PI 7.1 - Configuring a client proxy - not working.

I am trying to send a Client proxy from ECC to XI.
This is a new PI 7.1 install so I am trying to test a quick and easy client proxy from ECC to XI and cant even  get a message sent to XI.
On ECC, I am getting a weird message in SXI_MONITOR
I get a gray colored flag and when I hover over it, give me the following info:
"Message recorded (Commit Missing)". 
Has anyone encounter this type of status.
Basically the message never send out to XI.  Also, the message does not let me restart or even cancel the message. 
Overall, all the config looks good on ECC
SLDCHECK looks good.
In ECC, I configured the Integration engine config as an Application Server and pointed it to RFC destination that points to the XI server.
-steve

Hi,
1) Queues are clean
2) I have checked the RFC Destination for the HTTP connection.  It brings back a 500 empty response which is good.
I did a check on the Integration Engine Config and it brings back a yellow status that "Corresponding Integration Server not Maintined" 
I wasnt sure if this was an info message that really wasnt an error.....any thoughts?

Similar Messages

  • BPC 7.5 Admin Client Links Not Working

    I am working in BPC 7.5 SP15 NW. I have recently upgraded to Windows 7 64-bit and now the links in the action pane in the desktop admin client are not working.  The cursor does not change from the nornal pointer to the hand.  That would indicate that the admin client is no longer recognizing them as links.  The links work fine in the desktop Excel client.  I am using 32-bit Excel 2010 with no other version of Office installed.
    Has anyone heard of this behavior and how to correct for it?

    Hi Kannan,
    i think this is a Osoft web site configuration issue, the error indicates that you have one duplicate section in the web site configuration file (web.config).
    If you didn't alter the web.config file then the problem may occur because when you use framework 4.0, the machine config already has some of the sections defined that were used in previous ASP.NEt versions.
    You should check which version of the MS Framework is configured for the application pool of the web site, change it to v2.
    Let me know if this solves the issue. Or if you need more help to resolve it.
    Kindest regards,

  • [solved] NFS client will not work correctly

    I have all my $HOME on an NFS Server. So long I used suse and debian, now I want switch to arch but the nfs-client ist not working correctly:
    I start "portmap nfslock nfsd netfs" over rc.conf. When I do a "rpcinfo -p <ip-arch-system>" I got the following
    stefan:/home/stefan # rpcinfo -p 192.168.123.3
       Program Vers Proto   Port
        100000    2   tcp    111  portmapper
        100000    2   udp    111  portmapper
        100021    1   udp  32768  nlockmgr
        100021    3   udp  32768  nlockmgr
        100021    4   udp  32768  nlockmgr
        100003    2   udp   2049  nfs
        100003    3   udp   2049  nfs
        100003    4   udp   2049  nfs
        100021    1   tcp  48988  nlockmgr
        100021    3   tcp  48988  nlockmgr
        100021    4   tcp  48988  nlockmgr
        100003    2   tcp   2049  nfs
        100003    3   tcp   2049  nfs
        100003    4   tcp   2049  nfs
        100005    3   udp    891  mountd
        100005    3   tcp    894  mountd
    As you see "status" is missing, so the statd is not running. It sould look like the result on my suse box:
    stefan:/home/stefan # rpcinfo -p 192.168.123.2
       Program Vers Proto   Port
        100000    2   tcp    111  portmapper
        100000    2   udp    111  portmapper
        100024    1   udp  32768  status
        100021    1   udp  32768  nlockmgr
        100021    3   udp  32768  nlockmgr
        100021    4   udp  32768  nlockmgr
        100024    1   tcp  35804  status
        100021    1   tcp  35804  nlockmgr
        100021    3   tcp  35804  nlockmgr
        100021    4   tcp  35804  nlockmgr
    There is the "status" line and so the statd is running.
    How can I fix that problem, so that statd ist running on my arch box too?
    Last edited by stka (2007-06-10 15:59:48)

    The Problem ist solved.
    I use ldap for authentication. During the setup of the ldapclient I copied the nsswitch.ldap to nsswitch.conf. But the line for "hosts:" was:
    hosts:          dns ldap
    but in my dns ist no localhost entry. After I changed this line to:
    hosts:          files dns ldap
    everything was ok. The statd is now running and I can start to migrate to archlinux ;-)

  • Connect a Client Computer Not Working At All

    I have a new Windows 7 clean install with updates that is not able to connect to SBS 2011 at all.
    In the past (about 2 years ago) I ran into the same problem and by following the simple steps outlined here - http://blog.ronnypot.nl/?p=594 - it worked no problem. Now it does not help at all.
    For a test, I took a spare machine and did a clean install of SBS 2011, applied the updates (except NET 4.5.1). When I tried to connect the new Windows 7 machine to the new SBS 2011 machine - this also has failed.

    Server's ipconfig /all
    Windows IP Configuration
       Host Name . . . . . . . . . . . . : BLAH-1
       Primary Dns Suffix  . . . . . . . : BLAH.local
       Node Type . . . . . . . . . . . . : Hybrid
       IP Routing Enabled. . . . . . . . : Yes
       WINS Proxy Enabled. . . . . . . . : No
       DNS Suffix Search List. . . . . . : BLAH.local
    Ethernet adapter Local Area Connection:
       Connection-specific DNS Suffix  . : BLAH.local
       Description . . . . . . . . . . . : Broadcom NetXtreme 57xx Gigabit Controller
       Physical Address. . . . . . . . . : REMOVED
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
       IPv6 Address. . . . . . . . . . . : REMOVED (Preferred)
       Link-local IPv6 Address . . . . . : REMOVED (Preferred)
       Link-local IPv6 Address . . . . . : REMOVED (Preferred)
       IPv4 Address. . . . . . . . . . . : 192.168.1.12(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Default Gateway . . . . . . . . . : REMOVED
                                           192.168.1.1
       DHCPv6 IAID . . . . . . . . . . . : REMOVED
       DHCPv6 Client DUID. . . . . . . . : REMOVED
       DNS Servers . . . . . . . . . . . : REMOVED
                                           192.168.1.12
       NetBIOS over Tcpip. . . . . . . . : Enabled
       Connection-specific DNS Suffix Search List :
                                           BLAH.local
    Tunnel adapter isatap.{REMOVED}:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . : BLAH.local
       Description . . . . . . . . . . . : Microsoft ISATAP Adapter
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Teredo Tunneling Pseudo-Interface:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Workstation's ipconifg /all
    Windows IP Configuration
       Host Name . . . . . . . . . . . . : BLAH-1
       Primary Dns Suffix  . . . . . . . : BLAH.local
       Node Type . . . . . . . . . . . . : Hybrid
       IP Routing Enabled. . . . . . . . : Yes
       WINS Proxy Enabled. . . . . . . . : No
       DNS Suffix Search List. . . . . . : BLAH.local
    Ethernet adapter Local Area Connection:
       Connection-specific DNS Suffix  . : aspa2.local
       Description . . . . . . . . . . . : Broadcom NetXtreme 57xx Gigabit Controller
       Physical Address. . . . . . . . . : REMOVED
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
       IPv6 Address. . . . . . . . . . . : REMOVED (Preferred)
       Link-local IPv6 Address . . . . . : REMOVED (Preferred)
       Link-local IPv6 Address . . . . . : REMOVED (Preferred)
       IPv4 Address. . . . . . . . . . . : 192.168.1.12(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Default Gateway . . . . . . . . . : REMOVED
                                           192.168.1.1
       DHCPv6 IAID . . . . . . . . . . . : REMOVED
       DHCPv6 Client DUID. . . . . . . . : REMOVED
       DNS Servers . . . . . . . . . . . : REMOVED
                                           192.168.1.12
       NetBIOS over Tcpip. . . . . . . . : Enabled
       Connection-specific DNS Suffix Search List :
                                           BLAH.local
    Tunnel adapter isatap.{REMOVED}:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . : BLAH.local
       Description . . . . . . . . . . . : Microsoft ISATAP Adapter
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Teredo Tunneling Pseudo-Interface:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    HCI3 - I tried the steps you have listed and it did not work.

