How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (2024)

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager. We need to have proper certificates to Authenticate and Encrypt the data flow between ConfigMgr clients and Management Point (Even in Mixed mode).

Sometimes, we need to play with certificates to resolve client authentication and registration issues. The following steps would be useful to fix that kind of issue.

Latest Post – Free ConfigMgr Training Part 2 | 20 Hours Of Technical | SCCM HTMD Blog (anoopcnair.com)

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager

The following topics are covered in this post how to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager.

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (1)

  • SMS certificate Store Details (MMC)
  • Export certificates
  • Import Certificates
  • Certificates stored folder location in windows explorer or in the file system
  • Find the location and name of the private key file associated the certificates

SMS certificate Store Details (MMC)

Launch MMC (mmc.exe) and Click on File —> Add/Remove Snap-in

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (2)

Select Certificates from Available Snap-ins and click on Add button

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (3)

Select “Computer Account” and click NEXT

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (4)

Select Local Computer and click on FINISH

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (5)

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (6)

Click OK on the “Add or Remove Snap-ins” window

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (7)

Here are the TWO certificates, “SMS Signing Certificate” and “SMS Encryption Certificate,” used for Authentication and Encryption.

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (8)

Export certificates

You need to right-click on the certificate All Tasks – Export….This will open up Certificate Export Wizard.

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (9)

Select “Yes, export the private key” and click “Next.”

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (10)

Select Export File Format” page, “Personal Information Exchange – PKCS #12(.PFX)” and click NEXT (Even, you can select INCLUDE and EXPORT checkboxes mentioned in the below screenshot)

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (11)

Type in the password on the Password window and click NEXT

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (12)

On the “File to Export” page, enter the file name you wish to store the exported certificate. Please do not give it an extension. Click NEXT

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (13)

Click on FINISH

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (14)

Import Certificates

Right Click on “Certificates (Local Computer)” –> “SMS” -> “Certificates” –> All Tasks –> Import

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (15)

On the “Welcome to the Certificate Import Wizard” page, click “NEXT.”

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (16)

Browse through and provide the path of the certificate export file you are importing, and click “NEXT.”

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (17)

Enter the password that you used in the export process, check “Mark this key as exportable. This will allow you to back up or transport your keys at a later time”, and click “NEXT.”

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (18)

“Place all certificates in the following store” should already be selected, and the Certificate store value should already say “SMS.” Click “NEXT”

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (19)

Click FINISH

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (20)

Certificates stored folder location in windows explorer or in the file system

Windows 2008 R2 servers – “C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys”

Windows 7 workstations – “C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys”

Note – Both SMS certificates are stored in the 19cf* Machine Key files.

Find the location and name of the private key file associated with the certificates

FindPrivateKey.exe tool can be used to find out those details.

Syntax and examples of FindPrivateKey.exe in the following MSDN link.

Download FindPrivateKey.exe HERE

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (21)

Author

AnoopisMicrosoft MVP! He is a Solution Architect in enterprise client management with more than 20 years of experience (calculation done in 2021) in IT. He is a blogger, Speaker, and Local User Group HTMD Community leader. His main focus is on Device Management technologies like SCCM 2012, Current Branch, and Intune. E writes about ConfigMgr, Windows 11, Windows 10, Azure AD, Microsoft Intune, Windows 365, AVD, etc…

How To Check And Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager HTMD Blog (2024)

FAQs

How to check SCCM client certificate? ›

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager
  1. SMS certificate Store Details (MMC)
  2. Export certificates.
  3. Import Certificates.
  4. Certificates stored folder location in windows explorer or in the file system.
  5. Find the location and name of the private key file associated the certificates.
Jan 24, 2022

How to verify SCCM client is installed? ›

In preparing a Windows-based client for use, you will need to check if all entries of SCCM are loaded on the client machine after post-config has completed. Not completing the last step of post-config causes SCCM to not install properly. Make sure that under the Components tab Status shows as installed or enabled.

How will you check if a SCCM client is healthy? ›

Launch MPA Tools and connect it to your SCCM site. Navigate to the “SCCM Client Properties” section and check the status of clients. MPA Tools provides a clear overview of client health, allowing you to identify any failures.

How to check version of Configuration Manager? ›

How to check the version. To check the version of your Configuration Manager site, in the console go to About Configuration Manager at the top-left corner of the console. This dialog displays the site and console versions. The console version is slightly different from the site version.

