuration.
    Site 1 (Contains two servers of Windows Server 2012)
    CA-Central Administration
    PK-Primary Site 
    Site 2 (Contain one server of Windows Server 2012)
    SS-Secondary Site (Role = DP , MP and all default roles associate with SS Site)
    Boundaries and Boundary Groups are configured with proper Site Assignment and DP.
    I have one application pkg which is successfully distributed on both DP's but client installation response is extremely slow on Secondary Site. I have also checked the network connectivity and its fine there is not bandwidth issue at all. 
    What will be reason for that ??? 
    REGARDS DANISH DANIE

    By going through these log files my issue is resolved, go for below mentioned belong for clear understanding that how client are communicating with DP and MP.
    execmgr.log
    MP_Location.log
    LocationServices.log
    http://blogs.technet.com/b/configmgrteam/archive/2010/01/14/troubleshooting-client-content-download-in-configuration-manager-2007.aspx
    REGARDS DANISH DANIE

  • Package Not deploying to secondary Site

    Dears,
    I have 1 primary site and 2 secondary site servers configured. I distributed software update and One Java installation (Bat file) to all 3 servers, its getting installed for clients which are reporting to primary server & in one secondary server but
    the packages are not getting downloaded to 3rd server which is acting as secondary site server. I checked Bits, redistributed packages but no luck. Kindly help what to troubleshoot in this case.
    Regards,
    Anil Suthar

    Jeff, 
    Thank you for reply.
    This is resolved after changing secondary DP setting, "Allow Clients to connect anonymously".
    When i checked ccmmessaging.log i found "security context failed due to Integrated Windows Authentication failure". Dont know why, but after enabling above settings issue got resolved..

  • Secondary site clients inactive

    hi
    I am having issues with SCCM 2012 R2 and secondary sites going inactive. We have four secondary sites and I am having issues with two of them. Clients were rolled out succesfully on the sites but have now gone
    inactive. Heartbeat shows it has not contacted them recently. The clients themselves are working as i can roll out SCEP or sftware updates and they show on the clients and deploy but they still say inactive in the console. 
    I have tried removing and re-adding the management point as suggested in a few forums and the SQL logins but none of them have helped.
    Site and boundaries look correct and the logs show the clients successfully connecting to the local sites management point, but still show up as inactive, as does the site servers themselves. They are about 10% of clients on the site that are working but
    cannot see any difference in those.
    The other 2 secondary sites are working ok. 
    Any ideas?
    sg

    Hi,
    >>secondary sites going inactive
    Have you checked site status of the inactive secondary site in the Monitoring workspace? Any error?
    You could also check Component Status to see if there is any error.
    Best Regards,
    Joyce
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • How Can I Remove a Secondary Site When The Server no Longer Exists?

    This organisation deployed a new SCCM site and then decommissioned the server before successfully removing either the site or the server/roles.
    I tried to force the removal of the site which failed:
    C:\Program Files\Microsoft Configuration Manager\bin\X64\00000409>preinst.exe /delsite xxx
    Microsoft System Center 2012 Configuration Manager v5.00 (Build 7804)
    Copyright (C) 2011 Microsoft Corp.
    Cannot find site [xxx] in the site control data in the database. Checking in ServerData in the database.
    Failed to execute SQL query.
    The secondary site is showing in the console as 'deleting'.
    Can anyone advise the best way to proceed?
    Thanks.

    I had the same issue and this is what they sent me... I used it and it worked for me.
    1.       Please follow these steps to manually delete the
    Secondary Site from the Secondary site server
    2.       We also used the PREINST tool to remove the pending jobs.
    3.       On the ConfigMgr primary site (parent) computer, click Start, and then click Run.
    4.       Type cmd in the Open box, and then click OK.
    5.       At the command prompt, type cd\, and then press the ENTER key.
    6.       Type cd sms\bin\i386\00000409, and then press the ENTER key.
    7.       To remove any pending or active jobs to a site, type Preinst /DELJOB SiteCode , and then press the ENTER key.
    8.       We deleted the Secondary Site from the console of parent  site.
    9.       We removed the Sender Addresses from the Configuration Manager console, as explained below.
    10.   Click Start, point to All Programs, point to Systems Management Server, and then click ConfigMgr Administrator Console.
    11.   Locate the Site Settings\Addresses subtree.
    12.   Right-click the address for the failed secondary site, and then click Delete.
    13.   Then we cleaned the registry, by taking the backup of the HKLM Node
    ·         HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SMS
    ·         HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NAL
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SMS_Executive
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SMS_Site_Component_Manager
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SMS_Bootstrap
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CLISVC
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SMS_Discovery_Data_Manager
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SMS_Lan_Sender
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SMS_Scheduler
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SMS_Site_Backup
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SMS_Software_Metering_Processor
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SMS_Status_Manager
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CLISVC
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SMS_BOOTSTRAP
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SMS_EXECUTIVE
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SMS_HARDWARE_INVENTORY_AGENT_SERVICE
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SMS_KEY_CREATION_SERVICE
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SMS_SERVER_BOOTSTRAP_servername
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SMS_SITE_COMPONENT_MANAGER
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SMS Client
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SMS Performance Data Provider
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SMS Provider
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SMS Remote Control
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SMS Server
    ·         HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SmsClient
    Thanks Lavelle, however your instructions are clearly for SCCM 2007:
    11.   Locate the Site Settings\Addresses subtree. 
    12.   Right-click the address for the failed secondary site,
    and then click Delete. 
    Can you confirm you have run these steps on your own SCCM 2012 site?

