Enterprise Root Certification Authority not trusted



Yesterday installed Enterprise Root and Enterprise Subordinate CA on
Windows 2003 standard in Windows 2000 active directory domain. It
appears that the enterprise root certificate has not been published in
active directory as my client machines are getting SSL warning "the
certificate cannot be verified up to a trusted certification
authority". When I view the certification path, the root certificate
has a red X and the status is "This CA Root certificate is not trusted
because it is not in the Trusted Root Certification Authorities store."
Also, the "send request immediately to an online certification
authority" is grayed out in IIS.

Background info/steps taken:
-Domain controllers running Windows 2000 SP4.
-Previous CA infrastructure consisted of stand alone root and stand
alone subordinate running windows 2000.
-Backed up the system state on domain controllers
-Backed up existing windows 2000 CAs
-uninstalled certificate service on existing windows 2000 CAs
-replicated AD links
-Manually cleaned up AD per this KB article:
http://support.microsoft.com/default.aspx?scid=kb;en-us;555151
-replicated AD links
-Updated AD schema to windows 2003 using adprep.exe /forestprep
-replicated AD links
-installed enterprise root CA on server 1
-installed enterprise subordinate CA on server 2
-no errors encountered during installation.


This warning was logged in the application log on both the enterprise
root CA and the enterprise subordinate CA.

Event ID: 103
Source: CertSvc
Description: Certificate Services temporarily added the root
certificate of certificate chain 0 to the downloaded Enterprise Root
store. If this problem persists, publishing the root certificate to
the Active Directory may be necessary.

This warning was logged twice (once for each DC) in the application log
on enterprise root CA.

Event ID: 103
Source: CertSvc
Description: Certificate Services could not publish a Certificate for
request 2 to the following location on server dc1.channeladvisor.com:
CN=DC1,OU=Domain Controllers,DC=mydomain,DC=com. Insufficient access
rights to perform the operation. 0x80072098 (WIN32: 8344).
ldap: 0x32: 00002098: SecErr: DSID-03150646, problem 4003
(INSUFF_ACCESS_RIGHTS), data 0
-----

No other errors or warnings on the DCs or CAs.

The DCs did successfully receive a domain controller certificate from
the root CA and I have been able to issue some web server certs
manually on the subordinate CA. Any suggestions appreciated. TIA.

Jim

.



Relevant Pages

  • Re: How to re-issue root CA certificate
    ... the sample scripts link is on the link I provided in the ... Renew the CA certificate. ... See Publishing the Offline Root CA. ... During installation for our Windows 2003 Server's certificate authority, ...
    (microsoft.public.windows.server.security)
  • Re: Renew Certificate Automatically
    ... We have a Windows 2000 root CA which would be expiring in next few ... section "Reviewing and Renewing the Root CA Certificate". ... Not with a Windows 2000 CA. Autoenrollment is only available when you ... Remaining validity period of the CA's certificate ...
    (microsoft.public.windows.server.security)
  • Re: Convert Enterprise Root CA to Standalone Root CA and create newSubordinate CAs
    ... client computer auto enrolled and received a certificate from a root CA ... compared to other computers who were issued via the subordinate CA ... do enterprise root CA issue certificates to ...
    (microsoft.public.security)
  • Non domain member, IPSec VPN Certificate
    ... We have an Enterprise Root CA installed, running on Windows 2003 ... How do I get a valid IPSec VPN cert onto his computer? ... I need to duplicate the certificate (if my ...
    (microsoft.public.isa.vpn)
  • Re: Windows Server 2008 CA
    ... First thing I do notice is that you should be using a Standalone Root CA rather than an enterprise root CA. ... You cannot take an enterprise root CA offline and there really is no sense for a subordinate enterprise CA with an enterprise root CA. ... I have installed Windows Server 2008 Enterprise Root CA and Subordinate CA. ... Windows XP is not capable for web enrollment. ...
    (microsoft.public.security)