  • Webservice client is not working for secured service

    Hi Experts,
    Currently i am facing issue when i try to access the secured webservice,
    I used jdeveloper 11.1.2.1.0 to create the webservice client proxy and found the following error if i invoke the service,
    I am using the following code to access the service,
    URL url = new URL(".", wsdl_url);
    MyService myservice = new MyService(url, new QName("urn:drs.test.com",
    "MyService"));
    myTester = myservice .getTester();
    Map<String, Object> reqContext = ((BindingProvider) myTester ).getRequestContext();
    reqContext.put(BindingProvider.USERNAME_PROPERTY, "user name");
    reqContext.put(BindingProvider.PASSWORD_PROPERTY, "password");
    May i know the reason for this issue?
    javax.wsdl.WSDLException: WSDLException: faultCode=INVALID_WSDL: Invalid XML in source with PublicId: null: oracle.xml.parser.v2.XMLParseException: Whitespace required.
         at oracle.j2ee.ws.wsdl.xml.WSDLReaderImpl.readWSDL(WSDLReaderImpl.java:344)
         at oracle.j2ee.ws.wsdl.xml.WSDLReaderImpl.readWSDL(WSDLReaderImpl.java:294)
         at oracle.j2ee.ws.wsdl.xml.WSDLReaderImpl.readWSDL(WSDLReaderImpl.java:278)
         at oracle.jdeveloper.webservices.wsdl.CachedWSDLReader.readWSDLInternal(CachedWSDLReader.java:531)
         at oracle.jdeveloper.webservices.wsdl.CachedWSDLReader.readWSDL(CachedWSDLReader.java:484)
         at oracle.jdeveloper.webservices.wsdl.CachedWSDLReader.readWSDL(CachedWSDLReader.java:455)
         at oracle.jdevimpl.webservices.wizard.jaxrpc.common.SpecifyWsdlPanel.fetchWSDL(SpecifyWsdlPanel.java:1050)
         at oracle.jdevimpl.webservices.wizard.jaxrpc.common.SpecifyWsdlPanel$1.run(SpecifyWsdlPanel.java:364)
         at oracle.ide.dialogs.ProgressBar.run(ProgressBar.java:655)
         at java.lang.Thread.run(Thread.java:662)
    Caused by: oracle.xml.parser.v2.XMLParseException: Whitespace required.
         at oracle.xml.parser.v2.XMLError.flushErrors1(XMLError.java:323)
         at oracle.xml.parser.v2.XMLReader.scanQuotedString(XMLReader.java:1831)
         at oracle.xml.parser.v2.XMLReader.scanQuotedString(XMLReader.java:1939)
         at oracle.xml.parser.v2.NonValidatingParser.parseDoctypeDecl(NonValidatingParser.java:489)
         at oracle.xml.parser.v2.NonValidatingParser.parseProlog(NonValidatingParser.java:363)
         at oracle.xml.parser.v2.NonValidatingParser.parseDocument(NonValidatingParser.java:321)
         at oracle.xml.parser.v2.XMLParser.parse(XMLParser.java:226)
         at oracle.xml.jaxp.JXDocumentBuilder.parse(JXDocumentBuilder.java:155)
         at oracle.j2ee.ws.wsdl.xml.WSDLReaderImpl.readWSDL(WSDLReaderImpl.java:337)

    Hi
    I am facing similar issue but with Custom Adapter . I copied the axis jars under the JavaTasks folder but it does not help.
    I then copied them under the oim.ear/APP_INF/lib and restarted the OIM managed server but somehow even that does not help.
    I get following error.
    Caused by: java.lang.NoSuchMethodError: org/apache/axiom/om/OMAbstractFactory.getMetaFactory()Lorg/apache/axiom/om/OMMetaFactory;
            at org.apache.axiom.om.OMXMLBuilderFactory.createOMBuilder(OMXMLBuilderFactory.java:150)
            at org.apache.axiom.om.OMXMLBuilderFactory.createOMBuilder(OMXMLBuilderFactory.java:133)
            at org.apache.axiom.om.OMXMLBuilderFactory.createOMBuilder(OMXMLBuilderFactory.java:104)
            at org.apache.axis2.util.XMLUtils.toOM(XMLUtils.java:590)
            at org.apache.axis2.util.XMLUtils.toOM(XMLUtils.java:575)
            at org.apache.axis2.deployment.DescriptionBuilder.buildOM(DescriptionBuilder.java:97)
            at org.apache.axis2.deployment.AxisConfigBuilder.populateConfig(AxisConfigBuilder.java:90)
            at org.apache.axis2.deployment.DeploymentEngine.populateAxisConfiguration(DeploymentEngine.java:857)
            at org.apache.axis2.deployment.FileSystemConfigurator.getAxisConfiguration(FileSystemConfigurator.java:116)
            at org.apache.axis2.context.ConfigurationContextFactory.createConfigurationContext(ConfigurationContextFactory.java:64)
            at org.apache.axis2.context.ConfigurationContextFactory.createConfigurationContextFromFileSystem(ConfigurationContextFactory.java:210)
            at org.apache.axis2.client.ServiceClient.configureServiceClient(ServiceClient.java:151)
    Any pointer on how I can try to resolve it.
    Regards
    Abhinav

  • Inbound Proxy not working

    Hi,
    I have configured a proxy for a BAPI (SAP EM EventHandler.AddEventMessage02) but it does not work.
    EventHandler.AddEventMessage02 has a deep structure.
    Step by Step:
    ABAP Proxy generated.
    Activate changes
    Export WSDL from Proxy.
    Import WSDL to ESR, and generate a Service Interface.
    Activate changes
    Use SIW to generate the AIF configuration
    Correct syntax ABAP errors in the code generated.
    Activate changes
    When I execute the service, AIF log says message header does not exist.
    Looking through debug, the source data is not mapped to the target. When BAPI is called, curr_line structure is INITIAL
    So I tried to check if the mappings are fine in /AIF/CUST but when I tried to define a source mapping, AIF says "DDIC structure ZCHAR1 does not exist"
    Do you have any tips?
    Thanks,
    Erik Bengtson

    The solution to my mapping problem is the following:
    Map: Source TRACKINGHEADER to DESTINATION TRACKINGHEADER
    In /AIF/CUST Destination Structure add the Function Before Mapping. This function will copy TRACKINGHEADER/ITEM/* to the destination TRACKINGHEADER/*
    FUNCTION ZMA_E1_MAP.
    *"*"Local Interface:
    *"  IMPORTING
    *"     REFERENCE(RAW_STRUCT)
    *"     REFERENCE(RAW_LINE)
    *"     REFERENCE(SMAP) TYPE  /AIF/T_SMAP
    *"     REFERENCE(INTREC) TYPE  /AIF/T_INTREC
    *"     REFERENCE(SENDING_SYSTEM) TYPE  /AIF/AIF_BUSINESS_SYSTEM_KEY
    *"       OPTIONAL
    *"  TABLES
    *"      RETURN_TAB STRUCTURE  BAPIRET2 OPTIONAL
    *"  CHANGING
    *"     REFERENCE(OUT_STRUCT)
    *"     REFERENCE(DEST_LINE)
    *"     REFERENCE(DEST_TABLE)
    *"     REFERENCE(APPEND_FLAG) TYPE  C
       BREAK-POINT.   "#EC NOBREAK
    FIELD-SYMBOLS: <_item> TYPE ANY TABLE.
    FIELD-SYMBOLS: <_row> TYPE ANY.
    ASSIGN COMPONENT 'ITEM' OF STRUCTURE RAW_LINE TO <_item>.
    LOOP AT <_item> ASSIGNING <_row> .
       MOVE-CORRESPONDING <_row> TO DEST_LINE.
    ENDLOOP.
    ENDFUNCTION.

  • SRM XI standard content ...SRM Server 7.0 - Outbound proxy not working

    Hello All,
    we have integrated SRM SUS with ECC 6.0 using XI standard content XI SRMSERVER IC 7.0. With same configuration, Purchase Order has been send from ECC to SUS and PO is created successfully in SRM SUS. But, while confirming the purchase order, its not generating outbound proxy message.
    And when we check the interface PurchaseOrderConfirmation_Out(i.e dobule clicking) in SPROXY transaction of SRM SUS, getting the following LOG:
    1. Logical port template is inconsistent, regenerate it and activate it
    2. cannot create LPT without DT profiles
    3. Regernate proxy(inactive version incorrect)
    Let me know if you have any suggestions.
    Regards,
    Sreenivas.

    Hello Srinivas,
    1.Check your Port creation from ECC to XI  2 SRM.
    2. Activate your proxies properly and check whethar your proxy communication working properly or not.
    check this links for your reference.
    MM -XI-SUS
    MM System - XI - SUS
    MM-XI
    How to integrate MM using XI
    SRM-XI
    SRM  and XI Integration
    http://service.sap.com/~sapidb/011000358700002897342004E/CCMConfig10_01_05.pdf
    http://service.sap.com/~sapidb/011000358700003992672005E/Config_Guide_CCM200_640doc.pdf
    http://service.sap.com/~sapidb/011000358700002897402004E/ServiceProcurementNEW.pdf
    http://service.sap.com/~sapidb/011000358700002897382004E/Plan-DrivenwithSInew.pdf
    SRM and XI
    Is there pre-configured message mapping for SRM Content?
    /people/vijaya.kumari2/blog/2006/01/26/how-do-you-activate-abap-proxies
    SRM XI scenario
    Which version of SRM needs XI?
    SRM  AND SAP XI
    XI with SRM 4.0
    Regards,
    Mahesh

  • SOAP Axis adapter_Encryption via Client Certificate not working

    Dear Experts,
    Could anyone please share the steps to enable encryption via client certificate in SOAP AXIS receiver adapter.
    I am able to do the same using normal SOAP adapter but with AXIS framework the steps are not working.
    I have come across few sdn links to configure axis framework for authentication using wsse security standard but this seems to be different as it requires user and password whereas with certificates we are not given any user/password.
    Please provide some valuable inputs.
    Thanks.

    Hi Shikha,
    see the -
    Advanced Usage Questions
        8. How can I configure a channel to use the encryption and ....
    of the FAQ attached to the note -
    1039369 - FAQ XI Axis Adapter
    Regards
    Kenny

  • Java FTP client do not work in Solaris 10

    We just upgrade our Solaris 8.0 system to Solaris10. A java FTP client don't work anymore when I try to download a remote file. It worked nicely in Solaris8. Specifically, this java program is using JDK FtpClient, the command that downloading a file is something like this:
    TelnetInputStream in = ftpClient.get(remotefilename);
    However, I still can send a file to a remote machine. Anyone knows this?
    Thnak you very much!

