ProLiant Servers (ML,DL,SL)
1825045 Members
3037 Online
109678 Solutions
New Discussion

Re: Automatic Certificate enrollment using Microsoft NDES (SCEP) doesnt work

 
AlexPotter
Advisor

Automatic Certificate enrollment using Microsoft NDES (SCEP) doesnt work

Just wanted to let everyone know the automatic certificate enrollment using Microsoft NDES (SCEP) server doesn't work (despite documentation says it is supposed to). At least on the current 2.78 iLO. Don't spend time trying to get it working. Dissapointed with HP. Works perfectly with with Dell iDRAC.

14 REPLIES 14
techin
Valued Contributor

Re: Automatic Certificate enrollment using Microsoft NDES (SCEP) doesnt work

@AlexPotter ,

 

Did you check with HPE Support?

AlexPotter
Advisor

Re: Automatic Certificate enrollment using Microsoft NDES (SCEP) doesnt work

I did. The answer was "It works in our lab so suppose to work". No details or explanations how they managed to get it working. I have my environment configured as per MS standard and other devices are working fine. SO definitely problem with on HP side. 

Suman_1978
HPE Pro

Re: Automatic Certificate enrollment using Microsoft NDES (SCEP) doesnt work

Hi,

May we know the error message you get during certificate enrolment?

Automatic certificate enrollment

NOTE:  This feature is not supported when iLO is in CNSA security state.

Disabling the CNSA security state

Thank You!
I work with HPE but opinions expressed here are mine.
Recent Support Video Releases



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
AlexPotter
Advisor

Re: Automatic Certificate enrollment using Microsoft NDES (SCEP) doesnt work

Suman_1978
HPE Pro

Re: Automatic Certificate enrollment using Microsoft NDES (SCEP) doesnt work

Hi,

Please contact HPE Support and log a ticket to get this checked.

Thank You!
I work with HPE but opinions expressed here are mine.
Recent Support Video Releases



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
thutchings
HPE Pro

Re: Automatic Certificate enrollment using Microsoft NDES (SCEP) doesnt work

Is the certificate being supplied to the iLO using SCEP an intermediate cert? If so, then this is likely related to a known problem that is resolved in an upcoming iLO 5 firmware.



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
AlexPotter
Advisor

Re: Automatic Certificate enrollment using Microsoft NDES (SCEP) doesnt work

Finally some useful info. Yes, you absolutely right - it is Intermediate sert. And I had support case open with support - they were useless, telling me "it is suppose to work because it works in our lab".

Thank you for your comment.

drehstrom79
Advisor

Re: Automatic Certificate enrollment using Microsoft NDES (SCEP) doesnt work

We're just installing and configuring about 200 servers using HPE OneView. Of course I don't want to rollout every certificate manually. Is using an MS SCEP-Server with an intermediate certificate working with iLO 2.96 yet?

Regards
Stephan

Sunitha_Mod
Honored Contributor

Re: Automatic Certificate enrollment using Microsoft NDES (SCEP) doesnt work

Hello @drehstrom79,

Thank you for posting! We would recommend you to create a new topic using the create a "New Discussion" button, so the experts can check and assist you further. 

drehstrom79
Advisor

Re: Automatic Certificate enrollment using Microsoft NDES (SCEP) doesnt work

Hi,

I don't really see why I should create a new topic containing the exact same problem!?
Meanwhile I have my SCEP-Server working and can confirm that problems with iLO 2.96 are still the same. I also use an intermediate certificate and get the same error message as AlexPotter.

iLO-SCEP.JPG

I got about 200 servers to configure, so please HPE get going! Can't be that difficult if DELL got it working!?

jnc277
Regular Visitor

Re: Automatic Certificate enrollment using Microsoft NDES (SCEP) doesnt work

Hi,

I have the same problem. Switching to http the wireshark trace says "Bad request" when sending: http://x.x.x.x/certsrv/mscep/mscep.dll?operation=GetCACaps

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN""http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>Bad Request</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; charset=us-ascii"></HEAD>
<BODY><h2>Bad Request - Invalid Verb</h2>
<hr><p>HTTP Error 400. The request verb is invalid.</p>
</BODY></HTML>

 

drehstrom79
Advisor

Re: Automatic Certificate enrollment using Microsoft NDES (SCEP) doesnt work

Hi,

I can confirm this. My wireshark-trace shows the exact same error.
Pretty disappointing that there is obviously no rush to fix this error by HPE. All in all I'm very displeased with HPE OneView. There are so many bugs and missing features. All my 200 servers are claiming security risks that are pre-configured ex factory as for instance
- Login for RBSU
- SNMPv1 enabled
- Password Complexity disabled
but none of them can be adjusted with the OneView template. If there is no real improvement over the next years we'll be forced to move to DELL...

jnc277
Regular Visitor

Re: Automatic Certificate enrollment using Microsoft NDES (SCEP) doesnt work


Thanks for confirming.

Move to DELL - we will consider that as well.

 

AlexPotter
Advisor

Re: Automatic Certificate enrollment using Microsoft NDES (SCEP) doesnt work

+1 with the same conclusion. Has already started migration.