I have two domains (X and Y) in one forest that are both at a functional 2003
level,
the forest is also 2003 functional. I cannot get the domain controller in
domain X to automatically retrieve it's certificate. The domain controller
in domain Y has recieved it certificates, but it is also the FSMO master of
the forest. The XP clients and 2003 server roles have all recieved their
certificates via auto-enrollment (GPOs) The Certificate Server is 2008 and
when I look in Server Manager at the issued certificates there is nothing in
the store, even though if I look individually at each server and bring up
certificates, each server has one. I am stumped on why I can go individually
to each server and see that they have a certificate issued, but not on the
CA. Also, when I look at the certificates, there is no root to any of them
like my CA server did not issue them. I would appreciate some help from
someone out there in answering a few of these issues. Thank you so much!
Can someone help me understand and fix:
number one: Why can't I see the issued certificates on the 2008 CA?
number two: how do I get the child domain controller to automatically
retrieve a certificate?
Thank you for your time on this!
Dawn
|