    Hello Community,
    the problem is solved. The VM on the workstation is very slow. The Java EE server use more than one hour to start. No problem with the hardware key or anything else, only a problem of my patience. It seems that the configuration file of the VM stores special entrys of the basic physical machine to run optimal. And which is optimal for the notebook is not optimal for the workstation.
    Cheers
    Stefan
    Edited by: Stefan Schnell on Mar 4, 2008 2:10 PM

  • Client DHCP not working

    Here's the situation;
    4402 controller (2 actually), AP-manager and manager in vlan 1, untagged, native vlan of trunked switchport set to 1. Not using LAG at this time. See access points, so that works (DHCP in VLAN 1).
    Got 3 additional data VLAN's. Created 3 dynamic interaces with IP's in that specific VLAN, and 3 WLAN's. Have 3 DHCP server addresses (one DHCP server per VLAN) and i configured these server addresses on the dynamic interface, not on the WLAN.
    Clients get associated, but cannot get an IP address.
    Should this work or should i configure the DHCP server on the WLAN's instead?
    And does a 2003 server needs config to accept DHCP relay?

    Hi Friend,
    You need not have DHCP server on every VLAN. You can have one DHCP server with multiple pools for different subnet and can attach your DHCP server on one VLAN as you have done in your case on vlan 2.
    You can simply have layer 3 device doing routing between your data vlans and vlan having DHCP server.
    When you specify your DHCP server IP address on your interfaces which you have configured on controller it will play a role of relay agent.
    If you routing is fine between your vlans and you have specified your dhcp server ip address under interface configuration on controller it should work.
    Tell me if I got your problem or not and if not can you please explain your problem again.
    Regards,
    Ankur

  • Cisco 1841 as PPTP client Does not work

    Dear All,
    I have Cisco 1841 router running the below roles       
    1) SSL VPN Server
    2) PPTP Server
    3) Site to Site Connection with Sonicwall router
    I want the router to be configured a pptp client to internet vpn server (so that i will get a fixed public ip )
    Once i get this ip address i want to use this connection to accept in coming connection and forward ports to internal host,
    I went through below
    http://www.mreji.eu/content/cisco-router-pptp-client
    https://supportforums.cisco.com/thread/2167562
    But it does not work as i do not have the option for the below 2 commands in vpdn-group 2 section.(Please see section in blue)
    protocol pptp
      rotary-group 4
    Please Advise and Help
    Regards
    Hasan Reza
    My Current Config is as below
    =~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2013.06.09 17:55:23 =~=~=~=~=~=~=~=~=~=~=~=
    exit
    Gateway#show run |      
    Building configuration...
    Current configuration : 25109 bytes
    ! Last configuration change at 13:33:57 UTC Sun Jun 9 2013 by admin
    version 15.1
    service timestamps debug datetime msec
    service timestamps log datetime msec
    service password-encryption
    hostname Gateway
    boot-start-marker
    boot system flash c1841-advsecurityk9-mz.151-2.T1.bin
    boot-end-marker
    logging buffered 4096
    no logging console
    enable secret 5 $1$SciF$TlX1tR5qaG9ZE7pdZHcRJ/
    no aaa new-model
    dot11 syslog
    ip source-route
    no ip dhcp use vrf connected
    ip dhcp excluded-address 10.236.5.1 10.236.5.20
    ip dhcp excluded-address 10.236.5.21 10.236.5.50
    ip dhcp excluded-address 172.21.51.2 172.21.51.50
    ip dhcp pool ContosoPool
       network 10.236.5.0 255.255.255.0
       default-router 10.236.5.254
       dns-server 213.42.20.20 195.229.241.222
    ip dhcp pool DMZ
       network 172.21.51.0 255.255.255.0
       dns-server 172.21.51.10
       default-router 172.21.51.1
       domain-name contoso.local
    ip cef
    ip domain name contoso.local
    ip name-server 213.42.20.20
    ip name-server 195.229.241.22
    ip name-server 195.229.241.222
    ip ddns update method dyndns
    HTTP
      add http://xxxxxx:[email protected]/nic/update?system=dyndns&hostname=<h>&myip=<a>
      remove http://xxxxxx:yyyyy@@members.dyndns.org/nic/update?system=dyndns&hostname=<h>&myip=<a>
    interval maximum 0 1 0 0
    multilink bundle-name authenticated
    vpdn enable
    vpdn-group 2
    request-dialin
      protocol l2tp
    initiate-to ip 173.195.0.42
    vpdn-group RAS-VPN
    ! Default PPTP VPDN group
    accept-dialin
      protocol pptp
      virtual-template 1
    l2tp tunnel timeout no-session 15
    crypto pki token default removal timeout 0
    crypto pki trustpoint TP.StartSSL.CA
    enrollment terminal pem
    revocation-check none
    crypto pki trustpoint TP.StartSSL-vpn
    enrollment terminal pem
    usage ssl-server
    serial-number none
    fqdn ssl.spktelecom.com
    ip-address none
    revocation-check crl
    rsakeypair RSA.StartSSL-vpn
    crypto pki trustpoint TP-self-signed-1981248591
    enrollment selfsigned
    subject-name cn=IOS-Self-Signed-Certificate-1981248591
    revocation-check none
    rsakeypair TP-self-signed-1981248591
    crypto pki trustpoint VMWare
    enrollment terminal
    revocation-check crl
    crypto pki trustpoint OWA
    enrollment terminal pem
    revocation-check crl
    crypto pki certificate chain TP.StartSSL.CA
    certificate ca 01
      (removed the certificate info for clarity)
       quit
    crypto pki certificate chain TP.StartSSL-vpn
    certificate 0936E1
        (removed the certificate info for clarity)9
       quit
    certificate ca 18
      (removed the certificate info for clarity)
       quit
    crypto pki certificate chain TP-self-signed-1981248591
    certificate self-signed 01
        (removed the certificate info for clarity)
       quit
    crypto pki certificate chain VMWare
    certificate ca 008EDCE6DBCE6B
        (removed the certificate info for clarity)
       quit
    crypto pki certificate chain OWA
       (removed the certificate info for clarity)
    license udi pid CISCO1841 sn FCZ122191TW
    archive
    log config
      hidekeys
    username admin privilege 15 password 7 1304131F02023B7B7977
    username ali password 7 06070328
    redundancy
    crypto isakmp policy 10
    encr 3des
    authentication pre-share
    group 2
    lifetime 84000
    crypto isakmp key admin_123 address 0.0.0.0 0.0.0.0
    crypto isakmp keepalive 10
    crypto ipsec security-association lifetime seconds 28800
    crypto ipsec transform-set vpnset esp-3des esp-sha-hmac
    crypto ipsec transform-set strongsha esp-3des esp-sha-hmac
    crypto dynamic-map mydyn 10
    set transform-set strongsha
    crypto map Dxb-Auh 1000 ipsec-isakmp dynamic XXXXXXXXXX
    interface FastEthernet0/0
    description Internal Network (Protected Interface)
    ip address 10.236.5.254 255.255.255.0
    ip nat inside
    ip virtual-reassembly in
    duplex auto
    speed auto
    interface FastEthernet0/1
    no ip address
    duplex auto
    speed auto
    pppoe enable group global
    pppoe-client dial-pool-number 1
    interface ATM0/0/0
    no ip address
    shutdown
    no atm ilmi-keepalive
    interface BRI0/1/0
    no ip address
    encapsulation hdlc
    shutdown
    interface Virtual-Template1
    ip unnumbered Dialer1
    peer default ip address dhcp-pool ContosoPool
    ppp encrypt mppe auto required
    ppp authentication ms-chap ms-chap-v2 eap
    interface Dialer1
    ip ddns update hostname XXXXXXX.dyndns.org
    ip ddns update dyndns
    ip address negotiated
    ip nat outside
    ip virtual-reassembly in
    encapsulation ppp
    ip tcp adjust-mss 1450
    dialer pool 1
    ppp pap sent-username vermam password 7 13044E155E0913323B
    crypto map Dxb-Auh
    interface Dialer2
    mtu 1460
    ip address negotiated
    ip nat outside
    ip virtual-reassembly in
    encapsulation ppp
    dialer in-band
    dialer idle-timeout 0
    dialer string 123
    dialer vpdn
    dialer-group 2
    ppp pfc local request
    ppp pfc remote apply
    ppp encrypt mppe auto
    ppp authentication ms-chap ms-chap-v2 callin
    ppp eap refuse
    ppp chap hostname hasanreza
    ppp chap password 7 070E2541470726544541
    interface Dialer995
    no ip address
    ip local pool webssl 10.236.6.10 10.236.6.30
    ip forward-protocol nd
    ip http server
    ip http secure-server
    ip nat inside source list nat interface Dialer1 overload
    ip nat inside source static tcp 10.236.5.12 25 interface Dialer1 25
    ip route 0.0.0.0 0.0.0.0 Dialer1
    ip route 172.21.51.0 255.255.255.0 10.236.5.253
    ip access-list extended internal
    permit ip any 10.236.5.0 0.0.0.255
    ip access-list extended nat
    deny   ip 10.236.5.0 0.0.0.255 172.31.1.0 0.0.0.255
    deny   ip 10.236.5.0 0.0.0.255 172.19.19.0 0.0.0.255
    permit ip 10.236.5.0 0.0.0.255 any
    ip access-list extended nonat
    permit ip 10.236.5.0 0.0.0.255 172.19.19.0 0.0.0.255
    permit ip 10.236.5.0 0.0.0.255 172.31.1.0 0.0.0.255
    ip access-list extended sslacl
    ip access-list extended webvpn
    permit tcp any any eq 443
    logging esm config
    access-list 101 permit ip 10.236.5.0 0.0.0.255 172.31.1.0 0.0.0.255
    control-plane
    line con 0
    line aux 0
    line vty 0 4
    exec-timeout 0 0
    login local
    transport preferred ssh
    transport input telnet ssh
    line vty 5 15
    exec-timeout 0 0
    login local
    transport preferred ssh
    transport input telnet ssh
    scheduler allocate 20000 1000
    webvpn gateway gateway1
    ip interface Dialer1 port 443
    ssl encryption rc4-md5
    ssl trustpoint TP.StartSSL-vpn
    inservice
    webvpn install svc flash:/webvpn/anyconnect-win-3.1.00495-k9.pkg sequence 1
    webvpn install csd flash:/webvpn/sdesktop.pkg
    webvpn context webvpn
    ssl authenticate verify all
    url-list "Webservers"
       heading "SimpleIT Technologies NBNS Servers"
       url-text "Google" url-value "www.google.com"
       url-text "Mainframe" url-value "10.236.5.2"
       url-text "Mainframe2" url-value "https://10.236.5.2"
    nbns-list "ContosoServer"
       nbns-server 10.236.5.10
       nbns-server 10.236.5.11
       nbns-server 10.236.5.12
    port-forward "PortForwarding"
       local-port 3389 remote-server "10.236.5.10" remote-port 3389 description "Server-DC01"
    policy group policy1
       url-list "Webservers"
       port-forward "PortForwarding"
       nbns-list "ContosoServer"
       functions file-access
       functions file-browse
       functions file-entry
       functions svc-enabled
       svc address-pool "webssl"
       svc default-domain "Contoso.Local"
       svc keep-client-installed
       svc split include 10.236.5.0 255.255.255.0
       svc split include 10.236.6.0 255.255.255.0
       svc split include 172.31.1.0 255.255.255.0
       svc split include 172.21.51.0 255.255.255.0
       svc dns-server primary 172.21.51.10
    default-group-policy policy1
    gateway gateway1
    inservice
    end
    Gateway#          

