NDES Troubleshooting - GetCACert&message=MyDeviceID get 404 error


hi all,

sccm integrated intune, built ndes server have scep profile deployed mobile devices use corporate wifi network. ca, ndes, sccm in different servers , os windows 2012 r2. crp installed in sccm primary server , policy module plugin installed in ndes server. followed following blog "https://blogs.technet.microsoft.com/tune_in_to_windows_intune/2014/04/25/part-2-scep-certificate-enrolling-using-configmgr-2012-crp-ndes-and-windows-intune/" installing , configuring ndes server. outputs resulted expected except below url.

https://uslndesprd01.corp.usl.in/certsrv/mscep/mscep?operation=getcacert&message=mydeviceid

it gives 404 error , not download cert file. logged support case microsoft, not able find cause even. tried enabling mscep.log in ndes server enabling load user profile, did not create mscep.log file. disappointing , stopping our production rollout. please help.

*********************************crpctrl.log*********************************

checking crp service availability state sms_certificate_registration_point 12/26/2016 10:07:07 am 22376 (0x5768)
machine name 'sccmpmrprd01.corp.usl.in'. sms_certificate_registration_point 12/26/2016 10:07:08 am 22376 (0x5768)
begin validation of certificate [thumbprint ede92580190188371ab3416ff3ecee6362538397] issued 'sccmpmrprd01.corp.usl.in' sms_certificate_registration_point 12/26/2016 10:07:08 am 22376 (0x5768)
certificate has "ssl client authentication" capability. sms_certificate_registration_point 12/26/2016 10:07:08 am 22376 (0x5768)
completed validation of certificate [thumbprint ede92580190188371ab3416ff3ecee6362538397] issued 'sccmpmrprd01.corp.usl.in' sms_certificate_registration_point 12/26/2016 10:07:08 am 22376 (0x5768)
begin validation of certificate [thumbprint 79231e2ba317d9d142710a5b0dda668612c6f6f8] issued 'sccmpmrprd01.corp.usl.in' sms_certificate_registration_point 12/26/2016 10:07:08 am 22376 (0x5768)
certificate doesn't have "ssl client authentication" capabilities. sms_certificate_registration_point 12/26/2016 10:07:08 am 22376 (0x5768)
completed validation of certificate [thumbprint 79231e2ba317d9d142710a5b0dda668612c6f6f8] issued 'sccmpmrprd01.corp.usl.in' sms_certificate_registration_point 12/26/2016 10:07:08 am 22376 (0x5768)
skipping certificate not valid configmgr usage. sms_certificate_registration_point 12/26/2016 10:07:08 am 22376 (0x5768)
>>> selected certificate [thumbprint ede92580190188371ab3416ff3ecee6362538397] issued 'sccmpmrprd01.corp.usl.in' https client authentication sms_certificate_registration_point 12/26/2016 10:07:08 am 22376 (0x5768)
crp's previous status 0 (0 = online, 1 = failed, 4 = undefined) sms_certificate_registration_point 12/26/2016 10:07:08 am 22376 (0x5768)
completed crp availability check against local computer. sms_certificate_registration_point 12/26/2016 10:07:08 am 22376 (0x5768)

