Access is denied 0x8007005 error when adding Certiciate Authority

From: Steve309 (anonymous_at_discussions.microsoft.com)
Date: 03/21/04


Date: Sat, 20 Mar 2004 15:11:05 -0800

Hello,

I installed a root enterprise CA (I'll call it "bigdog") and then wanted to install a subordinate enterprise CA in the same domain (I'll call the domain "barks.org"). When I do, I get this error:

"Cannot ping selected CA. Make sure the CA is running
Access is denied. 0x80070005 (Win32: 5)"

Also, I'm logged in as an Enterprise admin when installing the CA. I opened the CA installation log (WINNT\certocm.log) and found this error:

CA Certificate Request: 0x0(0)
Select CA: bigdog.barks.org: BARKS root CA
Get Server CA Name: bigdog.barks.org: Access is denied. 0x80070005 (WIN32: 5)

It seems like its some sort of permissions error when my soon-to-be subordinate CA (member server) attempts to access some active directory information about the enterprise CA (domain controller).

I attempted the fix in KB 281271 (single-level domain scenario) to no avail. I also tried giving the everyone group enroll permissions on the enterprise CA, and trusting the member server for delecation in ADUC.

Also, I can ping my enterprise CA from the member server.

BTW, the member server is running in a VMware virtual machine (bridged NIC).

Any ideas?



Relevant Pages

  • RE: Enterprise Admins have no permissions in Tree Root.
    ... the test is really trying to use an enterprise user across 2 ... server on one domain to a workstation on another domain. ... Domain A includes DC and 1 member server ...
    (microsoft.public.windows.server.general)
  • Re: Access is denied 0x8007005 error when adding Certiciate Authority
    ... The reason was that all Enterprise CAs must be ... and the subordinate CA that I was trying to create was ... Upgrading it to a domain controller fixed the issue. ... subordinate CA (member server) attempts to access some active directory ...
    (microsoft.public.win2000.security)
  • Re: Error Message on Installation of Enterprise ISA Server
    ... Make sure the internal DNS registrations are correct for this machine. ... Do you maintain a reverse-lookup zone in your internal DNS? ... Have already run the ISA Enterprise installation AND all Service Packs are up to date on the 2003 Member Server. ...
    (microsoft.public.isa.enterprise)
  • Move domain controller E2k server to member server
    ... I would like to move exchange from DC ... to a member server on a newer hardware and don't know what all to do, ... migration but nothing on how to move e2k dc to a member server. ... Enterprise E2k a DC ...
    (microsoft.public.exchange2000.admin)
  • Re: Welcome screen appears but with no account
    ... "crushcard" wrote ... nothing else to do, I installed the latest verison of Enterprise, updated it, ... Why was it you were just installing and> running ... Select Safe Mode and press enter. ...
    (microsoft.public.windowsxp.general)