  • SCCM 2012 Clients at Secondary Site don't update and shows status as INACTIVE

    I have 1 Primary site and 1 Secondary sites. I have setup Secondary site Boundaries using IP subnet.  I see that the systems from secondary
    site show in the console and they all have clients installed but however 60% of the system shows client activity as INACTIVE and not receiving any heartbeat DDR none of the system showing hardware inventory.   I am not positive
    where to look as far as logs are concerned.  I think the clients aren't receiving policy like they should.
    Just to give a brief idea, Secondary Site server crashed and we had to rebuild the server and re install secondary site after rebuilding all the
    problem. Everything is working fine in Primary site.
    Secondary site is communicating with primary site MP and DP
    I have checked MPcontrol.log it shows status as OK
    I am able to install client through console but yes when I check the configuration manager properties it shows CCM Notification Agent as DISSABLED
    and in the Action Tab Machine and User policy are the only cycles showing.
    Checked replmgr.log and rclctrl.log but it’s not showing any error
    Only log file which shows error is bgdserver.log  ( pasting log errors )
    ERROR: SQL exception when retrieve client certificate from DB. Exception: The EXECUTE permission was denied on the object 'sp_GetPublicKeyForSMSID', database 'CM_PRI',
    schema 'dbo'. -2146232060           SMS_NOTIFICATION_SERVER     05-07-2014 12:09:01               3968 (0x0F80)
    ERROR: Can't do post authentication without client certificate stored in regsitration.            SMS_NOTIFICATION_SERVER    
    05-07-2014 12:09:01                3968 (0x0F80)
    ERROR: Failed to authenticate with client [::ffff:10.5.55.88]:49623.        SMS_NOTIFICATION_SERVER     05-07-2014
    12:09:01               3968 (0x0F80)
    ERROR: SQL exception when retrieve client certificate from DB. Exception: The EXECUTE permission was denied on the object 'sp_GetPublicKeyForSMSID', database 'CM_PRI',
    schema 'dbo'. -2146232060           SMS_NOTIFICATION_SERVER     05-07-2014 12:09:01               3968 (0x0F80)
    ERROR: Can't do post authentication without client certificate stored in regsitration.            SMS_NOTIFICATION_SERVER    
    05-07-2014 12:09:01                3968 (0x0F80)
    ERROR: Failed to authenticate with client [::ffff:10.5.62.68]:49923.        SMS_NOTIFICATION_SERVER     05-07-2014
    12:09:01               3968 (0x0F80)
    ERROR: SQL exception when retrieve client certificate from DB. Exception: The EXECUTE permission was denied on the object 'sp_GetPublicKeyForSMSID', database 'CM_PRI',
    schema 'dbo'. -2146232060           SMS_NOTIFICATION_SERVER     05-07-2014 12:09:06               3968 (0x0F80)
    ERROR: Can't verify signature in message without client certificate for client SCCM GUID:B47059B1-D4E4-41A2-BC88-486A597FE399               
    SMS_NOTIFICATION_SERVER     05-07-2014 12:09:06               3968 (0x0F80)
    ERROR: Invalid hook to be decoded. Authentication                SMS_NOTIFICATION_SERVER    
    05-07-2014 12:09:06               3968 (0x0F80)
    ERROR: Failed to decode message body (<BgbSignInMessage TimeStamp="2014-07-05T06:39:01Z"><ClientType>SCCM</ClientType><ClientVersion>5.00.7804.1000</ClientVersion><ClientID>GUID:B47059B1-D4E4-41A2-BC88-486A597FE399</ClientID></BgbSignInMessage>)
    with message header
    Help me resolve this issue as I am struggling to resolve this for almost 2 weeks.
    Please let me know which logs are helpful and I'll try to add it to replies.

    Hi,
    Quote:"see that the systems from secondary site show in the console and they all have clients installed but however 60% of the system shows client activity as INACTIVE and not receiving any heartbeat DDR none of the system showing hardware inventory. "
    So not all the clients show inactive? Have you checked the logs in an inactive client? Such as ClientIDManagerStartup.log.
    Have you checked Secondary Site server's computer name from SQL logins? You could try to remove this account, wait a while, recreate the same computeraccount login with sysadmin access. (http://social.technet.microsoft.com/Forums/en-US/d5383c23-6b71-47cc-9fad-fda82a44a3aa/secondary-site-showing-inactive-clients?forum=configmanagerdeployment)
    You could use Configuration Analyzer for System Center 2012 R2 to troubleshoot issues.
    http://technet.microsoft.com/en-us/library/dn469435.aspx
    Best Regards,
    Joyce
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Uninstalling Secondary Site Server through SW Delivery fails

