Automatic certificate enrollment for local system failed after upgrading member server to domain controller

From: Arch Willingham (nospam_arch_at_tuparks.com)
Date: 08/26/05

  • Next message: news_at_mail.adsl4less.com: "Re: Does the SCW break Windows Firewall?"
    Date: Thu, 25 Aug 2005 18:11:40 -0400
    
    

    I am getting errors after upgrading a member sever running Windows 2003 to a
    domain controller (via DCPROMO). Every five minutes, I get this error:

    Event Type: Error
    Event Source: AutoEnrollment
    Event Category: None
    Event ID: 13
    Date: 08/25/2005
    Time: 5:56:59 PM
    User: N/A
    Computer: DOG
    Description:
    Automatic certificate enrollment for local system failed to enroll for one
    Domain Controller certificate (0x80070005). Access is denied.

    Any ideas?

    Arch


  • Next message: news_at_mail.adsl4less.com: "Re: Does the SCW break Windows Firewall?"

    Relevant Pages

    • Auto Enrollment Event ID: 13 Failed to enroll ... Certificate Access Denied
      ... I get these error messages on a windows 2003 server domain controller ... Is it something I should be worry about I didn't find any ... Automatic certificate enrollment for local system failed to enroll for ... see Help and Support Center at ...
      (microsoft.public.win2000.security)
    • Automatic certificate enrollment for local system failed
      ... Event Source: AutoEnrollment ... Computer: DC01 ... Automatic certificate enrollment for local system failed to enroll for one ... Domain Controller certificate. ...
      (microsoft.public.windows.server.general)
    • Re: Autoenrollment error
      ... Automatic certificate enrollment for local system successfully received one Domain Controller certificate from certificate authority xx-AD_CA on xxxxx.ad.xxxxx.edu. ... I read in a couple places to try "certutil -setreg SetupStatus ...
      (microsoft.public.windows.server.active_directory)
    • AutoEnrollment error in event log
      ... I cannot connect to the domain controller: ... In the event log: ... Automatic certificate enrollment for local system failed to contact ... the active directory. ...
      (microsoft.public.windowsxp.general)
    • Re: FSMO - can I turn on a DC after its PDCe role has been seized?
      ... According to the article I guess it would have been "Safe" to turn on the ... previously failed Domain controller even though its PDCe FSMO role had been ... the article states the server would have figured ... then run dcpromo. ...
      (microsoft.public.windows.server.active_directory)