*********************************crpctrl.log*********************************

*********************************inetpub logs*********************************

#software: microsoft internet information services 8.5
#version: 1.0
#date: 2016-12-26 02:31:18
#fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(user-agent) cs(referer) sc-status sc-substatus sc-win32-status time-taken
2016-12-26 02:31:18 ::1 /certsrv/mscep/mscep.dll operation=getcacert&message=scep%20authority 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 0
2016-12-26 02:31:20 ::1 /certsrv/mscep/mscep.dll operation=getcacaps&message=scep%20authority 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 0
2016-12-26 02:31:21 ::1 /certsrv/mscep/mscep.dll ... 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 158
2016-12-26 02:31:25 ::1 /certsrv/mscep/mscep.dll operation=getcacert&message=scep%20authority 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 0
2016-12-26 02:31:25 ::1 /certsrv/mscep/mscep.dll operation=getcacaps&message=scep%20authority 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 0
2016-12-26 02:31:30 ::1 /certsrv/mscep/mscep.dll ... 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 109
#software: microsoft internet information services 8.5
#version: 1.0
#date: 2016-12-26 03:53:05
#fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(user-agent) cs(referer) sc-status sc-substatus sc-win32-status time-taken
2016-12-26 03:53:05 ::1 /certsrv/mscep/mscep.dll operation=getcacert&message=scep%20authority 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 562
2016-12-26 03:53:08 ::1 /certsrv/mscep/mscep.dll operation=getcacaps&message=scep%20authority 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 0
2016-12-26 03:53:11 ::1 /certsrv/mscep/mscep.dll ... 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 173
2016-12-26 03:53:16 ::1 /certsrv/mscep/mscep.dll operation=getcacert&message=scep%20authority 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 0
2016-12-26 03:53:17 ::1 /certsrv/mscep/mscep.dll operation=getcacaps&message=scep%20authority 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 0
2016-12-26 03:53:19 ::1 /certsrv/mscep/mscep.dll ... 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 109
#software: microsoft internet information services 8.5
#version: 1.0
#date: 2016-12-26 04:14:07
#fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(user-agent) cs(referer) sc-status sc-substatus sc-win32-status time-taken
2016-12-26 04:14:07 ::1 /certsrv/mscep/mscep.dll operation=getcacaps&message=ca 443 - ::1 dalvik/2.1.0+(linux;+u;+android+6.0;+lenovo+a7020a48+build/mra58k) - 200 0 0 1533
2016-12-26 04:14:11 ::1 /certsrv/mscep/mscep.dll operation=getcacaps&message=ca 443 - ::1 dalvik/2.1.0+(linux;+u;+android+6.0;+lenovo+a7020a48+build/mra58k) - 200 0 0 15
2016-12-26 04:14:15 ::1 /certsrv/mscep/mscep.dll operation=getcacert&message=ca 443 - ::1 dalvik/2.1.0+(linux;+u;+android+6.0;+lenovo+a7020a48+build/mra58k) - 200 0 0 31
2016-12-26 04:14:20 ::1 /certsrv/mscep/mscep.dll operation=getcacaps&message=ca 443 - ::1 dalvik/2.1.0+(linux;+u;+android+6.0;+lenovo+a7020a48+build/mra58k) - 200 0 0 0
2016-12-26 04:14:25 ::1 /certsrv/mscep/mscep.dll operation=getcacert&message=ca 443 - ::1 dalvik/2.1.0+(linux;+u;+android+6.0;+lenovo+a7020a48+build/mra58k) - 200 0 0 0
2016-12-26 04:14:31 ::1 /certsrv/mscep/mscep.dll operation=getcacaps&message=ca 443 - ::1 dalvik/2.1.0+(linux;+u;+android+6.0;+lenovo+a7020a48+build/mra58k) - 200 0 0 0
2016-12-26 04:14:44 ::1 /certsrv/mscep/mscep.dll ... 443 - ::1 dalvik/2.1.0+(linux;+u;+android+6.0;+lenovo+a7020a48+build/mra58k) - 200 0 0 3219
2016-12-26 04:14:49 ::1 /certsrv/mscep/mscep.dll operation=getcacaps&message=ca 443 - ::1 dalvik/2.1.0+(linux;+u;+android+6.0;+lenovo+a7020a48+build/mra58k) - 200 0 0 0
2016-12-26 04:14:54 ::1 /certsrv/mscep/mscep.dll operation=getcacaps&message=ca 443 - ::1 dalvik/2.1.0+(linux;+u;+android+6.0;+lenovo+a7020a48+build/mra58k) - 200 0 0 0
2016-12-26 04:15:23 ::1 /certsrv/mscep/mscep.dll operation=getcacert&message=scep%20authority 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 0
2016-12-26 04:15:23 ::1 /certsrv/mscep/mscep.dll operation=getcacaps&message=scep%20authority 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 0
2016-12-26 04:15:25 ::1 /certsrv/mscep/mscep.dll ... 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 124
2016-12-26 04:15:35 ::1 /certsrv/mscep/mscep.dll operation=getcacert&message=scep%20authority 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 0
2016-12-26 04:15:35 ::1 /certsrv/mscep/mscep.dll operation=getcacaps&message=scep%20authority 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 0
2016-12-26 04:15:38 ::1 /certsrv/mscep/mscep.dll ... 443 - ::1 profiled/1.0+cfnetwork/808.2.16+darwin/16.3.0 - 200 0 0 124
2016-12-26 04:20:29 ::1 /certsrv/mscep/mscep operation=getcacert&message=mydeviceid 443 - ::1 mozilla/4.0+(compatible;+msie+7.0;+windows+nt+6.3;+wow64;+trident/7.0;+.net4.0e;+.net4.0c;+.net+clr+3.5.30729;+.net+clr+2.0.50727;+.net+clr+3.0.30729) - 404 0 2 2031

*********************************inetpub logs*********************************



hi,

1.if receive 404, open iis manager , navigate cmcertificateregistration below default website. change ssl settings "require ssl" , "require client certificates". restart sms_exec service.

2.by default, iis 7 installs "request filtering" enabled, , default maximum query string size (the length of request string, seems) set 2048 bytes, while pkioperation url closer 3000 bytes.  setting maxquerystring parameter ndes web site 4096.

and seems opened case microsoft,please understand, can provide general suggestions here.

and debugging beyond can in forum, support call our product service team needed debugging service. we'd recommend contact microsoft customer support service (css) assistance problem can resolved efficiently. obtain phone numbers specific technology request please take @ web site listed below:

https://support.microsoft.com/en-us/gp/customer-service-phone-numbers


best regards,
cartman
please remember mark replies answers if , unmark them if provide no help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client