System information
38
Deploying Parallels Mac Management for Microsoft SCCM 2012
To view the certificate store permissions
1 Run regedit.exe on the computer where the Configuration Manager Proxy is installed.
2 Navigate to HKLM\Software\Microsoft\SystemCertificates.
3 Right-click SystemCertificates and select Permissions from the pop-up menu.
4 In the Permissions for SystemCertificates dialog, verify that the user that you use to run the
Configuration Manager Proxy service has the Read permission selected.
To verify that the Configuration Manager Proxy service account has permissions to
read the certificate private key
1 Open the Microsoft Management Console (MMC) from the Start menu by clicking Run and
then typing "mmc".
2 In the File menu, select Add/Remove Snap-in...
3 In the Add or Remove Snap-ins dialog, find and select Certificates in the Available snap-ins
list. Click Add.
4 In the Certificate snap-in dialog, select Computer account and then select Local computer.
5 Click OK in the Add or Remove Snap-in dialog.
6 In the snap-in tree, navigate to Certificates (Local Computer)\Personal\Certificates and
expand it to view the available certificates.
7 Make sure that the Configuration Manager Proxy certificate exists. If it doesn't, run the
Configuration Manager Proxy configuration utility.
8 Right-click the Configuration Manager Proxy certificate, point to All Tasks, and then click
Manage Private Keys.
9 In the Permissions for Configuration Manager Proxy private keys dialog, verify that the user
(or a group to which the user belongs) has Read access to the certificate's private key.
Note: To view certificates on Windows versions prior to Windows Server 2008, use a resource kit utility
winhttpcertcfg.exe.
Migrating Configuration Manager Proxy
This section describes how to migrate the Configuration Manager Proxy to another server on the
same Configuration Manager site.
To migrate the Proxy to another server, you need to:
1 Export the Configuration Manager Proxy certificate from the Windows Certificate Store on the
current server.
2 Uninstall the Configuration Manager Proxy from the current server.
3 Import the certificate into the Windows Certificate Store on the new server.