Microsoft · Microsoft Configuration Manager

Configuration Manager PXE certificate error 0x80092002

Investigate Configuration Manager PXE certificate encoding error 0x80092002 and the IssuingCertificateList registry value.

Short answer

Microsoft documents a Configuration Manager PXE failure where the IssuingCertificateList registry value is missing under HKLM\SOFTWARE\Microsoft\SMS\Security. The relevant SMSPXE.log certificate-encoding error includes 0x80092002. Confirm that exact signature and compare the affected distribution point with its management point before applying the documented registry repair.

Symptoms and exact log signature

The log can include a certificate-list encoding failure such as:

Failed to encode certificate list. error 0x80092002

This can appear among other PXE messages. An unrelated 0x80070002 message about performance counters is not, by itself, the certificate issue described here.

Environment

Microsoft Configuration Manager PXE-enabled distribution point. The affected registry path is:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SMS\Security

The value discussed by Microsoft is IssuingCertificateList. Do not publish or copy certificate material from an unrelated site or environment.

Evidence to collect

  1. Save the relevant SMSPXE.log lines with timestamps and redact identifiers.
  2. Check whether IssuingCertificateList exists on the affected distribution point and management point.
  3. Compare the value on the management point associated with the same Configuration Manager site.
  4. Record the site and server roles involved, without exposing real identifiers in public notes.
  5. Take a supported system-state/registry backup and follow change control before editing a production server.

Root cause

In the documented scenario, the required IssuingCertificateList value is missing. Configuration Manager cannot encode the issuing-certificate list while processing PXE requests.

Microsoft-documented repair

If the value exists on the correct management point, export that value and import it to the affected distribution point, following Microsoft’s procedure. The documented command pattern is:

REG EXPORT "HKLM\SOFTWARE\Microsoft\SMS\Security" C:\SMS\Security.reg

Use the export/import process only after checking the exact value and ensuring the source is the management point for the same site. Review the exported file before importing; do not blindly replace the entire security key if unrelated values differ.

If the value is also missing from the management point, Microsoft documents retrieving the value from the site database and adding it to the management point and distribution point. That database operation is site-specific and should be performed only by an administrator who understands the supported procedure in the linked article. Do not run improvised SQL updates.

Verification

After the approved change, restart or refresh the relevant Configuration Manager components only as directed by the vendor procedure. Re-run a controlled PXE test and confirm SMSPXE.log no longer shows the certificate-encoding failure and the client proceeds through boot image selection.

Version notes

This procedure is tied to the Microsoft troubleshooting article and Configuration Manager role configuration. Confirm the current supported steps before use; certificate and site data must match the same environment.

Sources

Evidence status

This is an original guide based on linked Microsoft documentation. It is not a report of a field investigation or a tested repair on a customer site.

Related cases