{"id":2689,"date":"2018-03-31T20:32:56","date_gmt":"2018-03-31T18:32:56","guid":{"rendered":"http:\/\/blog.hosebei.ch\/?p=2689"},"modified":"2018-03-31T20:32:56","modified_gmt":"2018-03-31T18:32:56","slug":"intune-ndes-enrollment","status":"publish","type":"post","link":"https:\/\/blog.hosebei.ch\/?p=2689","title":{"rendered":"Intune &#8211; NDES Enrollment"},"content":{"rendered":"<p>I recently changed my Intune Subscription from SCCM Hybrid to Intune Standalone. Within this change, I face an issue with the NDES, respectively the SCEP, enrollment for the certificates.<br \/>\nAfter I have configured the SCEP profile within Intune, my Windows 10 Clients show th following error Message within the eventlog:<\/p>\n<p><code>A security error occurred 0x80072f8f (WinHttp: 12175 ERROR_WINHTTP_SECURE_FAILURE)<\/code><br \/>\n<!--more--><\/p>\n<p>This error was thrown because I had misconfigured the HTTPS Certificate of the NDES web site. The webserver Certificate I used was from my PKI, and the client also trusted the PKI, but with an old public key of the PKI. So the Webserver Certificate was created based on a newer PKI Root CA certifiacte, and was therefore not trusted.<\/p>\n<p>After I published the newer Root CA certificate to the client, this error message was gone, but only to show a new one:<br \/>\n<code>The hash value is not correct. 0x80091007 (-2146889721 CRYPT_E_HASH_VALUE)<\/code><br \/>\nThis error was now based on the SCEP Profile assigned to the clients. I had Uploaded the new Root CA to the Intune Console, within the same profile existed already. But the client still was getting the old thunmbprint of the Root CA certificate. I was led to this conclusion through the following MS article:<br \/>\n<a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4045957\/you-can-t-issue-scep-certificates-to-devices-in-intune-after-a-certifi\" rel=\"noopener\" target=\"_blank\">You can&#8217;t issue SCEP certificates to devices in Intune after a certificate renewal<\/a><\/p>\n<p>So I assumed, that the SCEP Profile does not update the Hash from the Certificate trust profile, when updated. I deleted the SCEP profile, and created a new one, and voil\u00e0, afterwards the Hash mismatch error was gone.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I recently changed my Intune Subscription from SCCM Hybrid to Intune Standalone. Within this change, I face an issue with the NDES, respectively the SCEP, enrollment for the certificates. After I have configured the SCEP profile within Intune, my Windows 10 Clients show th following error Message within the eventlog: A security error occurred 0x80072f8f [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15],"tags":[],"class_list":["post-2689","post","type-post","status-publish","format-standard","hentry","category-configmgr"],"_links":{"self":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/2689","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2689"}],"version-history":[{"count":0,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/2689\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2689"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2689"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2689"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}