How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details. Proper certificates are needed to Authenticate and Encrypt the data flow between ConfigMgr clients and Management Point (even in Mixed mode).

Sometimes, we must play with certificates to resolve client authentication and registration issues. The following steps would help fix that kind of issue.

Iddex
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details
SMS certificate Store Details (MMC)
Export certificates
Import Certificates
Certificates Stored Folder Location in Windows Explorer or the File System
Certificates are stored in a folder location in Windows Explorer or the File System.
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Table 1

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details

This post covers the above index topics on checking and verifying ConfigMgr SCCM Mixed Mode Certificate Details Endpoint Manager.

SMS certificate Store Details (MMC)

Launch MMC (mmc.exe) and Click on File —> Add/Remove Snap-in

Patch My PC
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.1
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.1

Select Certificates from Available Snap-ins and click on the Add button

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.2
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.2

Select “Computer Account” and click NEXT

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.3
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.3

Select Local Computer and click on FINISH.

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.4
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.4

Click OK on the “Add or Remove Snap-ins” window.

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.5
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.5

Here are the TWO certificates, SMS Signing Certificate and SMS Encryption Certificate, used for Authentication and Encryption.

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.6
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.6

Export certificates

You need to right-click on the certificate All Tasks – Export….This will open up Certificate Export Wizard.

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.7
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.7

Select Yes, export the private key and click Next.

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.8
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.8

Select the Export File Format page, Personal Information Exchange – PKCS #12(.PFX), and click NEXT (You can select the INCLUDE and EXPORT checkboxes mentioned in the screenshot below)

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.9
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.9

Type in the password on the Password window and click NEXT

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.10
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.10

On the File to Export page, enter the file name you wish to store the exported certificate. Please do not give it an extension. Click NEXT

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.11
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.11

Click on FINISH

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.12
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.12

Import Certificates

Right-click on “Certificates (Local Computer)” –> “SMS” -> “Certificates” –> All Tasks –> Import.

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.13
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.13

On the “Welcome to the Certificate Import Wizard” page, click NEXT.

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.14
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.14

Browse through and provide the path of the certificate export file you are importing, and click “NEXT.”

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.15
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.15

Enter the password you used in the export process, and Mark this key as exportable. This will allow you to back up or transport your keys later”, and click “NEXT.”

imageHow to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.16
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.16

“Place all certificates in the following store” should already be selected, and the Certificate store value should already say “SMS.” Click NEXT

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.17
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.17

Click FINISH

How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.18
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.18

Certificates Stored Folder Location in Windows Explorer or the File System

  • Windows 2008 R2 servers – “C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys”
  • Windows 7 workstations – “C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys”
  • Note – Both SMS certificates are stored in the 19cf* Machine Key files.

Find the Location and Name of the Private Key file Associated with the Certificates.

  • FindPrivateKey.exe tool can be used to find out those details.
  • Syntax and examples of FindPrivateKey.exe in the following MSDN link.
  • Download FindPrivateKey.exe HERE
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details - Fig.19
How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details – Fig.19

We are on WhatsApp. To get the latest step-by-step guides and news updates, Join our Channel. Click here –HTMD WhatsApp.

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and leader of the Local User Group Community. His main focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

1 thought on “How to Check and Verify ConfigMgr SCCM Mixed Mode Certificate Details”

  1. Thx for your thread. There is no information on the internet conterning SCCM self-signed certificates implementation.

    But the most important question is… How to check the cert is used, data is encrypted. Which log file to check?

    If you have information regarding this…

    Thx in advance.

    Luc

    Reply

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.