    We have migrated to SCCM2012
    and now need to uninstall our
    SCCM 2007 Secondary Siteserver.
    Since we have 300 Secondary Site Server
    in the Hirarchy, the uninstall
    of the software must be distributed.
    We have to create a task sequence,
    in which the following steps are
    performed:
    Put the server in the SCOM
    Maintenance Mode
    Stop SCCM services SMS_SITE_COMPONENT_MANAGER
    and SMS_EXECUTIVE
    Uninstalling the Secondary Siteserver with the
    Command "{install path} \setup.exe /deinstall"
    Cleanup of folders and files that are left
    Restarting the Server
    Take server out of the SCOM
    Maintenance Mode
    The uninstallation works well on all Windows Server 2008 R2 Server. But not on the Windows Server 2003. There we get errors "Failed to open key Software\Microsoft\SMS\47006C006F00620061006C005C007B00350031004100300031003600420036002D0046003000440045002D0034003700350032002D0042003900370043002D003500340045003600460033003800360041003900310032007D00\SMSTS"
    and "MP name must be set in an environment variable" and "Fatal error is returned in execution of the action (Uninstall Secondary Site). The system cannot find the file specified. (Error: 80070002; Source: Windows)".
    After this errors, the Task Sequence Deployment aborts.
    Has anybody a solution for this situation?
    Here is the SMSTS.Log
    !--------------------------------------------------------------------------------------------! TSManager 26.02.2014 05:16:02 4392 (0x1128)
    Successfully completed the action (Set TS Variable SSS_Uninstall to True) with the exit win32 code 0 TSManager 26.02.2014 05:16:02 4392 (0x1128)
    Set authenticator in transport TSManager 26.02.2014 05:16:02 4392 (0x1128)
    Set a global environment variable _SMSTSLastActionRetCode=0 TSManager 26.02.2014 05:16:02 4392 (0x1128)
    Set a global environment variable _SMSTSLastActionSucceeded=true TSManager 26.02.2014 05:16:02 4392 (0x1128)
    Clear local default environment TSManager 26.02.2014 05:16:02 4392 (0x1128)
    Updated security on object K:\_SMSTaskSequence. TSManager 26.02.2014 05:16:02 4392 (0x1128)
    Set a global environment variable _SMSTSNextInstructionPointer=25 TSManager 26.02.2014 05:16:02 4392 (0x1128)
    Set a TS execution environment variable _SMSTSNextInstructionPointer=25 TSManager 26.02.2014 05:16:02 4392 (0x1128)
    Set a global environment variable _SMSTSInstructionStackString=0 18 19 22 TSManager 26.02.2014 05:16:02 4392 (0x1128)
    Set a TS execution environment variable _SMSTSInstructionStackString=0 18 19 22 TSManager 26.02.2014 05:16:02 4392 (0x1128)
    Save the current environment block TSManager 26.02.2014 05:16:02 4392 (0x1128)
    Start executing an instruction. Instruction name: Uninstall Secondary Site. Instruction pointer: 25 TSManager 26.02.2014 05:16:03 4392 (0x1128)
    Set a global environment variable _SMSTSCurrentActionName=Uninstall Secondary Site TSManager 26.02.2014 05:16:03 4392 (0x1128)
    Set a global environment variable _SMSTSNextInstructionPointer=25 TSManager 26.02.2014 05:16:03 4392 (0x1128)
    Set a local default variable SMSTSDisableWow64Redirection TSManager 26.02.2014 05:16:03 4392 (0x1128)
    Set a local default variable _SMSTSRunCommandLineAsUser TSManager 26.02.2014 05:16:03 4392 (0x1128)
    Set a global environment variable _SMSTSLogPath=C:\WINDOWS\CCM\Logs\SMSTSLog TSManager 26.02.2014 05:16:03 4392 (0x1128)
    Evaluating an AND expression TSManager 26.02.2014 05:16:03 4392 (0x1128)
    Evaluating a file condition expression TSManager 26.02.2014 05:16:03 4392 (0x1128)
    Expand a string: E:\Program Files\Microsoft Configuration Manager\bin\i386\smsexec.exe TSManager 26.02.2014 05:16:03 4392 (0x1128)
    Expand a string:  TSManager 26.02.2014 05:16:03 4392 (0x1128)
    Expand a string:  TSManager 26.02.2014 05:16:03 4392 (0x1128)
    Expand a string:  TSManager 26.02.2014 05:16:03 4392 (0x1128)
    Expand a string:  TSManager 26.02.2014 05:16:03 4392 (0x1128)
    The condition for the action (Uninstall Secondary Site) is evaluated to be true TSManager 26.02.2014 05:16:03 4392 (0x1128)
    Expand a string: smsswd.exe /run: "E:\Program Files\Microsoft Configuration Manager\bin\i386\setup.exe" /deinstall TSManager 26.02.2014 05:16:03 4392 (0x1128)
    Expand a string:  TSManager 26.02.2014 05:16:03 4392 (0x1128)
    Start executing the command line: smsswd.exe /run: "E:\Program Files\Microsoft Configuration Manager\bin\i386\setup.exe" /deinstall TSManager 26.02.2014 05:16:03 4392 (0x1128)
    !--------------------------------------------------------------------------------------------! TSManager 26.02.2014 05:16:03 4392 (0x1128)
    Expand a string: WinPEandFullOS TSManager 26.02.2014 05:16:03 4392 (0x1128)
    Executing command line: smsswd.exe /run: "E:\Program Files\Microsoft Configuration Manager\bin\i386\setup.exe" /deinstall TSManager 26.02.2014 05:16:03 4392 (0x1128)
    [ smsswd.exe ] InstallSoftware 26.02.2014 05:16:03 11464 (0x2CC8)
    PackageID = '' InstallSoftware 26.02.2014 05:16:03 11464 (0x2CC8)
    BaseVar = '', ContinueOnError='' InstallSoftware 26.02.2014 05:16:03 11464 (0x2CC8)
    ProgramName = '"E:\Program Files\Microsoft Configuration Manager\bin\i386\setup.exe" /deinstall' InstallSoftware 26.02.2014 05:16:03 11464 (0x2CC8)
    SwdAction = '0001' InstallSoftware 26.02.2014 05:16:03 11464 (0x2CC8)
    Working dir 'not set' InstallSoftware 26.02.2014 05:16:03 11464 (0x2CC8)
    Executing command line: Run command line InstallSoftware 26.02.2014 05:16:03 11464 (0x2CC8)
    Process completed with exit code 0 InstallSoftware 26.02.2014 05:31:19 11464 (0x2CC8)
    Command line returned 0 InstallSoftware 26.02.2014 05:31:19 11464 (0x2CC8)
    Process completed with exit code 0 TSManager 26.02.2014 05:31:19 4392 (0x1128)
    !--------------------------------------------------------------------------------------------! TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Successfully completed the action (Uninstall Secondary Site) with the exit win32 code 0 TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Failed to open key Software\Microsoft\SMS\47006C006F00620061006C005C007B00350031004100300031003600420036002D0046003000440045002D0034003700350032002D0042003900370043002D003500340045003600460033003800360041003900310032007D00\SMSTS TSManager 26.02.2014
    05:31:19 4392 (0x1128)
    Failed to open key Software\Microsoft\SMS\47006C006F00620061006C005C007B00350031004100300031003600420036002D0046003000440045002D0034003700350032002D0042003900370043002D003500340045003600460033003800360041003900310032007D00\SMSTS TSManager 26.02.2014
    05:31:19 4392 (0x1128)
