I'm just finding out that this is happening on both 'known/unknown' clients.. here is a partial from smsts.log
No hook is found to be executed before downloading policy TSMBootstrap 8/6/2013 1:17:35 PM 984 (0x03D8) Authenticator from the environment is empty. TSMBootstrap 8/6/2013 1:17:35 PM 984 (0x03D8) Need to create Authenticator Info using PFX TSMBootstrap 8/6/2013 1:17:35 PM 984 (0x03D8) Initialized CStringStream object with string: 538C46C1-D93B-43C5-B099-F346B5F2A5C4;2013-08-06T21:17:35Z. TSMBootstrap 8/6/2013 1:17:35 PM 984 (0x03D8) Using user-defined MP locations: http://MP1.DOMAIN.COM*http://MP2.DOMAIN.COM *http://MP3.DOMAIN.COM TSMBootstrap 8/6/2013 1:17:35 PM 984 (0x03D8) Set authenticator in transport TSMBootstrap 8/6/2013 1:17:35 PM 984 (0x03D8) Set media certificates in transport TSMBootstrap 8/6/2013 1:17:35 PM 984 (0x03D8) IP: 11.11.11.27 11.11.11.0 TSMBootstrap 8/6/2013 1:17:35 PM 984 (0x03D8) CLibSMSMessageWinHttpTransport::Send: URL: MP1.DOMAIN.COM:80 GET /SMS_MP/.sms_aut?MPLOCATION&ir=11.11.11.27&ip=11.11.11.0 TSMBootstrap 8/6/2013 1:17:35 PM 984 (0x03D8) Request was succesful. TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) Default CSP is Microsoft Enhanced RSA and AES Cryptographic Provider TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) Default CSP Type is 24 TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) New settings: TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) site=HQ1,HQ1, MP=http://MP4.DOMAIN.COM, ports: http=80,https=443 TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) certificates are received from MP. TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) Set authenticator in transport TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) Preparing Client Identity Request. TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) Setting transport. TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) Setting SourceID = 538C46C1-D93B-43C5-B099-F346B5F2A5C4. TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) Setting site code = HQ1. TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) Can not find DeploymentType in file TsmBootstrap.ini or the file doesn't exist. This is not running on Windows To Go. TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) Setting SMBIOS GUID = 744B7581-51F9-11CB-B857-F726F4075C49. TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) Adding MAC Address 3C:97:0E:29:F7:1B. TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) Executing Client Identity Request. TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) Requesting client identity TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) Setting message signatures. TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) Setting the authenticator. TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) CLibSMSMessageWinHttpTransport::Send: URL: MP4.DOMAIN.COM:80 CCM_POST /ccm_system/request TSMBootstrap 8/6/2013 1:17:36 PM 984 (0x03D8) Request was succesful. TSMBootstrap 8/6/2013 1:18:40 PM 984 (0x03D8) pNext != NULL, HRESULT=80004005 (e:\nts_sccm_release\sms\framework\osdmessaging\libsmsmessaging.cpp,1972) TSMBootstrap 8/6/2013 1:18:40 PM 984 (0x03D8) reply has no message header marker TSMBootstrap 8/6/2013 1:18:40 PM 984 (0x03D8) DoRequest (sReply, true), HRESULT=80004005 (e:\nts_sccm_release\sms\framework\osdmessaging\libsmsmessaging.cpp,5868) TSMBootstrap 8/6/2013 1:18:40 PM 984 (0x03D8) Failed to get client identity (80004005) TSMBootstrap 8/6/2013 1:18:40 PM 984 (0x03D8) oClientIdentity.RequestClientIdentity(), HRESULT=80004005 (e:\qfe\nts\sms\framework\tscore\tspolicy.cpp,668) TSMBootstrap 8/6/2013 1:18:40 PM 984 (0x03D8) Failed to read client identity (Code 0x80004005) TSMBootstrap 8/6/2013 1:18:40 PM 984 (0x03D8) On Thu, Aug 8, 2013 at 12:48 PM, CESAR.ABREG0 . <[email protected]> wrote: > This is happening during the initial boot when a client is trying to > determine adver. TSs. > On Aug 8, 2013 12:28 PM, "Jason Sandys" <[email protected]> wrote: > >> None of the above. MP use by clients is not in any way location aware.** >> ** >> >> ** ** >> >> When you say “they wanting to connect to the new one”, when is this? >> During the initial boot, during the TS, after the TS, some other time?*** >> * >> >> ** ** >> >> J**** >> >> ** ** >> >> *From:* [email protected] [mailto: >> [email protected]] *On Behalf Of *CESAR.ABREG0 . >> *Sent:* Thursday, August 8, 2013 1:05 PM >> *To:* [email protected]; [email protected] >> *Subject:* [mssms] OSD boot selecting the wrong MP on CM12 sp1 cu2.**** >> >> ** ** >> >> I have a situation when an unknown client boots to get imaged, it is >> trying to get policies from a newly created MP; however, this MP is not >> part of the preferred MPs on the boot media.**** >> >> ** ** >> >> This is the setup.**** >> >> - CAS (yes going over 100k soon)>Primary>MP1, MP2, MP3, MP4 (new on >> untrusted domain), 8 DPs. (no HTTPS) one cm site HQ1.**** >> >> - Boundaries: AD sites.**** >> >> ** ** >> >> the boot media was created to select any of the first 3 MPs but when the >> new MP was added they are wanting to connect to the new one to get >> policies. result, client fails since we are having some issues with this >> particular MP.**** >> >> ** ** >> >> Ultimately, we would like to prevent clients HQ from using the new MP, is >> that possible?. How can I prevent this? or where I would find the process >> of MP assignments for unknown clients?**** >> >> ** ** >> >> Can this be accomplished with boundary groups? or would this be a case of >> using AD site boundaries vs IP ranges.**** >> >> ** ** >> >> Any ideas or direction would help and be appreciated. **** >> >> ** ** >> >> Thanks,**** >> >> Cesar.**** >> >> ** ** >> >