    Dear All,
    I have Cisco 1841 router running the below roles       
    1) SSL VPN Server
    2) PPTP Server
    3) Site to Site Connection with Sonicwall router
    I want the router to be configured a pptp client to internet vpn server (so that i will get a fixed public ip )
    Once i get this ip address i want to use this connection to accept in coming connection and forward ports to internal host,
    I went through below
    http://www.mreji.eu/content/cisco-router-pptp-client
    https://supportforums.cisco.com/thread/2167562
    But it does not work as i do not have the option for the below 2 commands in vpdn-group 2 section.(Please see section in blue)
    protocol pptp
      rotary-group 4
    Please Advise and Help
    Regards
    Hasan Reza
    My Current Config is as below
    =~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2013.06.09 17:55:23 =~=~=~=~=~=~=~=~=~=~=~=
    exit
    Gateway#show run |      
    Building configuration...
    Current configuration : 25109 bytes
    ! Last configuration change at 13:33:57 UTC Sun Jun 9 2013 by admin
    version 15.1
    service timestamps debug datetime msec
    service timestamps log datetime msec
    service password-encryption
    hostname Gateway
    boot-start-marker
    boot system flash c1841-advsecurityk9-mz.151-2.T1.bin
    boot-end-marker
    logging buffered 4096
    no logging console
    enable secret 5 $1$SciF$TlX1tR5qaG9ZE7pdZHcRJ/
    no aaa new-model
    dot11 syslog
    ip source-route
    no ip dhcp use vrf connected
    ip dhcp excluded-address 10.236.5.1 10.236.5.20
    ip dhcp excluded-address 10.236.5.21 10.236.5.50
    ip dhcp excluded-address 172.21.51.2 172.21.51.50
    ip dhcp pool ContosoPool
       network 10.236.5.0 255.255.255.0
       default-router 10.236.5.254
       dns-server 213.42.20.20 195.229.241.222
    ip dhcp pool DMZ
       network 172.21.51.0 255.255.255.0
       dns-server 172.21.51.10
       default-router 172.21.51.1
       domain-name contoso.local
    ip cef
    ip domain name contoso.local
    ip name-server 213.42.20.20
    ip name-server 195.229.241.22
    ip name-server 195.229.241.222
    ip ddns update method dyndns
    HTTP
      add http://xxxxxx:[email protected]/nic/update?system=dyndns&hostname=<h>&myip=<a>
      remove http://xxxxxx:yyyyy@@members.dyndns.org/nic/update?system=dyndns&hostname=<h>&myip=<a>
    interval maximum 0 1 0 0
    multilink bundle-name authenticated
    vpdn enable
    vpdn-group 2
    request-dialin
      protocol l2tp
    initiate-to ip 173.195.0.42
    vpdn-group RAS-VPN
    ! Default PPTP VPDN group
    accept-dialin
      protocol pptp
      virtual-template 1
    l2tp tunnel timeout no-session 15
    crypto pki token default removal timeout 0
    crypto pki trustpoint TP.StartSSL.CA
    enrollment terminal pem
    revocation-check none
    crypto pki trustpoint TP.StartSSL-vpn
    enrollment terminal pem
    usage ssl-server
    serial-number none
    fqdn ssl.spktelecom.com
    ip-address none
    revocation-check crl
    rsakeypair RSA.StartSSL-vpn
    crypto pki trustpoint TP-self-signed-1981248591
    enrollment selfsigned
    subject-name cn=IOS-Self-Signed-Certificate-1981248591
    revocation-check none
    rsakeypair TP-self-signed-1981248591
    crypto pki trustpoint VMWare
    enrollment terminal
    revocation-check crl
    crypto pki trustpoint OWA
    enrollment terminal pem
    revocation-check crl
    crypto pki certificate chain TP.StartSSL.CA
    certificate ca 01
      (removed the certificate info for clarity)
       quit
    crypto pki certificate chain TP.StartSSL-vpn
    certificate 0936E1
        (removed the certificate info for clarity)9
       quit
    certificate ca 18
      (removed the certificate info for clarity)
       quit
    crypto pki certificate chain TP-self-signed-1981248591
    certificate self-signed 01
        (removed the certificate info for clarity)
       quit
    crypto pki certificate chain VMWare
    certificate ca 008EDCE6DBCE6B
        (removed the certificate info for clarity)
       quit
    crypto pki certificate chain OWA
       (removed the certificate info for clarity)
    license udi pid CISCO1841 sn FCZ122191TW
    archive
    log config
      hidekeys
    username admin privilege 15 password 7 1304131F02023B7B7977
    username ali password 7 06070328
    redundancy
    crypto isakmp policy 10
    encr 3des
    authentication pre-share
    group 2
    lifetime 84000
    crypto isakmp key admin_123 address 0.0.0.0 0.0.0.0
    crypto isakmp keepalive 10
    crypto ipsec security-association lifetime seconds 28800
    crypto ipsec transform-set vpnset esp-3des esp-sha-hmac
    crypto ipsec transform-set strongsha esp-3des esp-sha-hmac
    crypto dynamic-map mydyn 10
    set transform-set strongsha
    crypto map Dxb-Auh 1000 ipsec-isakmp dynamic XXXXXXXXXX
    interface FastEthernet0/0
    description Internal Network (Protected Interface)
    ip address 10.236.5.254 255.255.255.0
    ip nat inside
    ip virtual-reassembly in
    duplex auto
    speed auto
    interface FastEthernet0/1
    no ip address
    duplex auto
    speed auto
    pppoe enable group global
    pppoe-client dial-pool-number 1
    interface ATM0/0/0
    no ip address
    shutdown
    no atm ilmi-keepalive
    interface BRI0/1/0
    no ip address
    encapsulation hdlc
    shutdown
    interface Virtual-Template1
    ip unnumbered Dialer1
    peer default ip address dhcp-pool ContosoPool
    ppp encrypt mppe auto required
    ppp authentication ms-chap ms-chap-v2 eap
    interface Dialer1
    ip ddns update hostname XXXXXXX.dyndns.org
    ip ddns update dyndns
    ip address negotiated
    ip nat outside
    ip virtual-reassembly in
    encapsulation ppp
    ip tcp adjust-mss 1450
    dialer pool 1
    ppp pap sent-username vermam password 7 13044E155E0913323B
    crypto map Dxb-Auh
    interface Dialer2
    mtu 1460
    ip address negotiated
    ip nat outside
    ip virtual-reassembly in
    encapsulation ppp
    dialer in-band
    dialer idle-timeout 0
    dialer string 123
    dialer vpdn
    dialer-group 2
    ppp pfc local request
    ppp pfc remote apply
    ppp encrypt mppe auto
    ppp authentication ms-chap ms-chap-v2 callin
    ppp eap refuse
    ppp chap hostname hasanreza
    ppp chap password 7 070E2541470726544541
    interface Dialer995
    no ip address
    ip local pool webssl 10.236.6.10 10.236.6.30
    ip forward-protocol nd
    ip http server
    ip http secure-server
    ip nat inside source list nat interface Dialer1 overload
    ip nat inside source static tcp 10.236.5.12 25 interface Dialer1 25
    ip route 0.0.0.0 0.0.0.0 Dialer1
    ip route 172.21.51.0 255.255.255.0 10.236.5.253
    ip access-list extended internal
    permit ip any 10.236.5.0 0.0.0.255
    ip access-list extended nat
    deny   ip 10.236.5.0 0.0.0.255 172.31.1.0 0.0.0.255
    deny   ip 10.236.5.0 0.0.0.255 172.19.19.0 0.0.0.255
    permit ip 10.236.5.0 0.0.0.255 any
    ip access-list extended nonat
    permit ip 10.236.5.0 0.0.0.255 172.19.19.0 0.0.0.255
    permit ip 10.236.5.0 0.0.0.255 172.31.1.0 0.0.0.255
    ip access-list extended sslacl
    ip access-list extended webvpn
    permit tcp any any eq 443
    logging esm config
    access-list 101 permit ip 10.236.5.0 0.0.0.255 172.31.1.0 0.0.0.255
    control-plane
    line con 0
    line aux 0
    line vty 0 4
    exec-timeout 0 0
    login local
    transport preferred ssh
    transport input telnet ssh
    line vty 5 15
    exec-timeout 0 0
    login local
    transport preferred ssh
    transport input telnet ssh
    scheduler allocate 20000 1000
    webvpn gateway gateway1
    ip interface Dialer1 port 443
    ssl encryption rc4-md5
    ssl trustpoint TP.StartSSL-vpn
    inservice
    webvpn install svc flash:/webvpn/anyconnect-win-3.1.00495-k9.pkg sequence 1
    webvpn install csd flash:/webvpn/sdesktop.pkg
    webvpn context webvpn
    ssl authenticate verify all
    url-list "Webservers"
       heading "SimpleIT Technologies NBNS Servers"
       url-text "Google" url-value "www.google.com"
       url-text "Mainframe" url-value "10.236.5.2"
       url-text "Mainframe2" url-value "https://10.236.5.2"
    nbns-list "ContosoServer"
       nbns-server 10.236.5.10
       nbns-server 10.236.5.11
       nbns-server 10.236.5.12
    port-forward "PortForwarding"
       local-port 3389 remote-server "10.236.5.10" remote-port 3389 description "Server-DC01"
    policy group policy1
       url-list "Webservers"
       port-forward "PortForwarding"
       nbns-list "ContosoServer"
       functions file-access
       functions file-browse
       functions file-entry
       functions svc-enabled
       svc address-pool "webssl"
       svc default-domain "Contoso.Local"
       svc keep-client-installed
       svc split include 10.236.5.0 255.255.255.0
       svc split include 10.236.6.0 255.255.255.0
       svc split include 172.31.1.0 255.255.255.0
       svc split include 172.21.51.0 255.255.255.0
       svc dns-server primary 172.21.51.10
    default-group-policy policy1
    gateway gateway1
    inservice
    end
    Gateway#          