    MP name must be set in an environment variable TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Non fatal error 0x80004005 in sending task sequence execution status message to MP TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Set a global environment variable _SMSTSLastActionRetCode=0 TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Failed to open key Software\Microsoft\SMS\47006C006F00620061006C005C007B00350031004100300031003600420036002D0046003000440045002D0034003700350032002D0042003900370043002D003500340045003600460033003800360041003900310032007D00\SMSTS TSManager 26.02.2014
    05:31:19 4392 (0x1128)
    Failed to set a global environment variable _SMSTSLastActionRetCode=0.
    The system cannot find the file specified. (Error: 80070002; Source: Windows) TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Clear local default environment TSManager 26.02.2014 05:31:19 4392 (0x1128)
    TS::Execution::CCommandLineInstruction::Execute() failed with the error code 80070002 TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Fatal error is returned in execution of the action (Uninstall Secondary Site).
    The system cannot find the file specified. (Error: 80070002; Source: Windows) TSManager 26.02.2014 05:31:19 4392 (0x1128)
    An error (0x80070002) is encountered in execution of the task sequence TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Failed to open key Software\Microsoft\SMS\47006C006F00620061006C005C007B00350031004100300031003600420036002D0046003000440045002D0034003700350032002D0042003900370043002D003500340045003600460033003800360041003900310032007D00\SMSTS TSManager 26.02.2014
    05:31:19 4392 (0x1128)
    Failed to open key Software\Microsoft\SMS\47006C006F00620061006C005C007B00350031004100300031003600420036002D0046003000440045002D0034003700350032002D0042003900370043002D003500340045003600460033003800360041003900310032007D00\SMSTS TSManager 26.02.2014
    05:31:19 4392 (0x1128)
    MP name must be set in an environment variable TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Non fatal error 0x80004005 in sending task sequence execution status message to MP TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Failed to open key Software\Microsoft\SMS\47006C006F00620061006C005C007B00350031004100300031003600420036002D0046003000440045002D0034003700350032002D0042003900370043002D003500340045003600460033003800360041003900310032007D00\SMSTS TSManager 26.02.2014
    05:31:19 4392 (0x1128)
    Failed to open key Software\Microsoft\SMS\47006C006F00620061006C005C007B00350031004100300031003600420036002D0046003000440045002D0034003700350032002D0042003900370043002D003500340045003600460033003800360041003900310032007D00\SMSTS TSManager 26.02.2014
    05:31:19 4392 (0x1128)
    Failed to open key Software\Microsoft\SMS\47006C006F00620061006C005C007B00350031004100300031003600420036002D0046003000440045002D0034003700350032002D0042003900370043002D003500340045003600460033003800360041003900310032007D00\SMSTS TSManager 26.02.2014
    05:31:19 4392 (0x1128)
    Task Sequence Engine failed! Code: 80070002 TSManager 26.02.2014 05:31:19 4392 (0x1128)
    **************************************************************************** TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Task sequence execution failed with error code 80070002 TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Cleaning Up. TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Removing Authenticator TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Failed to open key Software\Microsoft\SMS\47006C006F00620061006C005C007B00350031004100300031003600420036002D0046003000440045002D0034003700350032002D0042003900370043002D003500340045003600460033003800360041003900310032007D00\SMSTS TSManager 26.02.2014
    05:31:19 4392 (0x1128)
    Successfully unregistered Task Sequencing Environment COM Interface. TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Executing command line: "C:\WINDOWS\CCM\TsProgressUI.exe" /Unregister TSManager 26.02.2014 05:31:19 4392 (0x1128)
    ==========[ TsProgressUI started in process 12220 ]========== TsProgressUI 26.02.2014 05:31:19 7740 (0x1E3C)
    Unregistering COM classes TsProgressUI 26.02.2014 05:31:19 7740 (0x1E3C)
    Shutdown complete. TsProgressUI 26.02.2014 05:31:19 7740 (0x1E3C)
    Process completed with exit code 0 TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Successfully unregistered TS Progress UI. TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Failed to open key Software\Microsoft\SMS\47006C006F00620061006C005C007B00350031004100300031003600420036002D0046003000440045002D0034003700350032002D0042003900370043002D003500340045003600460033003800360041003900310032007D00\SMSTS TSManager 26.02.2014
    05:31:19 4392 (0x1128)
    Failed to open key Software\Microsoft\SMS\47006C006F00620061006C005C007B00350031004100300031003600420036002D0046003000440045002D0034003700350032002D0042003900370043002D003500340045003600460033003800360041003900310032007D00\SMSTS TSManager 26.02.2014
    05:31:19 4392 (0x1128)
    Getting active request access handle TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Error opening HKEY_LOCAL_MACHINE\Software\Microsoft\SMS\Task Sequence. code 80070002 TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Error - could not get package and program IDs. code 80070002 TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Failed to open the task sequence key HKLM\Software\Microsoft\SMS\Task Sequence. Error code 0x80070002 TSManager 26.02.2014 05:31:19 4392 (0x1128)
    Start to cleanup TS policy TSManager 26.02.2014 05:31:19 4392 (0x1128)
    End TS policy cleanup TSManager 26.02.2014 05:31:20 4392 (0x1128)
    RegOpenKeyExW failed for Software\Microsoft\SMS\Task Sequence TSManager 26.02.2014 05:31:20 4392 (0x1128)
    GetTsRegValue() failed. 0x80070002. TSManager 26.02.2014 05:31:20 4392 (0x1128)
    End program:  TSManager 26.02.2014 05:31:20 4392 (0x1128)
    Error executing Task Sequence Manager service. Code 0x80070002 TSManager 26.02.2014 05:31:20 4392 (0x1128)
    Sending error status message TSManager 26.02.2014 05:31:20 4392 (0x1128)
    Failed to open key Software\Microsoft\SMS\47006C006F00620061006C005C007B00350031004100300031003600420036002D0046003000440045002D0034003700350032002D0042003900370043002D003500340045003600460033003800360041003900310032007D00\SMSTS TSManager 26.02.2014
    05:31:20 4392 (0x1128)
    Failed to open key Software\Microsoft\SMS\47006C006F00620061006C005C007B00350031004100300031003600420036002D0046003000440045002D0034003700350032002D0042003900370043002D003500340045003600460033003800360041003900310032007D00\SMSTS TSManager 26.02.2014
    05:31:20 4392 (0x1128)
    MP name must be set in an environment variable TSManager 26.02.2014 05:31:20 4392 (0x1128)
    Non fatal error 0x80004005 in sending task sequence execution status message to MP TSManager 26.02.2014 05:31:20 4392 (0x1128)
    Successfully finalized logs to SMS client log directory from C:\WINDOWS\CCM\Logs TSManager 26.02.2014 05:31:20 4392 (0x1128)
    Kind regards Stefan Somogyi

