Devices in SCCM Console staying self-signed while its showing PKI on the client side

Patrick Baldonado 6 Reputation points
2021-09-30T11:22:53.447+00:00

Hi all, We initially setup our SCCM environemnt using HTTP but now decided to flip to PKI to support CMG. We only have 1 MP which is on the Primary site as well. I have switched over MP, DP and SUP to use HTTPS, also binded MP 443 port to the IIS cert I have generated. I have also switched site Communication tab to use PKI. Finally, I have pushed client auth cert through GPO and can see clients are getting certs on Personal Store. I can even see the clients switching over to PKI under SCCM client General Tab. Also verified client registered using PKI in ClientIDManagerStartup.log. My problem is when I go check Devices in SCCM Console, under client certificate, they still show as self-signed rather than PKI. Thoughts please...

Microsoft Configuration Manager
{count} vote

14 answers

Sort by: Most helpful
  1. Mes Ka 0 Reputation points
    2023-06-05T18:08:09.7166667+00:00

    Hello Jason, I have the issue still. Do you have any idea about when it will be fixed?


  2. Mes Ka 0 Reputation points
    2023-06-05T18:12:53.1566667+00:00

    Or is there a version that I need to get to solve this issue?


  3. Anonymous
    2024-01-29T18:14:25.1066667+00:00

    On 2309 and still experiencing "self-signed" vs "PKI" with some machines. Verified client shows "PKI". Submitted frown report a few minutes ago. So still an issue.


  4. NASSIR, Oday 0 Reputation points
    2025-05-13T06:03:57.93+00:00

    2503 finally resolved this issue. was noticed on 2309

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.