Re: Auto Enrollment

From: Dave Robinson (drobinson_at_endtoend.com)
Date: 10/15/03


Date: 15 Oct 2003 06:19:06 -0700

I've installed the CA on a DC now and things are working fine. I'd
like to move it again to a member server though. You suggested
running gpupdate /force, but I han't even made GP changes yet, I'm
trying to but I'm not able...Any ideas?

"Laudon Williams [MSFT]" <laudonw@online.microsoft.com> wrote in message news:<OLdrBAnkDHA.372@TK2MSFTNGP11.phx.gbl>...
> Could be propagation delay. Try running gpupdate /force from the system you
> are using to set group policy.
>
> --
> This posting is provided "AS IS" with no warranties, and confers no rights.
>
>
> "Dave Robinson" <drobinson@endtoend.com> wrote in message
> news:de1cc84c.0310140816.73d3ed14@posting.google.com...
> > Hi All,
> >
> > I've got a strange problem happening with certificates. I'm trying to
> > get LDAP SSL working. I've installed certificate services on a member
> > server and configured it as an Enterprise Root. When I try to
> > configure the Group Policy setting for Automatic Certificate Request
> > Settings and I choose the Domain Controller template, I get the error:
> >
> > There is no Certification Authority available for the selected
> > Certificate Template
> >
> > I see the CA listed in Sites and Services and I also see the CA listed
> > in the Cert Publishers security group. The CA has Domain Controllers
> > listed under Policy Settings...
> >
> > Any ideas? What do I need to do to get this group policy setting to
> > recognize the CA?



Relevant Pages

  • Re: EFS Errors
    ... Disabling DFS can disrupt your Group Policy propagation which may be causing ... your EFS errors if you have changed your Recovery Agent Certificate. ... I am able to encrypt on the server but noone is able to encrypt ...
    (microsoft.public.security)
  • Re: EFS Errors
    ... > domain computers but there is a KB article that refers to the errors you are ... > your EFS errors if you have changed your Recovery Agent Certificate. ... > prevent Group Policy from working correctly. ...
    (microsoft.public.security)
  • Re: Cert Server - Changed Enterprise CA
    ... So as per the Instructions I added an IPSec Cert Template and added that to ... the Default Group Policy. ... 323342 How to install a certificate for use with IP Security in Windows ...
    (microsoft.public.win2000.active_directory)
  • Re: Encrypted Data Recovery Agents
    ... If you do remove it from Group Policy setting be sure NOT to delete ... Be sure you add the new RA certificate to the same GPO that shows ... I want to encrypt some files, but can't with an expired recovery agent ...
    (microsoft.public.security)
  • Re: Expired Recovery Agent EFS Cert
    ... Once you add the new certificate to the Group Policy where the EFS RA is ... gpupdate on the XP pro computers to speed up the propagation of Group Policy ... > the Recovery Agent at the domain level policy. ...
    (microsoft.public.win2000.security)

Loading