Re: CA Problems



In article <OkWX7bIRGHA.4452@xxxxxxxxxxxxxxxxxxxx>, in the
microsoft.public.win2000.security news group, JMS <jms_pt@xxxxxxx>
says...

Hello Brian

No autoenrollment allowed?

But the computers certificates are being issued!!!

The computer certificates are not being distributed via autoenrollment,
they are being distributed via Automatic Certificate Request Services
(ACRS) which is a different mechanism and is only available for machine
certificates that are based on version 1 certificate templates.

Can i make manual certificate requests for doamin controller?

Yes, but you shouldn't have to do this. You'll need to troubleshoot the
RPC error and resolve that.


Thanks.

"Brian Komar [MVP]" <bkomar@xxxxxxxxxxxxxxxxx> wrote in message
news:MPG.1e7b9b7ba39c5f9f989709@xxxxxxxxxxxxxxxxxxxxxxx
In article <uiw0LYHRGHA.5552@xxxxxxxxxxxxxxxxxxxx>, jms_pt@xxxxxxx
says...
I forgot to Say that both Domain Controller (Windows Server 2003 Stabdard
Edition) and Member Server my CA (Windows 2003 Standard Edition) both
have
SP1 installed.

Best regards


Glad (sad) you added this. Autoenrollment requires that the CA be
running Enterprise Edition. Autoenrollment is not supported on Standard
Edition CAs.

Brian




--
Paul Adare - MVP Virtual Machines
It all began with Adam. He was the first man to tell a joke--or a lie.
How lucky Adam was. He knew when he said a good thing, nobody had said
it before. Adam was not alone in the Garden of Eden, however, and does
not deserve all the credit; much is due to Eve, the first woman, and
Satan, the first consultant." - Mark Twain
.



Relevant Pages

  • Re: Certificate for VPN Client has expired (Computer Certificate)
    ... >> Autoenrollment is used. ... So when users are connected to LAN everything ... and then certificates are not updated. ... > renew/enroll computer certs as W2K only supports ACRS (computer ...
    (microsoft.public.windowsxp.network_web)
  • Re: Enabling a Certificate template
    ... computer certificates can be obtained via automatic request]. ... to the domain and they automatically obtain certificates via autoenrollment. ... >> automatically via Group Policy automatic request and users can request ...
    (microsoft.public.security)
  • Re: Certificate for VPN Client has expired (Computer Certificate)
    ... Autoenrollment is used. ... VPN, and then certificates are not updated. ... >> or the Vpn connection - too be able to renew the certificate? ...
    (microsoft.public.windowsxp.network_web)
  • Re: autoenrollment/autorenewal
    ... Autoenrollment is not tied to any particular VPN server. ... Policy setting that allows computers and users to automatically receive ... certificates defined in the Group Policy setting. ...
    (microsoft.public.windows.server.security)
  • Re: ADAM using SSL Problem
    ... Thanks Lee! ... host ADAM will not be DCs, so I simply moved ADAM to another development ... server, and set it up in the same exact fashion, and after installing the ... I then seen the certificate in the snap-in at: Certificates - Current ...
    (microsoft.public.windows.server.active_directory)