RE: SMS Advanced Client 10803/10815 Error

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Joe Hoggood (jhoggood_at_jhoggood.com)
Date: 12/24/04

  • Next message: Andy: "Help: SMS and Kerberos "KRB_AP_ERR_MODIFIED" error?"
    Date: Thu, 23 Dec 2004 16:49:04 -0800
    
    

    Here's a related error message in the SMS 2003 Client
    C:\windows\system32\ccm\logs\CertificateMaintenance.log:

    <![LOG[Creating Signing Certificate...]LOG]!><time="17:32:17.981+300"
    date="12-23-2004" component="CertificateMaintenance" context="" type="1"
    thread="2024" file="ccmgencert.cpp:590">
    <![LOG[CryptGenKey failed: 0x80070057]LOG]!><time="17:32:18.080+300"
    date="12-23-2004" component="CertificateMaintenance" context="" type="3"
    thread="2024" file="ccmgencert.cpp:617">
    <![LOG[Failed to create certificate 80070057]LOG]!><time="17:32:18.080+300"
    date="12-23-2004" component="CertificateMaintenance" context="" type="3"
    thread="2024" file="ccmgencert.cpp:700">
    <![LOG[CCMDoCertificateMaintenance failed
    (0x80070057).]LOG]!><time="17:32:18.080+300" date="12-23-2004"
    component="CertificateMaintenance" context="" type="3" thread="2024"
    file="ccmgencert.cpp:1794">
    <![LOG[Failed to find the certificate in the store, retry
    1.]LOG]!><time="18:25:07.594+300" date="12-23-2004"
    component="CertificateMaintenance" context="" type="2" thread="3500"
    file="ccmgencert.cpp:980">
    <![LOG[Failed to find the certificate in the store, retry
    2.]LOG]!><time="18:25:07.704+300" date="12-23-2004"
    component="CertificateMaintenance" context="" type="2" thread="3500"
    file="ccmgencert.cpp:980">
    <![LOG[Failed to find the certificate in the store, retry
    3.]LOG]!><time="18:25:07.813+300" date="12-23-2004"
    component="CertificateMaintenance" context="" type="2" thread="3500"
    file="ccmgencert.cpp:980">
    <![LOG[Failed to find the certificate in the store, retry
    4.]LOG]!><time="18:25:07.922+300" date="12-23-2004"
    component="CertificateMaintenance" context="" type="2" thread="3500"
    file="ccmgencert.cpp:980">
    <![LOG[Failed to find the certificate in the store, retry
    5.]LOG]!><time="18:25:08.031+300" date="12-23-2004"
    component="CertificateMaintenance" context="" type="2" thread="3500"
    file="ccmgencert.cpp:980">
    <![LOG[Creating Signing Certificate...]LOG]!><time="18:25:08.141+300"
    date="12-23-2004" component="CertificateMaintenance" context="" type="1"
    thread="3500" file="ccmgencert.cpp:590">
    <![LOG[CryptGenKey failed: 0x80070057]LOG]!><time="18:25:08.234+300"
    date="12-23-2004" component="CertificateMaintenance" context="" type="3"
    thread="3500" file="ccmgencert.cpp:617">
    <![LOG[Failed to create certificate 80070057]LOG]!><time="18:25:08.234+300"
    date="12-23-2004" component="CertificateMaintenance" context="" type="3"
    thread="3500" file="ccmgencert.cpp:700">
    <![LOG[CCMDoCertificateMaintenance failed
    (0x80070057).]LOG]!><time="18:25:08.234+300" date="12-23-2004"
    component="CertificateMaintenance" context="" type="3" thread="3500"
    file="ccmgencert.cpp:1794">

    "Joe Hoggood" wrote:

    > I have verified too the client side security on C:\Documents and Settings\All
    > Users\Application
    > Data\Microsoft\Crypto\RSA\MachineKeys. SYSTEM has full rights on this client
    > side folder tree.
    >
    > "Joe Hoggood" wrote:
    >
    > > Here's another message in C:\ssm\logs\ddm.log:
    > >
    > > CDiscoverySource::VerifyClientPublicKeys - Public key does not exist for
    > > client GUID:E6C8B4B9-CD4C-4BB5-AD22-10FDA5862B0B.
    > >
    > >
    > > "Joe Hoggood" wrote:
    > >
    > > > The visible symptom is there are no advertisements on the client side when
    > > > using "Run Advertised Programs".
    > > >
    > > > "Joe Hoggood" wrote:
    > > >
    > > > > I've also tried deleting the %windir%\system32\catroot2 folder thinking it
    > > > > might be a certificate problem to no avail.
    > > > >
    > > > > "Joe Hoggood" wrote:
    > > > >
    > > > > > One one of my SMS 2003 Advanced Clients I am receiving the following errors
    > > > > > from the "Advanced Client" component. All my other Windows XP SP1 or SP2
    > > > > > Advanced clients work fine. I have tried ccmclean/all on this XP client to no
    > > > > > avail. I've also tried uninstalling/reinstalling BITS V1.5/2.0.
    > > > > >
    > > > > > Message ID: 10803
    > > > > > The client failed to download policy. The data transfer service returned
    > > > > > "Error downloading data." (-2147024809).
    > > > > >
    > > > > > Message ID: 10815
    > > > > > The SMS Service Host (CCMEXEC) encountered a failure (0x80070057) when
    > > > > > performing Certificate operations.
    > > > > > Possible cause: The ACLs on the Certificate store are incorrect.
    > > > > > Solution: Verify that the ACLs on the Certificate store are correct. If not,
    > > > > > fix the ACLs appropriately.
    > > > > > Possible cause: Encryption is not supported on this version of the Operating
    > > > > > System.
    > > > > > Solution: Refer to the SMS Documentation on supported Operating Systems.
    > > > > > Possible cause: The Certificate Store is corrupted.
    > > > > > Solution: Refer to the Windows Documentation on troubleshooting this.
    > > > > >
    > > > > >
    > > > > > --
    > > > > > Joe Hoggood


  • Next message: Andy: "Help: SMS and Kerberos "KRB_AP_ERR_MODIFIED" error?"

    Relevant Pages

    • Re: HttpWebRequest failure with TLS
      ... My guess is that you are going to want it in the machine store as the ... account your web service client is running under will eventually change to ... private key associated with it in the cert properties dialog. ... certificate should go in the personal store. ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: SMS 2003 SP1 Client Install Problem or Policy Retreival Problem?
      ... It is possible that the crypto store has somehow been corrupted. ... These clients> show as assigned to the site in the admin console, ... > Failed to find the certificate in the store, retry 1. ...
      (microsoft.public.sms.admin)
    • Re: cannot view indexed property
      ... I'm going to assume that your client is actually a service running under ... have a personal certificate store. ... It is located in the current user personla store ...
      (microsoft.public.dotnet.framework.webservices.enhancements)
    • Advanced Client: Unable to enable installed components
      ... machine serveral times, but it doesn't help. ... Failed to find the certificate in the store, retry ...
      (microsoft.public.sms.misc)
    • Re: Advanced Client: Unable to enable installed components
      ... Are you sure this client communicates with his mp? ... > Creating Signing Certificate... ... > Failed to find the certificate in the store, retry ...
      (microsoft.public.sms.misc)