    Hi,
    When removing a secondary site using the Delete Secondary Site Wizard, you must choose whether to delete or uninstall the secondary
    site:
    Deleting the site will delete all information about the site and its resources from the Configuration Manager site database at its
    parent site, but it will leave the Configuration Manager secondary site installed on the secondary site computer. Select this option if you have already manually uninstalled the secondary site using Configuration Manager Setup at the secondary site computer.
    When Configuration Manager 2007 sites are deleted, the deleted site information is only deleted from the deleted site's direct parent site. Site deletion
    information is not propagated up the hierarchy to grandparent sites. In order to delete the site from the site database at sites above the deleted site's direct parent site, the hierarchy maintenance tool (Preinst.exe) must be run on every primary site above
    the deleted site's parent primary site using the command Preinst /delsite. For more information about the hierarchy maintenance tool, see
    Hierarchy Maintenance Tool (Preinst.exe).
    Refer to:
    How to Remove a Secondary Site Using the Configuration Manager Console
    Thanks, Prabha G

  • Version of SQL Server Express for a Secondary Site in Configuration Manager 2012 R2

    Hi,
    I want to install a secondary site in my Configuration Manager 2012 R2. I want to install the SQL Server Express in a diferente drive. To do so, I want to previous install the SQL Server Express.
    Can I use the SQL Server 2014 Express?
    Thanks in advance...
    Dmsousa

    Sorry, going to be blunt here, but this is why "best practices" are useless. If you don't know the "why" of the best practice and when to apply it, it will cause you to do things that simply aren't necessary (or even harmful) by
    blindly trying to apply them. It is simply is not necessary for secondary sites for perf or any other reason. Also, if this is a VM, then your virtual disks will most likely be on the same physical disks which means you do *not* in any way gain any perf benefits
    anyway (perf benefits come from have additional physical spindles -- logical separation is just that *logical*).
    You have far bigger challenges ahead of you, push the easy button on this one, let ConfigMgr deploy SQL Express for you and move on.
    Jason | http://blog.configmgrftw.com | @jasonsandys