  • SCCM 2007 client registration not working.

    Hi guys,
    i'm in the following situation. Existing SCCM 2007 server at a customers environment. Site is running in Mixed mode. Windows XP clients connected by VPN to the customers infrastructure. The only allowed communication is Port 3333 (http) and Port
    3334 (https) from Windows XP to the SCCM Server for Client -> Server Communication. The client is not in the domain, has no DNS and no WINS available. Customer would like to install the SCCM Agent to these computers for hardware inventory purposes.
    What I did:
    Changed the SCCM Client Communication Port from 80 to 3333 (HTTP)
    Changed Site Mode Settings to "Automatically approve all computers" (I know it is not recommended but for first testing, this is ok for us.
    Added a host file entry on the Windows XP client to point sccm01.mydomain.local to the appropriate IP Adress of the SCCM Server.
    Manually installed the SCCM client on the Windows XP client by using the following command
    -> ccmsetup.exe CCMHTTPPORT=3333 CCMHTTPSPORT=3334 SMSMP=sccm01.mydomain.local SMSSLP=sccm01.mydomain.local SMSSITECODE=TST
    I see that the client gets installed and shows the correct Site Code etc. but it never appears on the SCCM Server. The ClientIDManagerStartup.log shows that the registration fails:
    RegTask - Executing registration task synchronously. 1/1/1601 12:00:00 AM 0 (0x0000)
    Evaluated SMBIOS (encoded): 1/1/1601 12:00:00 AM 0 (0x0000)
    SMBIOS unchanged 1/1/1601 12:00:00 AM 0 (0x0000)
    SID unchanged 1/1/1601 12:00:00 AM 0 (0x0000)
    HWID unchanged 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Initial backoff interval: 1 minutes 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Reset backoff interval: 257 minutes 1/1/1601 12:00:00 AM 0 (0x0000)
    RegEndPoint: Event notification: CCM_RemoteClient_Reassigned 1/1/1601 12:00:00 AM 0 (0x0000)
    RegEndPoint: Received notification for site assignment change from '<none>' to 'TST'. 1/1/1601 12:00:00 AM 0 (0x0000)
    GetSystemEnclosureChassisInfo: IsFixed=TRUE, IsLaptop=FALSE 1/1/1601 12:00:00 AM 0 (0x0000)
    Computed HardwareID=2:C0D8D94C7EAA20E943DEDC77694E744B8C147C09
    Win32_SystemEnclosure.SerialNumber=
    Win32_SystemEnclosure.SMBIOSAssetTag=
    Win32_BaseBoard.SerialNumber=
    Win32_BIOS.SerialNumber=
    Win32_NetworkAdapterConfiguration.MACAddress=xx:xx:xx:xx:xx:xx 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Client is not registered. Sending registration request... 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Failed to send registration request message. Error: 0x80040231 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Failed to send registration request. Error: 0x80040231 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Client is not registered. Sending registration request... 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Failed to send registration request message. Error: 0x80040309 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Failed to send registration request. Error: 0x80040309 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Client is not registered. Sending registration request... 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Failed to send registration request message. Error: 0x80040309 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Failed to send registration request. Error: 0x80040309 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Client is not registered. Sending registration request... 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Failed to send registration request message. Error: 0x80040309 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Failed to send registration request. Error: 0x80040309 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Client is not registered. Sending registration request... 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Client registration is pending. 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Client is pending registration. Sending confirmation request... 1/1/1601 12:00:00 AM 0 (0x0000)
    RegTask: Client is pending registration. Sending confirmation request... 1/1/1601 12:00:00 AM 0 (0x0000)
    In the CertificateMaintenance.log on the client I can see the following:
    Failed to verify signature for assigned MP. 1/1/1601 12:00:00 AM 0 (0x0000)
    Failed to verify signature for assigned MP. 1/1/1601 12:00:00 AM 0 (0x0000)
    Failed to verify signature for assigned MP. 1/1/1601 12:00:00 AM 0 (0x0000)
    Do you have any idea what I'm doing wrong? Did I miss an important step?
    Thanks in advance for any suggestion!
    Regards
    Stefan

    Did you add the SCCM server name and IP in LMHOST File  ? if not done please do it and check.
    are you able to browse the MP URL ?
    https://xxxxxxx.xxxx.com/SMS_MP/.sms_aut?mpcert
    but not the other one https://xxxxxxxx.xxxx.com/SMS_MP/.sms_aut?mplist
    http://www.windows-noob.com/forums/index.php?/topic/2029-managing-workgroup-computers-in-sccm-sms-environment/
    http://www.windows-noob.com/forums/index.php?/topic/8977-how-can-i-remotely-control-workgroup-computers-in-system-center-2012-configuration-manager/
    Kamala kannan.c| Please remember to click “Mark as Answer” or Vote as Helpful if its helpful for you. |Disclaimer: This posting is provided with no warranties and confers no rights

  • Automatic Client Push not working - Site System Servers

    Having an issue getting automatic site-wise client push to work when only
    having "Configuration Manager site system servers" selected.  This was turned on after discovery was enabled and fully executed.
    SCCM 2012 R2 CU1, Single Primary Site Server, 2 Management Points (one on primary and second is standalone), with 5 DP's (currently), SQL is standalone.
    The site systems are within the IP range boundaries and show as assigned (i.e. site code showing in console of object).  The boundaries are in a boundary group with site assignment selected, and a DP added.  When I view the object properties I
    see its returning the correct IP that does fall withing the IP range boundary.
    Nothing in the ccm.log indicating its ever trying to install the client and the ccr and ccrretry folders are empty.  I can do a manual client push without issue to a site server object or a discovered desktop/laptop object.
    Is there something I may be missing here?  And does anyone know the interval in which SCCM should be creating ccr records for discovered objects that don't have a client?

