This commit is contained in:
Jan Backstrom 2016-11-09 17:02:12 -08:00
parent 3f75b829b3
commit fbb579c958

View File

@ -124,16 +124,16 @@ On line 67, replace the value of the **$password** variable, from 1234, to the p
>[!Note] >[!Note]
>The last two characters of the certificate thumbprint are required to enroll a device in SEMM. This script will display these digits to the user, which allows the user or technician to record these digits before the system reboots to enroll the device in SEMM. The script uses the following code, found on lines 144-149, to accomplish this: >The last two characters of the certificate thumbprint are required to enroll a device in SEMM. This script will display these digits to the user, which allows the user or technician to record these digits before the system reboots to enroll the device in SEMM. The script uses the following code, found on lines 144-149, to accomplish this:
``` ```
144 # Device owners will need the last two characters of the thumbprint to accept SEMM ownership. 144 # Device owners will need the last two characters of the thumbprint to accept SEMM ownership.
145 # For convenience we get the thumbprint here and present to the user. 145 # For convenience we get the thumbprint here and present to the user.
146 $pw = ConvertTo-SecureString $password -AsPlainText -Force 146 $pw = ConvertTo-SecureString $password -AsPlainText -Force
147 $certPrint = New-Object System.Security.Cryptography.X509Certificates.X509Certificate2 147 $certPrint = New-Object System.Security.Cryptography.X509Certificates.X509Certificate2
148 $certPrint.Import($privateOwnerKey, $pw, [System.Security.Cryptography.X509Certificates.X509KeyStorageFlags]::DefaultKeySet) 148 $certPrint.Import($privateOwnerKey, $pw, [System.Security.Cryptography.X509Certificates.X509KeyStorageFlags]::DefaultKeySet)
149 Write-Host "Thumbprint =" $certPrint.Thumbprint 149 Write-Host "Thumbprint =" $certPrint.Thumbprint
``` ```
>Administrators with access to the certificate file (.pfx) can read the thumbprint at any time by opening the .pfx file in CertMgr. To view the thumbprint with CertMgr, follow this process: Administrators with access to the certificate file (.pfx) can read the thumbprint at any time by opening the .pfx file in CertMgr. To view the thumbprint with CertMgr, follow this process:
1. Right-click the .pfx file, and then click **Open**. 1. Right-click the .pfx file, and then click **Open**.
2. Expand the folder in the navigation pane. 2. Expand the folder in the navigation pane.
@ -357,6 +357,7 @@ To add the SEMM Configuration Manager scripts to Configuration Manager as an app
* **General Information** Enter a name for the deployment type (for example SEMM Configuration Scripts), and then click **Next** to continue. * **General Information** Enter a name for the deployment type (for example SEMM Configuration Scripts), and then click **Next** to continue.
* **Content** Click **Browse** next to the **Content Location** field, and then click the folder where your SEMM Configuration Manager scripts are located. In the **Installation Program** field, type the [installation command](#deploy-semm-configuration-manager-scripts) found earlier in this article. In the **Uninstall Program** field, enter the [uninstallation command](#deploy-semm-configuration-manager-scripts) found earlier in this article (shown in Figure 2). Click **Next** to move to the next page. * **Content** Click **Browse** next to the **Content Location** field, and then click the folder where your SEMM Configuration Manager scripts are located. In the **Installation Program** field, type the [installation command](#deploy-semm-configuration-manager-scripts) found earlier in this article. In the **Uninstall Program** field, enter the [uninstallation command](#deploy-semm-configuration-manager-scripts) found earlier in this article (shown in Figure 2). Click **Next** to move to the next page.
![Set the SEMM Configuration Manager scripts as the install and uninstall commands](images/config-mgr-semm-fig2.png "Set the SEMM Configuration Manager scripts as the install and uninstall commands") ![Set the SEMM Configuration Manager scripts as the install and uninstall commands](images/config-mgr-semm-fig2.png "Set the SEMM Configuration Manager scripts as the install and uninstall commands")
*Figure 2. Set the SEMM Configuration Manager scripts as the install and uninstall commands* *Figure 2. Set the SEMM Configuration Manager scripts as the install and uninstall commands*
@ -374,6 +375,7 @@ To add the SEMM Configuration Manager scripts to Configuration Manager as an app
![Use a registry key to identify devices enrolled in SEMM](images/config-mgr-semm-fig3.png "Use a registry key to identify devices enrolled in SEMM") ![Use a registry key to identify devices enrolled in SEMM](images/config-mgr-semm-fig3.png "Use a registry key to identify devices enrolled in SEMM")
*Figure 3. Use a registry key to identify devices enrolled in SEMM* *Figure 3. Use a registry key to identify devices enrolled in SEMM*
* Click **Next** to proceed to the next page. * Click **Next** to proceed to the next page.