cancel
Showing results for 
Search instead for 
Did you mean: 
apaloka
Level 1
12 10 0 0
Message 1 of 9
479
Flag Post
HP Recommended

ThinPro OS - SCEP Client

T530

Hello all, I continually receive the below error when trying to request a certificate through SCEP manager on the thin client.

 

HP DM is version 4.7 SP10

HP T530 is OS version T7x70015

 

2019-05-15 11:19:47 ErrorCode: 30720, Error Info: ../../Task/common/TaskScep.cpp@89: The ThinPro SCEP component probably only supports 1024 key length. ../../Task/common/TaskScep.cpp@88: Wed May 15 11:19:24 EDT 2019 SCEP enroll result: SCEP Client configuration error

 

Communication goes through fine, NDES supports 2048. SCEP Component should support higher than 1024, so not sure why this error shows. 

8 REPLIES 8
apaloka
Level 1
12 10 0 0
Message 2 of 9
391
Flag Post
HP Recommended

ThinPro OS - SCEP Client

Updating for visibility...

Reply
0 Kudos
Level 4 DM-AJ
Level 4
49 48 4 16
Message 3 of 9
356
Flag Post
HP Recommended

ThinPro OS - SCEP Client

You might need to update ThinPro image or the SCEP component on it to get the support for key length above 1024.

I am an HPI Employee.
My opinions are my own and do not express those of HPI.
**Click the Thumbs Up Button below to say Thanks**
Reply
0 Kudos
Level 4 DM-AJ
Level 4
49 48 4 16
Message 4 of 9
355
Flag Post
HP Recommended

ThinPro OS - SCEP Client

And this error info can mean something else.  Please verify the parameters including the URL and challenge code on a sample thin client before sending a task.

I am an HPI Employee.
My opinions are my own and do not express those of HPI.
**Click the Thumbs Up Button below to say Thanks**
Reply
0 Kudos
apaloka
Level 1
12 10 0 0
Message 5 of 9
320
Flag Post
HP Recommended

ThinPro OS - SCEP Client

All of my thin clients are sample thin clients at this point, SCEP is not working with:

 

ThinPro OS T7X710015, T7X710018

SCEP 1024, 2048

HPDM 4.7 SP9, SP10 or 5.0

Reply
0 Kudos
Level 4 DM-AJ
Level 4
49 48 4 16
Message 6 of 9
308
Flag Post
HP Recommended

ThinPro OS - SCEP Client

Please take one thin client and try locally with the SCEP component to verify the configuration works before sending via an HPDM task.

I am an HPI Employee.
My opinions are my own and do not express those of HPI.
**Click the Thumbs Up Button below to say Thanks**
Reply
0 Kudos
apaloka
Level 1
12 10 0 0
Message 7 of 9
285
Flag Post
HP Recommended

ThinPro OS - SCEP Client

Sorry for not clarifying, I've done that as well. I usually try both

Reply
0 Kudos
Level 4 DM-AJ
Level 4
49 48 4 16
Message 8 of 9
254
Flag Post
HP Recommended

ThinPro OS - SCEP Client

1. Please confirm what status do you see on a thin client when trying to enroll.  You can find it at the bottom of the dialog of SCEP Manager as shown in the attached picture with the red box.  I guess it can be the same as what you see in the task log: 

SCEP Client configuration error

2. With NDES there is more than one URL during preparation.  Please refer to the whitepaper WP_SCEP-Tutorial_HPDM-4.7.pdf and make sure the URL is the one to enroll.  It can be like http://NDES-address/certsrv/mscep/

I am an HPI Employee.
My opinions are my own and do not express those of HPI.
**Click the Thumbs Up Button below to say Thanks**
Reply
0 Kudos
apaloka
Level 1
12 10 0 0
Message 9 of 9
141
Flag Post
HP Recommended

ThinPro OS - SCEP Client

Thanks for the help here...

I was able to push scep cert to the device. What if I want to use a machine cert here? Is there additional steps I need for this to authenticate? 

The 802.1x appears as if it's trying to work with a client cert

Reply
0 Kudos
† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the Terms of Use and Rules of Participation