Close Menu
    Facebook X (Twitter) Instagram
    Monday, November 3
    X (Twitter) LinkedIn Reddit RSS
    All about Endpoint Management
    • Home
    All about Endpoint Management
    Home»SCCM 2007»what are SCCM client Certificates(where are they stored)

    what are SCCM client Certificates(where are they stored)

    Eswar KonetiBy Eswar KonetiDecember 20, 11:35 am2 Mins Read SCCM 2007 31,180 Views
    Share
    Facebook Twitter LinkedIn Reddit

    When you install SMS or SCCM client,clients need to authenticate their management point prior to establishing communications to prevent attackers from inserting rogue management points and redirecting clients to them to get it .

    sometimes,client will fail to identify its management point which is tracked in locationservices.log file which requires attention could be issues like boundaries etc.

    there are cases,where client might require to assign from its current hierarchy to different hierarchy but the certificates might be exist with old hierarchy and you mush reset it before it communicates with New.

    To remove the trusted root key

    • On the client computer, run CCMSetup RESETKEYINFORMATION = TRUE.

    some info about What is the trusted root key?

    The trusted root key provides a mechanism for clients to verify the authenticity of the management point and its certificate if they cannot query Active Directory Domain Services. Every primary site server generates a trusted root key, even if the site is running in native mode and even if Active Directory Domain Services publishing is enabled. If the primary site is joined to a parent site, the child site eliminates its own trusted root key and instead trusts the trusted root key of the parent site.

    Clients require the trusted root key only if they cannot query the Global Catalog for Configuration Manager 2007 information, either because they are in a workgroup or remote forest, or because the Active Directory Domain Services schema is not extended for Configuration Manager 2007. The trusted root key is stored in WMI in the root\ccm\locationservices namespace.

    here is the procedure to identify the SMS client certificates.

    image

    image

    image

    image

    image

    image

    More information about Trusted Root Key : http://technet.microsoft.com/en-us/library/bb680495.aspx

    How to manage trusted root key in config mgr :http://technet.microsoft.com/en-us/library/bb632759.aspx

    How to Pre-provision the Trusted Root Key on Clients : http://technet.microsoft.com/en-us/library/bb680504.aspx

    Configuration Manager Cryptographic Controls http://technet.microsoft.com/en-us/library/bb693798.aspx

    Client Ceriticates for SCCM used in Client side SCCM client certificates Storage for SCCM client ceritificates What are SCCM client Certificates and where are they stored
    Share. Twitter LinkedIn Email Facebook Reddit

    Related Posts

    Monitoring Endpoint Security Applications with SCCM ConfigMgr SQL

    October 11, 8:48 pm

    Addressing SCCM Software Update Deployment Challenges with PowerShell – Remote install

    October 23, 10:23 am

    SCCM report list collections with no deployments

    December 05, 12:04 pm

    4 Comments

    1. Pingback: How do I create a certificate registration point in Configuration Manager? - What Type Degree

    2. Pingback: software-website.com December 2021

    3. SCCM Niko on October 20, 2014 5:15 PM

      Hi Anoop,

      Are you aware how we can renew Boot Media Certificates?

      For example, If one of my Boot Media Certificates is going to expire tomorrow how can I renew it? In the certificate properties there is no mention of exactly which boot media the certificate relates to so how can we identify which boot media the certificate belongs to and then renew it?

      Reply
      • Eswar Koneti on October 24, 2014 3:46 PM

        Are you looking for information from Anoop ? and its Anoop here .
        The certificates comes from your PXE Service point. for more information,you can refer the blog post http://elgwhoppo.com/2012/03/29/sccm-pxe-boot-media-certificate-expiration/
        and http://blogs.technet.com/b/deploymentguys/archive/2011/08/04/how-to-limit-or-restrict-the-use-of-bootable-media-devices-for-os-deployment-using-sccm.aspx

        Reply

    Leave a ReplyCancel reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.

    Sign Up

    Get email notifications for new posts.

    Author

    I’m Eswar Koneti ,a tech enthusiast, security advocate, and your guide to Microsoft Intune and Modern Device Management. My goal? To turn complex tech into actionable insights for a streamlined management experience. Let’s navigate this journey together!

    Support

    Awards

    Archives

    © Copyright 2009-2025 Eswar Koneti, All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.