  • SCCM 2012 Secondary site Client Communication for SUP

     Hi,
    We have an SCCM 2012 Setup and here is the design CAS-->Primary-->Secondary site servers.
    SUP is configured for Secondary site too. Boundaries are defined with IP Address Range and is proper.
    Some clients are comminicating to Secondary site for updates. Downloading successfully and installing the software.
    But some of the clients are communicating to primary site for updates and retain with the status "Downloading update"
    I have checked the locationservices.log and it is fluctuating between Primary and secondary MP.
    2 proxy MP errors in the last 10 minutes, threshold is 5. LocationServices 4/5/2013 11:35:59 AM 768 (0x0300)
    Executing Task LSSiteRoleCycleTask LocationServices 4/5/2013 11:51:59 AM 4200 (0x1068)
    1 proxy MP errors in the last 10 minutes, threshold is 5. LocationServices 4/5/2013 11:51:59 AM 4200 (0x1068)
    Executing Task LSSiteRoleCycleTask LocationServices 4/5/2013 11:51:59 AM 5648 (0x1610)
    2 proxy MP errors in the last 10 minutes, threshold is 5. LocationServices 4/5/2013 11:51:59 AM 5648 (0x1610)
    I have also checed "DataTransferService.log" and found more errors.
    Error retrieving manifest (0x800704cf).  Will attempt retry 7 in 1920 seconds. DataTransferService 4/5/2013 11:51:59 AM 5576 (0x15C8)
    DTSJob {141CB5AE-8EF2-464D-8D8C-68B868EE7F7B} in state 'DownloadingManifest'. DataTransferService 4/5/2013 11:51:59 AM 4200 (0x1068)
    Failed to send request to /SMS_DP_SMSPKG$/1fd86ee1-ece0-41ae-a2b8-5a2b305746d4 at host xxxxxxxx.xxxxxxx.com, error 0x2efe DataTransferService 4/5/2013 11:51:59 AM 4200 (0x1068)
    [CCMHTTP] ERROR: URL=https://xxxxxxxx.xxxxxxx.com:443/SMS_DP_SMSPKG$/1fd86ee1-ece0-41ae-a2b8-5a2b305746d4, Port=443, Options=192, Code=12030, Text=ERROR_WINHTTP_CONNECTION_ERROR DataTransferService 4/5/2013 11:51:59 AM 4200 (0x1068)
    Raising event:
    instance of CCM_CcmHttp_Status
     ClientID = "GUID:0DA907D5-1709-4B10-B627-61E289FD7149";
     DateTime = "20130405062159.643000+000";
     HostName = "xxxxxxxx.xxxxxxx.com";
     HRESULT = "0x80072efe";
     ProcessID = 4260;
     StatusCode = 600;
     ThreadID = 4200;
     DataTransferService 4/5/2013 11:51:59 AM 4200 (0x1068)
    Successfully sent location services HTTPS failure message. DataTransferService 4/5/2013 11:51:59 AM 4200 (0x1068)
    Error sending DAV request. HTTP code 600, status '' DataTransferService 4/5/2013 11:51:59 AM 4200 (0x1068)
    GetDirectoryList_HTTP mapping original error 0x80072efe to 0x800704cf. DataTransferService 4/5/2013 11:51:59 AM 4200 (0x1068)
    GetDirectoryList_HTTP('https://xxxxxxxx.xxxxxxx.com:443/SMS_DP_SMSPKG$/1fd86ee1-ece0-41ae-a2b8-5a2b305746d4') failed with code 0x800704cf. DataTransferService 4/5/2013 11:51:59 AM 4200 (0x1068)
    Error retrieving manifest (0x800704cf).  Will attempt retry 7 in 1920 seconds. DataTransferService 4/5/2013 11:51:59 AM 4200 (0x1068)
    my query is how some of the clients are communicating primary site server for updates even though the boundary details are properly configured and Secondary site is configured with sup. Also need to know (as per the log "DataTransferService.log")how
    come the clients are communicating SSL port for updates. Plz help in resolving the issue.

    Hi Kent,
    Thanks for the reply.
    Primary and secondary sites are connected over WAN and we have around 2000 clients which are reporting to Secondary site.
    Considering the WAN bandwidth utiliztaion and number of clients on secondary site we have configured the SUP role.
    Not all the clients are with the above error message around 40%-50% of the clients are with above stated error message.
    Plz let me know what is the error message indicates and do we need to reffer any other logs for indepth analysis.
    Locationservices.log is with fluctuating connectivity
    2 proxy MP errors in the last 10 minutes, threshold is 5. LocationServices 4/5/2013 11:35:59 AM 768 (0x0300)
    Executing Task LSSiteRoleCycleTask LocationServices 4/5/2013 11:51:59 AM 4200 (0x1068)
    1 proxy MP errors in the last 10 minutes, threshold is 5. LocationServices 4/5/2013 11:51:59 AM 4200 (0x1068)
    Executing Task LSSiteRoleCycleTask LocationServices 4/5/2013 11:51:59 AM 5648 (0x1610)
    2 proxy MP errors in the last 10 minutes, threshold is 5. LocationServices 4/5/2013 11:51:59 AM 5648 (0x1610)
    how come the clients are communicating SSL port for updates. Plz help in resolving the issue.

  • Uninstall and Reinstall Secondary Site Management Point Role

    Dear Brothers,
    I have an issue with one of my SCCM 2012 Sp1 with CU3 Secondary Site Server which the client failed to install on the actual server due to a client issue observed in the CCMSetup.log.
    Observation Regarding the issue:
    Issue Detail No1.
    SCCM Client is not installing to my Secondary Site Server with site code (XYZ), after all the site server are also clients in SCCM hierarchy so it self needs SCCM Client as well. 
    CCMSetup.log:
    "Error 25150. Setup was unable to register the CCM_Service_HostingConfiguration endpoint" when you try to install the client agent in Configuration Manager"
    According to http://support.microsoft.com/kb/2905359
    the solution is to :
    1. Uninstall the management point role. 
    2. Reinstall the client agent on the management point computer. 
    3. Reinstall the management point role.
    Issue Detail No 2.
    When I am trying to uninstall the Management Point Role via SCCM Console as part of the solution posted on the above KB Article, unfortunately the delete or uninstall option is been greyed out.
    Now a lot of discussion on the topic "Can not remove management point role is greyed out "under this thread
    http://social.technet.microsoft.com/Forums/en-US/1a039893-4a65-4dc9-9feb-e6f09ea1fc0b/can-not-remove-management-point-remove-role-is-greyd-out?forum=configmanagerdeployment
    However on the last comment of the above thread from"Trana010"
    stated a tool or a command
    C:\program files\Microsoft Configuration Manager\bin\x64\rolesetup.exe /deinstall /siteserver:(sec server name) SMSMP
    0
    Which I never tried yet, and also cannot find a reliable KB supporting the command "rolesetup.exe".
    Questions:
    1. What is the best way to uninstall/Reinstall the management point on secondary site considering the above issue details?
    2. Should I installed CU4 directly instead? Maybe it will resolved the issue even though it is not related to the current case
    Regards,

