Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Re: Auto Enrolment failure after migration to server 2008

Reply
Thread Tools Display Modes

Re: Auto Enrolment failure after migration to server 2008

 
 
PA Bear [MS MVP]
Guest
Posts: n/a

 
      08-29-2009
[[Forwarded to & Followup-To set for
microsoft.public.windows.server.security newsgroup]]

PaulLG wrote:
> An old 2003 DC with Root CA was decomissioned and replaced with a new 2008
> server.
>
> The CA was backed up on the old server, and restored onto the new 2008 DC
> with the same name. The certificate database appears intact.
>
> We can request new user certificates via the web interface, but
> auto-enrolment fails. Nothing is shown in the Failed Requests list.
>
> User certificates can be requested via the MMC, but computer certificates
> fail with
> "The certificate requrest failed because of one of the following
> conditions:
> -The certificate requrest was submitted to a Certification Authority 9CA)
> that is not started.
> -You do not have the permissions ot request certificates from the
> available
> CAs."
>
> I have followed the troubleshooting guide
> http://blogs.technet.com/askds/archi...e-snap-in.aspx
> (as I haven't found a 2008 version) and everything seems OK except for the
> guide's reference to the group CERTSVC_DCOM_ACCESS, which does not exist
> in
> our AD. The certutil -setreg fix does not create the group, and our
> correctly-working lab network does not contain the group either.
>
> The Application log on the client shows:
> Event Type: Error
> Event Source: AutoEnrollment
> Event Category: None
> Event ID: 13
> Date: 24/08/2009
> Time: 14:04:42
> User: N/A
> Computer: FF8
> Description:
> Automatic certificate enrollment for local system failed to enroll for one
> Computer certificate (0x80070005). Access is denied.
>
> The System log on the client shows:
> Event Type: Error
> Event Source: DCOM
> Event Category: None
> Event ID: 10006
> Date: 24/08/2009
> Time: 14:04:42
> User: N/A
> Computer: FF8
> Description:
> DCOM got error "General access denied error " from the computer
> FF1.domain.local when attempting to activate the server:
> {D99E6E74-FC88-11D0-B498-00A0C90312F3}
>
> I have checked the DCOM permissions for "CertSrv Request" against our
> working lab server, and they are identical.
>
> Any idea what I'm missing?
>
> Paul


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Migration of ADD from SBS 2003 32 Bit to 2008 STD Server 64 Bit Venkatesh Windows Small Business Server 25 08-21-2009 07:33 PM
AD Migration from win 2000 to win 2008 server saqib ahmad Active Directory 5 08-03-2009 12:46 PM
Migration from Windows 2000 server to Windws Server 2008 Joe Windows Small Business Server 0 01-14-2009 08:22 PM
Migration To Server 2008(Sta. Adition) from server 2003 (Sta. adit saqib ahmad Active Directory 3 06-01-2008 09:52 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59