Logo
programming4us
programming4us
programming4us
programming4us
Home
programming4us
XP
programming4us
Windows Vista
programming4us
Windows 7
programming4us
Windows Azure
programming4us
Windows Server
programming4us
Windows Phone
 
Windows Server

System Center Configuration Manager 2007 : Operating System Deployment - Native Mode

- Free product key for windows 10
- Free Product Key for Microsoft office 365
- Malwarebytes Premium 3.7.1 Serial Keys (LifeTime) 2019
3/25/2013 6:33:45 PM

1. Native Mode

OSD in a native mode ConfigMgr environment requires one additional certificate. Systems use this certificate when they are booted using PXE or physical media. It allows these systems to authenticate and securely communicate with the ConfigMgr site systems. You can share a single certificate for all OSD deployments; this certificate is used only during the deployment process and not actually installed on the target system.

The requirements for this certificate are as follows:

  • The Enhanced Key Usage value must contain Client Authentication (1.3.6.1.5.5.7.3.2).

  • The Subject Name or Subject Alternative Name field must be unique.

  • The certificate must be stored in a Public Key Certificate Standard (PKCS #12) format file, which must also contain the private key.

  • The maximum key length is 2,048 bits.

When you create a PXE service point or task sequence media, ConfigMgr prompts you to create a self-signed certificate or import a certificate. For a native mode site, you must choose to import a certificate and supply the password protecting the certificate file.

You can view imported certificates under the Site Management -> <Site Code> -> <Site Name> -> Site Settings -> Certificates in the Boot Media and PXE nodes. Only two options are available from the context menu of imported certificates: Block and Unblock.

In addition to the new certificate, you must also specify the Root Certificate Authority (CA) certificate to ConfigMgr. You do this on the Site Mode tab of the Site Properties configuration dialog by pressing the Specify Root CA Certificates button, as shown in Figure 1.

Figure 1. Specifying Root CA Certificates

Certificate Revocation Lists

By default, ConfigMgr enables Certificate Revocation List (CRL) checking. Depending on your PKI implementation, you can publish the CRL to multiple, various locations including Active Directory and a website. OSD targets booted using PXE or media cannot access CRLs published to Active Directory. Thus if your CRLs are published only to Active Directory, OSD cannot access them and will fail.

In addition, if the first CRL distribution point listed in your certificates is Active Directory, you might experience a delay during the Windows PE startup process. This happens because Windows PE tries to access each CRL distribution point in the order listed in the certificate.

Although it is possible to change your CRL distribution points, certificates already issued will not reflect this change; you have to revoke the existing certificates and issue new ones. Disabling CRL checking in ConfigMgr is another option but is discouraged.

The recommended solution is to carefully plan your PKI infrastructure and ensure that your CRLs are accessible to all systems that need them.

2. Upgrading from SMS 2003

Although Microsoft supports both in-place upgrades and side-by-by-side migrations from SMS 2003 to Config 2007, you cannot directly transfer any work done in the OSD Feature Pack of SMS 2003. In fact, you must uninstall the OSD Feature Pack from SMS 2003 before you perform an upgrade. Here are some of the limitations:

  • The upgrade process creates a new node named OSD FP Packages under the Operating System Deployment node in the ConfigMgr console, with all existing operating system feature pack packages placed under this new node. The node appears until you delete the existing operating system packages.

  • You cannot create new advertisements in this node or distribute down-level feature pack operating system images to distribution points.

  • Down-level image packages are not available as a choice when choosing an Operating System Image package in the Apply Operating System Image task, although existing advertisements and package deployments for down-level images are upgraded intact and still usable after the upgrade.

  • Images created using the OSD Feature Pack are not compatible with OSD in ConfigMgr, and you cannot directly import them. 

For the long-term, you should definitely consider revamping your imaging process and use a full-fledged Build and Capture task sequence to create your image.

Other -----------------
- System Center Configuration Manager 2007 : Operating System Deployment - Post Deployment Tasks, Troubleshooting
- System Center Configuration Manager 2007 : Operating System Deployment - Drivers
- System Center Configuration Manager 2007 : Operating System Deployment - Tips and Techniques
- Understanding Network Services and Active Directory Domain Controller Placement for Exchange Server 2007 : Global Catalog and Domain Controller Placement
- Understanding Network Services and Active Directory Domain Controller Placement for Exchange Server 2007 : Configuring DNS to Support Exchange Servers, Troubleshooting DNS Problems
- Understanding Network Services and Active Directory Domain Controller Placement for Exchange Server 2007 : Understanding DNS Requirements for Exchange Server 2007
- Understanding Network Services and Active Directory Domain Controller Placement for Exchange Server 2007 : Examining DNS Components
- Nginx HTTP Server : Basic Nginx Configuration - Base module directives
- Nginx HTTP Server : Basic Nginx Configuration - Configuration file syntax
- SharePoint 2010 : Configuring Search Settings and the User Interface - Web Parts (part 4)
 
 
Top 10
- Microsoft Visio 2013 : Adding Structure to Your Diagrams - Finding containers and lists in Visio (part 2) - Wireframes,Legends
- Microsoft Visio 2013 : Adding Structure to Your Diagrams - Finding containers and lists in Visio (part 1) - Swimlanes
- Microsoft Visio 2013 : Adding Structure to Your Diagrams - Formatting and sizing lists
- Microsoft Visio 2013 : Adding Structure to Your Diagrams - Adding shapes to lists
- Microsoft Visio 2013 : Adding Structure to Your Diagrams - Sizing containers
- Microsoft Access 2010 : Control Properties and Why to Use Them (part 3) - The Other Properties of a Control
- Microsoft Access 2010 : Control Properties and Why to Use Them (part 2) - The Data Properties of a Control
- Microsoft Access 2010 : Control Properties and Why to Use Them (part 1) - The Format Properties of a Control
- Microsoft Access 2010 : Form Properties and Why Should You Use Them - Working with the Properties Window
- Microsoft Visio 2013 : Using the Organization Chart Wizard with new data
 
programming4us
Windows Vista
programming4us
Windows 7
programming4us
Windows Azure
programming4us
Windows Server