How do I check certificate configuration? ›

To check if SSL certificate is installed, you can use the Certificate Manager tool and check its validity period. Another alternative option is to use the sigcheck Windows Sysinternals utility to verify TLS version. Download the utility and run it with the switch command sigcheck -tv.

How to check certificate command? ›

Check the CSR, Private Key or Certificate using OpenSSL
  1. Check a CSR openssl req -text -noout -verify -in CSR.csr.
  2. Check a private key openssl rsa -in privateKey.key -check.
  3. Check a certificate openssl x509 -in certificate.crt -text -noout.
  4. Check a PKCS#12 file (.pfx or .p12) openssl pkcs12 -info -in keyStore.p12.

How to check Configuration Manager properties? ›

Go to Start > Control Panel > Configuration Manager . The Configuration Manager Properties dialog box is displayed.

How do I check my patch compliance in SCCM? ›

1.) In the SCCM console, navigate to the main menu Monitoring and then click the Reporting folder. 2.) Navigate to the sub-folder Software Updates - A Compliance, click on it and, on the right-hand side, right-click Compliance 2 - Specific software update, then Run.

How to check if SCCM is enabled? ›

How to check if a computer is SCCM or Intune managed
  1. Click the Start Menu.
  2. Click Settings.
  3. Click Accounts.
  4. Click Access work or school.
  5. If it says "Connected to Yale AD domain", it is managed by SCCM.
  6. If it says "Connected to Yale University's Azure AD", it is managed by Intune.

How to fix SCCM issues? ›

Repairing SCCM Client Components

In some cases, SCCM client components may become corrupt or damaged, causing the Software Center to malfunction. You can repair these components by running the Configuration Manager client repair process or by using the “ccmrepair.exe” command.

How do I check my content status in SCCM? ›

View content distribution
  1. In the Configuration Manager console, go to the Monitoring workspace, expand Distribution Status and select the Content Status node.
  2. If this node doesn't show anything, first distribute content.
  3. Select a distributed content item. ...
  4. In the ribbon, select View Content Distribution.
Oct 3, 2022

How to check SCCM server health? ›

This can be done by opening the SCCM console and navigating to the Monitoring workspace. From there, you can view the status of the site server and ensure that it is running properly. If any issues are found, they should be addressed as soon as possible to prevent them from becoming more serious problems.

Where is Configuration Manager SCCM? ›

Connecting to SCCM

Navigate to Admin | Configuration and select the Foreign Systems tab. Select System Center Configuration Manager. If this is not listed, make sure the connector is installed by verifying via the Privilege Manager Add/Upgrade Features page.

How do I update SCCM Configuration Manager? ›

At the top-level site of your hierarchy, in the Configuration Manager console, go to the Administration workspace, and select the Updates and Servicing node. Select an update with the state of Available, and then choose Install Update Pack in the ribbon. Your user account requires permissions to install updates.

How do I find my client certificate? ›

In Chrome, go to Settings. On the Settings page, below Default browser, click Show advanced settings. Under HTTPS/SSL, click Manage certificates. In the Certificates window, on the Personal tab, you should see your Client Certificate.

How do I know if my client certificate is valid? ›

To be considered valid, a client certificate must match all the validation rules defined by the attributes at the top-level element and match all defined claims for at least one of the defined identities. Use this policy to check incoming certificate properties against desired properties.

How to renew SCCM client certificate? ›

SCCM will renew the certificates automatically. If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

How do I open a client certificate? ›

Import a client certificate into Microsoft Internet Explorer
  1. On the Welcome page, click Next.
  2. On the File to Import page, click Browse and navigate to the location where you stored the certificate file.
  3. In the File Name field, type *. ...
  4. Select the certificate file and click Open, then click Next.
Mar 9, 2022

Top Articles
Latest Posts
Article information

Author: Carmelo Roob

Last Updated:

Views: 5797

Rating: 4.4 / 5 (45 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Carmelo Roob

Birthday: 1995-01-09

Address: Apt. 915 481 Sipes Cliff, New Gonzalobury, CO 80176

Phone: +6773780339780

Job: Sales Executive

Hobby: Gaming, Jogging, Rugby, Video gaming, Handball, Ice skating, Web surfing

Introduction: My name is Carmelo Roob, I am a modern, handsome, delightful, comfortable, attractive, vast, good person who loves writing and wants to share my knowledge and understanding with you.