Last month (July) I did another large ConfigMgr deployment. Last time I did an implementation with remote Site servers placed in almost all continents. This time I did a migration on a ConfigMgr 2007 Primary site and eight (8) Secondary site servers. It was needed also to install a Public Key Infrastructure (PKI) and Distribution & Management points on HTTPS because of MAC OS X management. Furthermore I installed Shavlik Patch for third-party updates.
Within ConfigMgr 2007 it was normal to install Secondary site servers because of bandwidth management. In ConfigMgr 2012 this isn't needed anymore, because this functionality is available on remote Distribution points too. Therefore I installed a new ConfigMgr 2012 Primary site server and eight (8) remote Distribution points. For MAC OS X management I installed another Site server with multiple roles needed for HTTPS communication.
Special tasks provided during implementation:
-Application Catalog (doesn't work out-of-the-box always)
-Asset Intelligence - Software (empty by default, but useful when configured)
-Compliance Settings - Configuration Items and Baselines (Windows and Mac systems)
-Mac OS X management (PKI, certificates and roles for HTTPS communication)
-Shavlik Patch (download and publish third-party updates)
Special collections created for overview:
-Departments (all departments)
-Locations (all locations)
-Operating Systems (all operating systems)
-System Type (all system types)
Queries on Computer name, Model and System Type are used.
With all queries available and nested collections, you can create anything you want! :-)
Special tasks provided during OS deployment:
-BIOS Configuration Utility (HP)
-Define Active Directory OU Location
-Set BIOS Password when not available (HP)
-Use applications instead of packages
-Configure BitLocker for notebooks
Very cool to manage Mac OS X systems and deploy applications to them! Furthermore Rate Limits on Remote Site servers are great to configure bandwidth usage. Again: You can do so much in ConfigMgr, that almost everything is possible :-)
Showing posts with label Shavlik. Show all posts
Showing posts with label Shavlik. Show all posts
Thursday, September 3, 2015
My findings after a ConfigMgr migration with Site servers through Europe
Friday, July 10, 2015
Failed to download updates to the WUAgent datastore. Error = 0x800b0109
With Shavlik Patch it's possible to download and publish third-party updates within the ConfigMgr console. Other products with comparable functionality are Secunia and Lumension. During a Shavlik Patch implementation, third-party updates on Adobe Reader and Mozilla Firefox didn't want to install. Updates were published without issue but they fail to install on the client. The following error was shown in WUAHandler.log: Failed to download updates to the WUAgent datastore. Error = 0x800b0109
Trick is, you must publish Self signed certificates in the local computer Trusted Publishers and Trusted Root Certification Authorities store and you will need to enable 'Allow signed updates from an intranet Microsoft update service location' as well.
Import the WSUS self signed certificate to the client computer's Trusted Publishers and Trusted Root Certification Authorities and to change this setting in GPO.
Create a GPO which will import this certificate and enable 'Allow signed updates from an intranet Microsoft update service location'.
After creating the GPO and make the necessary changes, both Adobe Reader and Mozilla Firefox updates were installed successfully.
Just great to use ConfigMgr for both Microsoft and third-party updates, within the same console! As you can see Adobe Reader (11.0.11) and Mozilla Firefox (38.0.5) are installed successfully now.
Trick is, you must publish Self signed certificates in the local computer Trusted Publishers and Trusted Root Certification Authorities store and you will need to enable 'Allow signed updates from an intranet Microsoft update service location' as well.
Import the WSUS self signed certificate to the client computer's Trusted Publishers and Trusted Root Certification Authorities and to change this setting in GPO.
Create a GPO which will import this certificate and enable 'Allow signed updates from an intranet Microsoft update service location'.
After creating the GPO and make the necessary changes, both Adobe Reader and Mozilla Firefox updates were installed successfully.
Just great to use ConfigMgr for both Microsoft and third-party updates, within the same console! As you can see Adobe Reader (11.0.11) and Mozilla Firefox (38.0.5) are installed successfully now.
Subscribe to:
Posts (Atom)