    Thanks or the quick replies everyone.  To answer Idan's questions, no errors in log or component status and SQL is not clustered.
    John, I hope this isn't the case.  If it were wouldn't that effectively mean you would not be able to enabled discovery until you are ready to turn on auto client push?  And if you did that you would have no way to control the client roll out.
     Maybe I am missing something in that equation.  I'll test that theory regardless but if that ends up being the case that is alarming!  :-)
    Jason, thanks for the tip on the potential bug.  Was really more so hoping to validate automatic client push rather than actually needing it for my site system servers.  So if it is the issue you reference above hopefully its just contained to
    the site system servers.  Would be nice to be able to select automatic client push to just a collection of devices prior to turning it on for site wide deployment.  
    I guess I could always just turn off discovery temporarily and delete all but some test clients, enable client push for workstations, then once validated, turn it back off and re-enable discovery.  (wouldn't turn push back on until most clients are
    deployed on the roll out schedule)

  • Client Push not working - Error 67, 5 & Install issues

    HI Everyone
    I cannot push the CCM Client to our computers.  You can manually install ccmsetup.exe on the client, and everything works.  There are no firewall issues.  I can get to the admin$ drive from the server to the client.  But when I push down
    the client, it comes up with error 67(---> ERROR: Unable to access target machine for request: "16777219", machine name: "CM-1208-O-CCB1",  access denied or invalid network path.)  
    The account I am using is a domain administrator, in the domain admin group.  The only way I can get push to work is to add our SCCM server to the clients admin group.  Then push works fine.  
    So its a permissions thing, but I can't figure out how to resolve it without adding our server to the domain admin group in AD.  We don't want to do this for security reasons.  
    We have not installed the Extended AD Schema; but I doubt that is the issue.  
    Can someone suggest something to help me fix this problem? What am I missing?
    Thanks
    Chad

    Here is the most recent log.  
    The files copy over now, but nothing happens after that.  There is a WMI error, but I've disabled the firewall, and enabled remote WMI administration.  However, I do not think that is preventing it from installing. 
    ======>Begin Processing request: "16777221", machine name: "CM-1208-O-CCB2" SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:56 AM 3348 (0x0D14)
    Execute query exec [sp_IsMPAvailable] N'SC1' SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:57 AM 3348 (0x0D14)
    ---> Trying the 'best-shot' account which worked for previous CCRs (index = 0x0) SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:57 AM 3348 (0x0D14)
    ---> Attempting to connect to administrative share '\\CM-1208-O-CCB2\admin$' using account 'MCCAD\chad.brower' SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:57 AM 3348 (0x0D14)
    ---> The 'best-shot' account has now succeeded 15 times and failed 9 times. SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:57 AM 3348 (0x0D14)
    ---> Connected to administrative share on machine CM-1208-O-CCB2 using account 'MCCAD\chad.brower' SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:57 AM 3348 (0x0D14)
    ---> Attempting to make IPC connection to share <\\CM-1208-O-CCB2\IPC$> SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:57 AM 3348 (0x0D14)
    ---> Searching for SMSClientInstall.* under '\\CM-1208-O-CCB2\admin$\' SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:57 AM 3348 (0x0D14)
    ---> System OS version string "6.3.9600" converted to 6.30 SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:57 AM 3348 (0x0D14)
    Submitted request successfully SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:58 AM 12600 (0x3138)
    Getting a new request from queue "Incoming" after 100 millisecond delay. SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:59 AM 12600 (0x3138)
    Waiting for change in directory "C:\Program Files\Microsoft Configuration Manager\inboxes\ccr.box" for queue "Incoming", (30 minute backup timeout). SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:59 AM 12600 (0x3138)
    ---> Unable to connect to WMI (root\ccm) on remote machine "CM-1208-O-CCB2", error = 0x8004100e. SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:59 AM 3348 (0x0D14)
    ---> Creating \ VerifyingCopying exsistance of destination directory \\CM-1208-O-CCB2\admin$\ccmsetup. SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:59 AM 3348 (0x0D14)
    ---> Copying client files to \\CM-1208-O-CCB2\admin$\ccmsetup. SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:59 AM 3348 (0x0D14)
    ---> Copying file "C:\Program Files\Microsoft Configuration Manager\bin\I386\MobileClient.tcf" to "MobileClient.tcf" SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:59 AM 3348 (0x0D14)
    ---> Copying file "C:\Program Files\Microsoft Configuration Manager\bin\I386\ccmsetup.exe" to "ccmsetup.exe" SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:59 AM 3348 (0x0D14)
    ---> Created service "ccmsetup" on machine "CM-1208-O-CCB2". SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:04:59 AM 3348 (0x0D14)
    ---> Started service "ccmsetup" on machine "CM-1208-O-CCB2". SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:05:00 AM 3348 (0x0D14)
    ---> Deleting SMS Client Install Lock File '\\CM-1208-O-CCB2\admin$\SMSClientInstall.SC1' SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:05:00 AM 3348 (0x0D14)
    Execute query exec [sp_CP_SetLastErrorCode] 16777221, 0 SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:05:00 AM 3348 (0x0D14)
    ---> Completed request "16777221", machine name "CM-1208-O-CCB2". SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:05:00 AM 3348 (0x0D14)
    Deleted request "16777221", machine name "CM-1208-O-CCB2" SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:05:00 AM 3348 (0x0D14)
    Execute query exec [sp_CP_SetPushRequestMachineStatus] 16777221, 4 SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:05:00 AM 3348 (0x0D14)
    Execute query exec [sp_CP_SetLatest] 16777221, N'10/29/2014 12:05:00', 48 SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:05:00 AM 3348 (0x0D14)
    <======End request: "16777221", machine name: "CM-1208-O-CCB2". SMS_CLIENT_CONFIG_MANAGER 10/29/2014 8:05:00 AM 3348 (0x0D14)
    Here is the log from the client machine.  Now it seems it can't find the DP..  Would this have anything to do with not having AD Schema extended or just a DNS problem?
    ==========[ ccmsetup started in process 2020 ]========== ccmsetup 10/29/2014 8:05:00 AM 4024 (0x0FB8)
    Running on platform X64 ccmsetup 10/29/2014 8:05:00 AM 4024 (0x0FB8)
    Launch from folder C:\windows\ccmsetup\ ccmsetup 10/29/2014 8:05:00 AM 4024 (0x0FB8)
    CcmSetup version: 5.0.7958.1000 ccmsetup 10/29/2014 8:05:00 AM 4024 (0x0FB8)
