CA Server and CA Web Enrollment on two different Machines

From: David Moore (anonymous_at_discussions.microsoft.com)
Date: 01/11/04


Date: Sun, 11 Jan 2004 12:11:22 -0800

I'm trying to get Certificate Services running on our
network. I have a network that has four servers, and
around 30 XP clients. I would like to install the CA
services on one machine, and the Web Enrollment on a
different machine. The rest that I would like to do this
is that the Servers that are being used for this project
are not the most powerful machine on this plant, and I
don't really think that they could handle the enrollment
and the CA function on the same machine. I have decided to
go with the stand-alone structure; due to the fact that a
lot of Certificates will be issued out side of the
company. I have installed the Certificate Services on the
machine with the most power of the two, which happens to
be our domain controller running Active Directory. This
domain controller's only job before this project was
solely doing authentication within the Active Directory,
and DNS. The installation went very well on this server
with no problems at all.
I then moved to the installing the Web Enrollment services
on the other machine. This machine is our current Web
Server that is running IIS. I followed the documentation
in this process, which seemed to install exactly has the
documentation was written. After the install, I go to the
web pages to see if it works; it appears that most things
do but I have not actually tried to request a certificate.
The thing that I'm running into is that the "Download a CA
certificate, certificate chain, or CRL" link, does not
work. When I click on this I get "An unexpected error has
occurred: The Certification Authority Service has not been
started".

Things I have tried:
1. Rebooting both servers.
2. Confirming the delegation in Active Directory for the
Web Server. Which from my understanding, it is not
actually required in a Stand-Alone solution.
3. Installing IIS on the CA Server to see if the same
problem occurs there, which it does not. Works fine on the
CA Server directly.
4. Confirmed that the Web Server was ASP enabled, which I
knew it was due to the fact that we run a lot of ASP on
the server everyday.
5. Made sure that the certsrv virtual directory had
execution enabled for scripts. It does.
6. Checked the event logs for errors, but there was no
errors.

I have missed something somewhere, but I have read the
documentation from Microsoft on doing this over and over.
I have searched the web for this problem in no tell how
different many ways. I know that other people are having
this problem because in searching the web for the file
certcarc.asp, which the file the web browser is trying to
open when the error occurs, I find several different
servers that appear to have the same error message.
Someone out there has had to have had this error and
actually fixed it. Any help on getting this to work would
be highly appreciated.

David



Relevant Pages

  • Re: New Event Log Errors!
    ... Somehow along those lines I'd also installed the Certificate Authority ... Did you apply the last Server Pack for SBS Server? ... Please install Windows Support Tools on the win2k3 sp1 problematic ... Microsoft is providing this information only as a convenience to you: ...
    (microsoft.public.windows.server.sbs)
  • Re: Adding EXCH2007 SP1 box to existing EXCH2003 SP2 Org
    ... Certificates - going to be using a SAN Certificate like I have many times before. ... We are making this a virtual server (someone is going on-site on Thursday to install VMWare (which will kill everything on this box) and WIN2008 Server SP1 x64 and then I will install EXCH2007 SP1. ... as mentioned - ISA was not involved in any of those eight environments.... ...
    (microsoft.public.exchange.admin)
  • Re: follow-up: need advice for installing VPN on Windows Server 2003
    ... I get this error message: ... Active Directory Federation Services ... X In order to install any ADFS component, ... The specified server cannot perform the requested operation.. ...
    (microsoft.public.windows.server.networking)
  • Re: removing Windows 2008 DC after demotion, time for ntdsutil
    ... Run diagnostics against your Active Directory domain. ... If you don't have the support tools installed, ... Windows 2003 DC had to do a reboot; ... REcently demoted a Windows 2008 x64 Enterprise DC to a member server. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Connection to a SAMBA Active Directory
    ... There is no such thing as a SAMBA active directory. ... workstations, servers, mac's, and nix boxes to the AD and then install ... Install Windows 2003 Server. ...
    (microsoft.public.exchange.connectivity)