    Well, it's by design that you can't remove a management point on a secondary site, so I can imagine that that's why there is nothing "official" written on that subject. I think there are three things you can do:
    Try to run the command line (which is probably unsupported)
    Submit a CSS call
    Upgrade to CU4 and assume the problem is gone.
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude
    Dear Peter,
    I end up shooting a case with CSS, he guided me and share that this issue is very common.
    The reason is that it requires CU3 upgrade (Configmgr2012ac-sp1-kb2882125-x64.msp) to be installed with the SCCM Client installation (The same time) via command line in an elevated permission.
    Follow the solution provided by Microsoft Support:
    CCMSetup.exe /forceinstall SMSSITECODE=XYZ CCMENABLELOGGING=TRUE CCMLOGLEVEL=0 PATCH=C:\Configmgr2012ac-sp1-kb2882125-x64.msp
    It seems the Client Push provided by SCCM 2012 Sp1 Infra, that includes your Hotfix under the "Hotfix" folder under the client source folder somehow doesn't work with this issue, that's why the work around is to help the ccmsetup to grab the Hotfix with
    by providing the path for the hotfix instead of relying to take the hotfix for the hotfix folder.
    Overall peter thanks for your suggestion. And also to Mr. Jason Sandys opening the option for an R2 upgrade, I will look into the KB for this to plan for implementation. 
    Regards,

  • Secondary site removal

    Hi, we have a CAS with four primaries and 2 secondary sites (each on different primaries) and we're gonna be removing one of the secondaries since the network limitations that made use install it has now be removed.
    I'm wondering what would be the best way to do this as I've read multiple threads of admins having issues with this kind or removal.
    THks in advance and don't hesitate if you have any questions.
    Steph
    joeblow

    How will the client know to go to the primary's management point instead of the secondary's?
    It's auto with the system container update it'll do?
    joeblow

  • Huge Sized download taking place at port 8530 between clients and WSUS\SUP of secondary site

    Hi Guy's
    Need a solution to the issue, the SCCM 2012 clients under a secondary site { Secondary site with SUP\WSUS } are downloading 200Mb + data at port 8530. This seems quite abnormal.
    Need to know answer of below
    1- Actual size of catalog what clients should download or path where on WSUS is stored
    2- How to restrict a huge sized download between WSUS and CM 2012 client
    This is not the case where clients are directly reporting to Primary size.
    Regards
    Sushain Kapoor
    Regards Sushain KApoor

    Hi Jason
    Just a little clarity, will the client download information for a particular product or all the products selected in wsus.
    Eg: Windows 7 systems will download the catalog information of Windows 7 only against selections made in WSUS. Or it will download the windows XP and windows vista and other product information also. This particular question i am asking as i see only 300
    updates as found in windowsupdate.log and not the thousands synced in WSUS
    Is the update metadata exported using the wsusutil.exe the actual catalog size what clients are downloading
    Regards Sushain KApoor

  • Secondary Site install - Site Control File is invalid

    I have installed 9 secondary sites successfully and without issue.  My tenth however is not going as well.
    The bootstrap.pkg made it there and the install shows as completed however reviewing sitecomp.log on the secondary site shows the following:
    Publish Servers in Active Directory. SMS_SITE_COMPONENT_MANAGER 3/15/2013 1:09:59 PM 2252 (0x08CC)
     Processing forest mydomain.com. SMS_SITE_COMPONENT_MANAGER 3/15/2013 1:09:59 PM 2252 (0x08CC)
      No publishing account defined for this forest, will use the machine account instead. SMS_SITE_COMPONENT_MANAGER 3/15/2013 1:09:59 PM 2252 (0x08CC)
       DS Root:DC=mydomain,DC=com SMS_SITE_COMPONENT_MANAGER 3/15/2013 1:09:59 PM 2252 (0x08CC)
       Searching for the System Management Container. SMS_SITE_COMPONENT_MANAGER 3/15/2013 1:09:59 PM 2252 (0x08CC)
       LDAP://CN=System Management,CN=System,DC=mydomain,DC=com container exists. SMS_SITE_COMPONENT_MANAGER 3/15/2013 1:09:59 PM 2252 (0x08CC)
      No Fallback Status Point installed on the Site SMS_SITE_COMPONENT_MANAGER 3/15/2013 1:09:59 PM 2252 (0x08CC)
      Size of Signing Certificate: 0 SMS_SITE_COMPONENT_MANAGER 3/15/2013 1:09:59 PM 2252 (0x08CC)
      Signing Certificate: SMS_SITE_COMPONENT_MANAGER 3/15/2013 1:09:59 PM 2252 (0x08CC)
    Failed to get top level site code SMS_SITE_COMPONENT_MANAGER 3/15/2013 1:09:59 PM 2252 (0x08CC)
     Not able to get [MIF Collection] settings. SMS_SITE_COMPONENT_MANAGER 3/15/2013 1:09:59 PM 2252 (0x08CC)
    Failed to get top level site code SMS_SITE_COMPONENT_MANAGER 3/15/2013 1:09:59 PM 2252 (0x08CC)
      Current copy of the Site Control File is invalid. Not able to read SMS_SITE_COMPONENT_MANAGER section of sitecontrol file of top level site. SMS_SITE_COMPONENT_MANAGER 3/15/2013 1:09:59 PM 2252 (0x08CC)
    Waiting for changes to the "D:\SCCM\inboxes\sitectrl.box" or "D:\SCCM\inboxes\sitecomp.box" directories, servers will be polled in 1 hour... SMS_SITE_COMPONENT_MANAGER 3/15/2013 1:09:59 PM 2252 (0x08CC)
    I have tried restarting the services and rebooting the server altogether and still hangs here.  Any ideas before I wipe it and start over?
    Thanks!

    So the site just changed from Pending to Active in the admin console.  Might be my OCD not waiting long enough. :-|  I will continue to monitor and see if it completes the process.  If all goes through, taking significantly longer that the
    other 9 site installs..