    In ServiceMain ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    Running on 'Microsoft Windows 8.1 Enterprise' (6.3.9600). Service Pack (0.0). SuiteMask = 272. Product Type = 18 ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    Ccmsetup command line: "C:\windows\ccmsetup\ccmsetup.exe" /runservice /config:MobileClient.tcf ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    Command line parameters for ccmsetup have been specified. No registry lookup for command line parameters is required. ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    Command line: "C:\windows\ccmsetup\ccmsetup.exe" /runservice /config:MobileClient.tcf ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    SslState value: 224 ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    CCMHTTPPORT: 80 ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    CCMHTTPSPORT: 443 ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    CCMHTTPSSTATE: 224 ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    CCMHTTPSCERTNAME: ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    FSP: SOURCREAM ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    CCMFIRSTCERT: 1 ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    Config file: C:\windows\ccmsetup\MobileClientUnicode.tcf ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    Retry time: 10 minute(s) ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    MSI log file: C:\windows\ccmsetup\Logs\client.msi.log ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    MSI properties: INSTALL="ALL" FSP="SOURCREAM" SMSSITECODE="SC1" CCMLOGLEVEL="0" CCMHTTPPORT="80" CCMHTTPSPORT="443" CCMHTTPSSTATE="224" CCMFIRSTCERT="1" ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    Source List: ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    \\SOURCREAM.mccad.mcc.edu\SMSClient ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    \\SOURCREAM.MCCAD.MCC.EDU\SMSClient ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    MPs: ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    SOURCREAM.mccad.mcc.edu ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    MapNLMCostDataToCCMCost() returning Cost 0x1 ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    No version of the client is currently detected. ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    Folder 'Microsoft\Configuration Manager' not found. Task does not exist. ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    Updated security on object C:\windows\ccmsetup\. ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    Sending Fallback Status Point message to 'SOURCREAM', STATEID='100'. ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    Failed to get client version for sending messages to FSP. Error 0x8004100e ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    Params to send FSP message '5.0.7958.1000 Deployment ' ccmsetup 10/29/2014 8:05:00 AM 3036 (0x0BDC)
    receiving response with winhttp failed; 80072efe FSPStateMessage 10/29/2014 8:05:21 AM 3036 (0x0BDC)
    Running as user "SYSTEM" ccmsetup 10/29/2014 8:05:21 AM 3036 (0x0BDC)
    Detected 211154 MB free disk space on system drive. ccmsetup 10/29/2014 8:05:21 AM 3036 (0x0BDC)
    Checking Write Filter Status. ccmsetup 10/29/2014 8:05:21 AM 3036 (0x0BDC)
    This is not a supported write filter device. We are not in a write filter maintenance mode. ccmsetup 10/29/2014 8:05:21 AM 3036 (0x0BDC)
    Performing AD query: '(&(ObjectCategory=mSSMSManagementPoint)(mSSMSDefaultMP=TRUE)(mSSMSSiteCode=SC1))' ccmsetup 10/29/2014 8:05:21 AM 3036 (0x0BDC)
    Retrieved 0 MP records from AD for site 'SC1' ccmsetup 10/29/2014 8:05:21 AM 3036 (0x0BDC)
    Failed to get site version from AD with error 0x87d00215 ccmsetup 10/29/2014 8:05:21 AM 3036 (0x0BDC)
    Sending message header '<Msg SchemaVersion="1.1"><ID>{5CAF943A-27EE-405F-873C-4CBA5D6BE2EB}</ID><SourceHost>CM-1208-O-CCB2</SourceHost><TargetAddress>mp:[http]MP_LocationManager</TargetAddress><ReplyTo>direct:CM-1208-O-CCB2:LS_ReplyLocations</ReplyTo><Priority>3</Priority><Timeout>600</Timeout><ReqVersion>5931</ReqVersion><TargetHost>SOURCREAM.mccad.mcc.edu</TargetHost><TargetEndpoint>MP_LocationManager</TargetEndpoint><ReplyMode>Sync</ReplyMode><Protocol>http</Protocol><SentTime>2014-10-29T12:05:21Z</SentTime><Body Type="ByteRange" Offset="0" Length="186"/><Hooks><Hook3 Name="zlib-compress"/></Hooks><Payload Type="inline"/></Msg>' ccmsetup 10/29/2014 8:05:21 AM 3036 (0x0BDC)
    MapNLMCostDataToCCMCost() returning Cost 0x1 ccmsetup 10/29/2014 8:05:21 AM 3036 (0x0BDC)
    CCM_POST 'HTTP://SOURCREAM.mccad.mcc.edu/ccm_system/request' ccmsetup 10/29/2014 8:05:21 AM 3036 (0x0BDC)
    Failed to get site version from MP 'SOURCREAM.mccad.mcc.edu' with error 0x80072efe ccmsetup 10/29/2014 8:05:42 AM 3036 (0x0BDC)
    SiteCode: SC1 ccmsetup 10/29/2014 8:05:42 AM 3036 (0x0BDC)
    SiteVersion: ccmsetup 10/29/2014 8:05:42 AM 3036 (0x0BDC)
    Only one MP SOURCREAM.mccad.mcc.edu is specified. Use it. ccmsetup 10/29/2014 8:05:42 AM 3036 (0x0BDC)
    Searching for DP locations from MP(s)... ccmsetup 10/29/2014 8:05:42 AM 3036 (0x0BDC)
    Current AD site of machine is CM1143A LocationServices 10/29/2014 8:05:42 AM 3036 (0x0BDC)
    Local Machine is joined to an AD domain LocationServices 10/29/2014 8:05:42 AM 3036 (0x0BDC)
    Current AD forest name is mccad.mcc.edu, domain name is mccad.mcc.edu LocationServices 10/29/2014 8:05:42 AM 3036 (0x0BDC)
    DhcpGetOriginalSubnetMask entry point is supported. LocationServices 10/29/2014 8:05:42 AM 3036 (0x0BDC)
    Begin checking Alternate Network Configuration LocationServices 10/29/2014 8:05:42 AM 3036 (0x0BDC)
    Finished checking Alternate Network Configuration LocationServices 10/29/2014 8:05:42 AM 3036 (0x0BDC)
    Adapter {5899829D-895E-430B-B150-63FE6989E4B9} is DHCP enabled. Checking quarantine status. LocationServices 10/29/2014 8:05:42 AM 3036 (0x0BDC)
    Sending message body '<ContentLocationRequest SchemaVersion="1.00">
    <AssignedSite SiteCode="SC1"/>
    <ClientPackage/>
    <ClientLocationInfo LocationType="SMSPACKAGE" DistributeOnDemand="0" UseProtected="0" AllowCaching="0" BranchDPFlags="0" AllowHTTP="1" AllowSMB="0" AllowMulticast="0" UseInternetDP="0">
    <ADSite Name="CM1143A"/>
    <Forest Name="mccad.mcc.edu"/>
    <Domain Name="mccad.mcc.edu"/>
    <IPAddresses>
    <IPAddress SubnetAddress="10.26.0.0" Address="10.26.2.57"/>
    </IPAddresses>
    </ClientLocationInfo>
    </ContentLocationRequest>
    ' ccmsetup 10/29/2014 8:05:42 AM 3036 (0x0BDC)
    Sending message header '<Msg SchemaVersion="1.1"><ID>{42770D1B-3371-412E-9726-887C2BA3B2EA}</ID><SourceHost>CM-1208-O-CCB2</SourceHost><TargetAddress>mp:[http]MP_LocationManager</TargetAddress><ReplyTo>direct:CM-1208-O-CCB2:LS_ReplyLocations</ReplyTo><Priority>3</Priority><Timeout>600</Timeout><ReqVersion>5931</ReqVersion><TargetHost>SOURCREAM.mccad.mcc.edu</TargetHost><TargetEndpoint>MP_LocationManager</TargetEndpoint><ReplyMode>Sync</ReplyMode><Protocol>http</Protocol><SentTime>2014-10-29T12:05:42Z</SentTime><Body Type="ByteRange" Offset="0" Length="1090"/><Hooks><Hook3 Name="zlib-compress"/></Hooks><Payload Type="inline"/></Msg>' ccmsetup 10/29/2014 8:05:42 AM 3036 (0x0BDC)
    MapNLMCostDataToCCMCost() returning Cost 0x1 ccmsetup 10/29/2014 8:05:42 AM 3036 (0x0BDC)
    CCM_POST 'HTTP://SOURCREAM.mccad.mcc.edu/ccm_system/request' ccmsetup 10/29/2014 8:05:42 AM 3036 (0x0BDC)
    GetDPLocations failed with error 0x80072efe ccmsetup 10/29/2014 8:06:04 AM 3036 (0x0BDC)
    Failed to get DP locations as the expected version from MP 'SOURCREAM.mccad.mcc.edu'. Error 0x80072efe ccmsetup 10/29/2014 8:06:04 AM 3036 (0x0BDC)
    Sending Fallback Status Point message to 'SOURCREAM', STATEID='101'. ccmsetup 10/29/2014 8:06:04 AM 3036 (0x0BDC)
    Failed to get client version for sending messages to FSP. Error 0x8004100e ccmsetup 10/29/2014 8:06:04 AM 3036 (0x0BDC)
    Params to send FSP message '5.0.7958.1000 Deployment ' ccmsetup 10/29/2014 8:06:04 AM 3036 (0x0BDC)
    receiving response with winhttp failed; 80072efe FSPStateMessage 10/29/2014 8:06:25 AM 3036 (0x0BDC)
    Next retry in 10 minute(s)... ccmsetup 10/29/2014 8:06:25 AM 3036 (0x0BDC)

