Cert for PXE-enabled SCCM distribution point?

Benninghouse, John D - DOT 90 Reputation points
2025-05-29T14:45:17.9+00:00

I am trying to setup a distribution point to use the built-in PXE capabilities and not use WDS. Our SCCM environment is HTTPS.

I have it setup but, when I attempt to PXE boot a device, it gets "no valid offer received". The SMSPXE.log shows a lot of 0x80070490 errors such as:

PXE::MP::GetMPListAndConnectionInfo failed; 0x80070490

PXE::MP::IsKnownMachine failed; 0x80070490

The smsdpusage.log shows error 80072ee5 such as:

Cannot connect with winhttp; 80072ee5

Failed to get information for MP: . 80072ee5.

I suspect this is a certificate issue for HTTPS communication. Does this scenario need a client authentication cert as described here under "Site systems that have a distribution point installed"?

https://free.blessedness.top/en-us/intune/configmgr/core/plan-design/network/pki-certificate-requirements

And would it be installed under the DP properties on the Communication tab replacing the self-signed cert there? Should the subject name be the FQDN of the DP?

Skip

Microsoft Security | Intune | Configuration Manager | Application
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Pavel yannara Mirochnitchenko 13,406 Reputation points MVP
    2025-06-02T11:24:40.3366667+00:00

    I try to remember, that PXE does not need its own certificate, and DP's cert is enough to launch PXE. I did setup last SCCM infra about 5-6 years ago, but even then the PXE cert was not needed. Back very old old days there was certificate inserted into boot image, but that should not be needed anymore.

    So, first make sure that can you download any content from that DP using Software Centrer, does the traffic works at all?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.