November 2020 Update for Asset Intelligence authentication certificate in Configuration Manager

Introduction

This article describes an update for the Asset Intelligence (AI) authentication certificate in Microsoft System Center System Center 2012 Configuration Manager Service Pack 2, System Center 2012 R2 Configuration Manager Service Pack 1, and the current branch of Microsoft Endpoint Configuration Manager versions 2006 and earlier. Before you install this update, check out the "Installation instructions" section.

Note Microsoft Endpoint Configuration Manager current branch version 2010 and later versions are pre-provisioned with this version of the Asset Intelligence (AI) authentication certificate, so you do not have to apply this update to those versions.

Symptoms

In Configuration Manager, the issuing certificate that System Center Online uses to validate the Asset Intelligence public authentication (bootstrap) certificate (expiration date January 7, 2021) was updated November 11, 2020. The previous issuing certificate will remain valid for a short period to allow for a smooth transition. When the old issuing certificate is removed, System Center Online will no longer recognize the pre-provisioned public authentication certificate that is used by the Asset Intelligence synchronization point site system role to enroll with the service.

  • Scenario 1: You try to install a new Asset Intelligence synchronization point, and it is making its first connection attempt to the System Center Online service.

  • Scenario 2: Your existing Asset Intelligence synchronization point tries to use the public authentication certificate to renew the specific per-installation certificate.

In either of these scenarios, System Center Online rejects the public authentication certificate, and you receive the following error message in the Asset Intelligence pane of the Configuration Manager Console:

Expired credentials/certificate/token. Need to re-provision online account.

Additionally, the following error message is logged in the Aiupdatesvc.log file:

Asset Intelligence Catalog Sync Service Warning: 0 :Log_Date:WebException trying to enroll: Status = ProtocolError
Asset Intelligence Catalog Sync Service Error: 0 :Log_Date:Exception attempting sync - The request failed with HTTP status 403: Forbidden.

 

File name

File version

File size

Date

Time

Platform

CMCSBootstrapCert.pfx

Not Applicable

2668

29-Oct-2020

09:31

Not Applicable

license_ENU.rtf

Not Applicable

43725

29-Jun-2015

15:19

Not Applicable

 

Need more help?

Expand your skills
Explore Training
Get new features first
Join Microsoft Insiders

Was this information helpful?

Thank you for your feedback!

Thank you for your feedback! It sounds like it might be helpful to connect you to one of our Office support agents.

×