  • SCCM 2012 Client Push Not Working

    Hello,
    The issue I'm having seems to be with getting the client installed on our Windows 7 64bit PC environment. 
    Once the client push request is sent, the client PC shows the "ccmsetup.exe *32" process running when I open task manager and look at the processes running, however after it finishes nothing is installed. 
    From the SCCM server I can access the
    \\CLIENTPC\ADMIN$ share, so I’m sure permissions are fine. 
    I'm very new to getting this configured and I'm not sure why it would go this far but never actually install. 
    Any help in the right direction would be greatly appreciated. 
    Here is a copy of the ccmsetup.log from the client if it might help:
    <IPAddress SubnetAddress="172.XXX.XXX.0" Address="172.XXX.XXX.6"/>
        </IPAddresses>
      </ClientLocationInfo>
    </ContentLocationRequest>
    ']LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="0" thread="4584" file="siteinfo.cpp:96">
    <![LOG[Sending message header '<Msg SchemaVersion="1.1"><ID>{D3D8AA78-3B63-4E8E-92FD-43064FD1B1B3}</ID><SourceHost>CLIENTPC</SourceHost><TargetAddress>mp:[http]MP_LocationManager</TargetAddress><ReplyTo>direct:CLIENTPC:LS_ReplyLocations</ReplyTo><Priority>3</Priority><Timeout>600</Timeout><ReqVersion>5931</ReqVersion><TargetHost>HTTPS://SCCMServer01.mydomain.com</TargetHost><TargetEndpoint>MP_LocationManager</TargetEndpoint><ReplyMode>Sync</ReplyMode><Protocol>http</Protocol><SentTime>2014-09-27T02:21:45Z</SentTime><Body
    Type="ByteRange" Offset="0" Length="1082"/><Hooks><Hook3 Name="zlib-compress"/></Hooks><Payload Type="inline"/></Msg>']LOG]!><time="22:21:45.792+240" date="09-26-2014"
    component="ccmsetup" context="" type="0" thread="4584" file="siteinfo.cpp:177">
    <![LOG[CCM_POST 'HTTPS://SCCMServer01.mydomain.com/ccm_system/request']LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="1" thread="4584" file="httphelper.cpp:807">
    <![LOG[Begin searching client certificates based on Certificate Issuers]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="1" thread="4584" file="ccmcert.cpp:3833">
    <![LOG[Completed searching client certificates based on Certificate Issuers]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="1" thread="4584" file="ccmcert.cpp:3992">
    <![LOG[Begin to select client certificate]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="1" thread="4584" file="ccmcert.cpp:4073">
    <![LOG[The 'Certificate Selection Criteria' was not specified, counting number of certificates present in 'MY' store of 'Local Computer'.]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context=""
    type="0" thread="4584" file="ccmcert.cpp:4109">
    <![LOG[There are no certificates in the 'MY' store.]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="1" thread="4584" file="ccmcert.cpp:4131">
    <![LOG[GetSSLCertificateContext failed with error 0x87d00280]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="3" thread="4584" file="ccmsetup.cpp:6025">
    <![LOG[GetHttpRequestObjects failed for verb: 'CCM_POST', url: 'HTTPS://SCCMServer01.mydomain.com/ccm_system/request']LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="3"
    thread="4584" file="httphelper.cpp:947">
    <![LOG[GetDPLocations failed with error 0x87d00280]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="3" thread="4584" file="siteinfo.cpp:532">
    <![LOG[Failed to get DP locations as the expected version from MP 'HTTPS://SCCMServer01.mydomain.com'. Error 0x87d00280]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context=""
    type="2" thread="4584" file="ccmsetup.cpp:10926">
    <![LOG[Failed to find DP locations from MP 'HTTPS://SCCMServer01.mydomain.com' with error 0x87d00280, status code 200. Check next MP.]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context=""
    type="2" thread="4584" file="ccmsetup.cpp:10782">
    <![LOG[Only one MP HTTPS://SCCMServer01.mydomain.com is specified. Use it.]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="1" thread="4584" file="ccmsetup.cpp:9745">
    <![LOG[Have already tried all MPs. Couldn't find DP locations.]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="3" thread="4584" file="ccmsetup.cpp:10811">
    <![LOG[GET 'HTTPS://SCCMServer01.mydomain.com/CCM_Client/ccmsetup.cab']LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="1" thread="4584" file="httphelper.cpp:807">
    <![LOG[Begin searching client certificates based on Certificate Issuers]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="1" thread="4584" file="ccmcert.cpp:3833">
    <![LOG[Completed searching client certificates based on Certificate Issuers]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="1" thread="4584" file="ccmcert.cpp:3992">
    <![LOG[Begin to select client certificate]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="1" thread="4584" file="ccmcert.cpp:4073">
    <![LOG[The 'Certificate Selection Criteria' was not specified, counting number of certificates present in 'MY' store of 'Local Computer'.]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context=""
    type="0" thread="4584" file="ccmcert.cpp:4109">
    <![LOG[There are no certificates in the 'MY' store.]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="1" thread="4584" file="ccmcert.cpp:4131">
    <![LOG[GetSSLCertificateContext failed with error 0x87d00280]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="3" thread="4584" file="ccmsetup.cpp:6025">
    <![LOG[GetHttpRequestObjects failed for verb: 'GET', url: 'HTTPS://SCCMServer01.mydomain.com/CCM_Client/ccmsetup.cab']LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="3"
    thread="4584" file="httphelper.cpp:947">
    <![LOG[DownloadFileByWinHTTP failed with error 0x87d00280]LOG]!><time="22:21:45.792+240" date="09-26-2014" component="ccmsetup" context="" type="3" thread="4584" file="httphelper.cpp:1081">
    <![LOG[CcmSetup failed with error code 0x87d00280]LOG]!><time="22:21:45.808+240" date="09-26-2014" component="ccmsetup" context="" type="1" thread="2552" file="ccmsetup.cpp:10544">

    This system is something I inherited from another system admin who set this up so I was unsure of how this was deployed.  I did go in and see that it had been set to deploy using ONLY HTTPS.  I have changed it to use either HTTPS or HTTP now. 
    Unfortunately I'm still getting the same result of ccmsetup.exe running on the client machine but it is not installing.  I see in the log that I'm still getting the 0x87d00280 error, but that should matter since it is now set to use HTTPS or HTTP correct?
    <IPAddress SubnetAddress="172.XXX.XXX.0" Address="172.XXX.XXX.6"/>
        </IPAddresses>
      </ClientLocationInfo>
    </ContentLocationRequest>
    ']LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="0" thread="5032" file="siteinfo.cpp:96">
    <![LOG[Sending message header '<Msg SchemaVersion="1.1"><ID>{AB0BE041-48D1-4BA3-8B1C-167DB7899CF3}</ID><SourceHost>CLIENTPC</SourceHost><TargetAddress>mp:[http]MP_LocationManager</TargetAddress><ReplyTo>direct:CLIENTPC:LS_ReplyLocations</ReplyTo><Priority>3</Priority><Timeout>600</Timeout><ReqVersion>5931</ReqVersion><TargetHost>HTTPS://SCCMServer.mydomain.com</TargetHost><TargetEndpoint>MP_LocationManager</TargetEndpoint><ReplyMode>Sync</ReplyMode><Protocol>http</Protocol><SentTime>2014-09-27T13:57:13Z</SentTime><Body
    Type="ByteRange" Offset="0" Length="1082"/><Hooks><Hook3 Name="zlib-compress"/></Hooks><Payload Type="inline"/></Msg>']LOG]!><time="09:57:13.404+240" date="09-27-2014"
    component="ccmsetup" context="" type="0" thread="5032" file="siteinfo.cpp:177">
    <![LOG[CCM_POST 'HTTPS://SCCMServer.mydomain.com/ccm_system/request']LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="1" thread="5032" file="httphelper.cpp:807">
    <![LOG[Begin searching client certificates based on Certificate Issuers]LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="1" thread="5032" file="ccmcert.cpp:3833">
    <![LOG[Completed searching client certificates based on Certificate Issuers]LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="1" thread="5032" file="ccmcert.cpp:3992">
    <![LOG[Begin to select client certificate]LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="1" thread="5032" file="ccmcert.cpp:4073">
    <![LOG[The 'Certificate Selection Criteria' was not specified, counting number of certificates present in 'MY' store of 'Local Computer'.]LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context=""
    type="0" thread="5032" file="ccmcert.cpp:4109">
    <![LOG[There are no certificates in the 'MY' store.]LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="1" thread="5032" file="ccmcert.cpp:4131">
    <![LOG[GetSSLCertificateContext failed with error 0x87d00280]LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="3" thread="5032" file="ccmsetup.cpp:6025">
    <![LOG[GetHttpRequestObjects failed for verb: 'CCM_POST', url: 'HTTPS://SCCMServer.mydomain.com/ccm_system/request']LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="3"
    thread="5032" file="httphelper.cpp:947">
    <![LOG[GetDPLocations failed with error 0x87d00280]LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="3" thread="5032" file="siteinfo.cpp:532">
    <![LOG[Failed to get DP locations as the expected version from MP 'HTTPS://SCCMServer.mydomain.com'. Error 0x87d00280]LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="2"
    thread="5032" file="ccmsetup.cpp:10926">
    <![LOG[Failed to find DP locations from MP 'HTTPS://SCCMServer.mydomain.com' with error 0x87d00280, status code 200. Check next MP.]LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context=""
    type="2" thread="5032" file="ccmsetup.cpp:10782">
    <![LOG[Only one MP HTTPS://SCCMServer.mydomain.com is specified. Use it.]LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="1"
    thread="5032" file="ccmsetup.cpp:9745">
    <![LOG[Have already tried all MPs. Couldn't find DP locations.]LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="3" thread="5032" file="ccmsetup.cpp:10811">
    <![LOG[GET 'HTTPS://SCCMServer.mydomain.com/CCM_Client/ccmsetup.cab']LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="1" thread="5032" file="httphelper.cpp:807">
    <![LOG[Begin searching client certificates based on Certificate Issuers]LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="1" thread="5032" file="ccmcert.cpp:3833">
    <![LOG[Completed searching client certificates based on Certificate Issuers]LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="1" thread="5032" file="ccmcert.cpp:3992">
    <![LOG[Begin to select client certificate]LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="1" thread="5032" file="ccmcert.cpp:4073">
    <![LOG[The 'Certificate Selection Criteria' was not specified, counting number of certificates present in 'MY' store of 'Local Computer'.]LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context=""
    type="0" thread="5032" file="ccmcert.cpp:4109">
    <![LOG[There are no certificates in the 'MY' store.]LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="1" thread="5032" file="ccmcert.cpp:4131">
    <![LOG[GetSSLCertificateContext failed with error 0x87d00280]LOG]!><time="09:57:13.404+240" date="09-27-2014" component="ccmsetup" context="" type="3" thread="5032" file="ccmsetup.cpp:6025">
    <![LOG[GetHttpRequestObjects failed for verb: 'GET', url: 'HTTPS://SCCMServer.mydomain.com/CCM_Client/ccmsetup.cab']LOG]!><time="09:57:13.420+240" date="09-27-2014" component="ccmsetup" context="" type="3"
    thread="5032" file="httphelper.cpp:947">
    <![LOG[DownloadFileByWinHTTP failed with error 0x87d00280]LOG]!><time="09:57:13.420+240" date="09-27-2014" component="ccmsetup" context="" type="3" thread="5032" file="httphelper.cpp:1081">
    <![LOG[CcmSetup failed with error code 0x87d00280]LOG]!><time="09:57:13.420+240" date="09-27-2014" component="ccmsetup" context="" type="1" thread="960" file="ccmsetup.cpp:10544">

Maybe you are looking for