  • Managing Secondary Site

    So I found a TechNet article on installing a secondary site, and got it going as far as any logs says it's going but now what?
    Where and how do I manage it? I tried googling and only found articles on installing a secondary site but no continuation on - Now that you have your secondary site installed go here to manage it.
    Why a secondary site? It's in a different domain, part of the same forest, with very few clients and I didn't really want to associate it with the Stand Alone Primary site as they have a slow network.
    I figured, open the Management Console, put in its name much like connecting to a Primary site and bam, you're done. Ick, a few errors.
    Okay, then I thought, just connect to the primary site. Okay, add domain user to local administrator group and go...sort of, but finally I can connect to the Primary site. Yay!
    But again, now what?

    Hey Jason,
    As always, it's a pleasure to get a nugget from you.
    Yes, I have some learning to do.  At the moment I'm slogging through Microsoft's Virtual Academy for SCCM, but before having done that I was poking along with just the imaging aspect of things and branched out to adding DPs and a few days ago wanting
    to get the  Windows Updates wrangled in which at the moment for one domain (A) it works groovy.  For the Domain B, I haven't integrated their WUS in to the mix.
    On a client in Domain A, I go in to the wuahandler.log and see the lines...
    Its a WSUS Update Source type ({22DDB6A6-E5A4-4493-8F90-EAD9875024B6}), adding it. WUAHandler 6/28/2014 2:00:01 AM 3836 (0x0EFC)
    Enabling WUA Managed server policy to use server:
    http://WSUS.mylittledomain.com:8530 WUAHandler 6/28/2014 2:00:01 AM 3836 (0x0EFC)
    Waiting for 2 mins for Group Policy to notify of WUA policy change... WUAHandler 6/28/2014 2:00:01 AM 3836 (0x0EFC)
    Waiting for 30 secs for policy to take effect on WU Agent. WUAHandler 6/28/2014 2:00:09 AM 3836 (0x0EFC)
    Added Update Source ({22DDB6A6-E5A4-4493-8F90-EAD9875024B6}) of content type: 2 WUAHandler 6/28/2014 2:00:39 AM 3836 (0x0EFC)
    YAY it works...
    I go to a client in Domain B, which points to their own WUS and don't quite see the same thing.
    <![LOG[Its a WSUS Update Source type ({22DDB6A6-E5A4-4493-8F90-EAD9875024B6}), adding it.]LOG]!><time="14:47:22.634+420" date="10-13-2014" component="WUAHandler" context="" type="1" thread="3660"
    file="sourcemanager.cpp:1232">
    <![LOG[Enabling WUA Managed server policy to use server:
    http://WSUS.ThatotherDomain.com:8530 and Policy ENABLED]LOG]!><time="14:47:29.965+420" date="10-13-2014" component="WUAHandler" context="" type="3" thread="3660" file="sourcemanager.cpp:1013">
    <![LOG[Failed to Add Update Source for WUAgent of type (2) and id ({22DDB6A6-E5A4-4493-8F90-EAD9875024B6}). Error = 0x87d00692.]LOG]!><time="14:47:30.028+420" date="10-13-2014" component="WUAHandler" context=""
    type="3" thread="3660" file="cwuahandler.cpp:2325">
    So I figure, I need to some how get SCCM to be aware of the other domain's WUS (I know, it's WSUS, just seems redundant to have that first 'S') Sooo, I added the role to it. I don't recall the outcome of that, but perhaps I should revisit it to get a feel
    for the deal of it. Anyway, I'm blathering at this point.
    Anyway, perhaps I'm hoping to find an honest-to-goodness blog that walks through Enterprise level dealings with SCCM in a non-CAS environment, and multiple WSUS servers, DPs, MPs, and cool stuff like that for each of the domains in the enterprise.
    That shows you how it's working, how to verify it is doing what it is suppose to do and stuff like that. Gone one?
    As for books, do you have any recommendations? Got my Kindle all fired up and ready to go...but then tech books seems to lack on e-devices...Ick. Poor formatting and such.
    And one other thing, about DPs that's got me baffled, and this is lack of understanding. I had a co-working IT guy call me some time ago and tell me that Firefox was failing to install. I looked at the log and scratched my head and saw that it was a boundary
    issue of sorts. His laptop belongs to Domain A, but was connected to the network in Domain C which may or may not have been part of the Forest. Sooo, I looked at that and scratched my head, and then said OK let's just add his network information
    to my boundary...Yay it worked. So I got to recognize boundary issues (And how to correctly spell boundary too). You are probably cringing at this point, if not already. But I'm guessing I over did it? I really have to figure out how boundaries work
    so that matter where a Domain A computer is at it can get content (Which was the issue, it couldn't find the content) from hopefully the closest content source. Meanwhile maintaining that Domain B computers are suppose to do the same thing.
    Ok, I'll go read now. Again. :(
    Look forward to hearing back from you.

  • Secondary Site Installation

    Hi,
    I have deployed one Standalone Primary site, but  i have deploy one Seconadry Site also for the IBCM with MP and DP.
    so, after installing the Secondary site, should i have to install CU4 for SCCM 2012 R2 on Secondary site server also... currently CU4 is already installed on Primary site server.
    Also can we have any step by step doc for installing SCCM 2012 R2 Secondary site along with required Prerequisites.
    Shailendra Dev

    That's correct. Secondary sites have nothing to do with IBCM. That explains why in your previous question you wanted to have a CA on a secondary site -- that still doesn't make sense but I see the logic now at least.
    Please, please, please, get a PKI smart person involved ASAP.
    Also, please read the following including the pages/documentation linked in detail:
    http://blogs.technet.com/b/configurationmgr/archive/2013/12/11/a-closer-look-at-internet-based-client-management-in-configmgr-2012.aspx
    http://blogs.technet.com/b/configmgrteam/archive/2012/05/25/system-center-2012-configuration-manager-r-i-p-native-mode.aspx
    Jason | http://blog.configmgrftw.com | @jasonsandys

Maybe you are looking for