裝置管理的憑證撤銷監視

Microsoft.SystemCenter2012.ConfigurationManager.EnrollmentPoint.CertificateRevokeMonitor (UnitMonitor)

此監視會檢查站台伺服器是否能夠順利撤銷裝置管理憑證。

Knowledge Base article:

摘要

這項「撤銷憑證失敗偵測規則」偵測到註冊點無法撤銷憑證的失敗情況。

原因

註冊點無法撤銷最近刪除或抹除之行動裝置的憑證。

註冊點無法撤銷未佈建之 AMT 用戶端的憑證。

解決方式

確定核發憑證的憑證授權單位 (CA) 正在執行,且註冊點電腦可連線到該 CA。

確認註冊點電腦擁有該特定憑證授權單位的管理權限。

Element properties:

TargetMicrosoft.SystemCenter2012.ConfigurationManager.EnrollmentPoint
Parent MonitorMicrosoft.SystemCenter2012.ConfigurationManager.RoleAggregateMonitor
CategoryCustom
EnabledTrue
Alert GenerateTrue
Alert SeverityMatchMonitorHealth
Alert PriorityNormal
Alert Auto ResolveTrue
Monitor TypeMicrosoft.SystemCenter2012.ConfigurationManager.StatusMessage2StateMonitor
RemotableTrue
AccessibilityPublic
Alert Message
無法撤銷裝置管理憑證
註冊點無法撤銷憑證。
RunAsDefault
CommentSIV:DM0001

Source Code:

<UnitMonitor ID="Microsoft.SystemCenter2012.ConfigurationManager.EnrollmentPoint.CertificateRevokeMonitor" Comment="SIV:DM0001" Accessibility="Public" Enabled="onEssentialMonitoring" Target="SCCM!Microsoft.SystemCenter2012.ConfigurationManager.EnrollmentPoint" ParentMonitorID="Microsoft.SystemCenter2012.ConfigurationManager.RoleAggregateMonitor" Remotable="true" Priority="Normal" TypeID="Microsoft.SystemCenter2012.ConfigurationManager.StatusMessage2StateMonitor" ConfirmDelivery="true">
<Category>Custom</Category>
<AlertSettings AlertMessage="Microsoft.SystemCenter2012.ConfigurationManager.EnrollmentPoint.CertificateRevokeMonitor_AlertMessageResourceID">
<AlertOnState>Error</AlertOnState>
<AutoResolve>true</AutoResolve>
<AlertPriority>Normal</AlertPriority>
<AlertSeverity>MatchMonitorHealth</AlertSeverity>
</AlertSettings>
<OperationalStates>
<OperationalState ID="UIGeneratedOpStateId91592d2972354917b61d24a265067537" MonitorTypeStateID="Good" HealthState="Success"/>
<OperationalState ID="UIGeneratedOpStateId6b9a5aabcc7d4bafa8325841e3386218" MonitorTypeStateID="Error" HealthState="Error"/>
</OperationalStates>
<Configuration>
<ComputerName>$Target/Host/Property[Type="Windows!Microsoft.Windows.Computer"]/PrincipalName$</ComputerName>
<ComponentName>SMS_ENROLL_SERVER</ComponentName>
<RuleId>61D52663-EA15-45A2-A63F-6870433E4CBE</RuleId>
<IntervalSeconds>360</IntervalSeconds>
</Configuration>
</UnitMonitor>