Re: Problems requesting computer certificates on an issuing CA



The exact permissions on my template are:

"Authenticated Users" - read
"CA Admins" - read and write
"Domain Admins" - read and write
"Enterprise Admins" - read and write
"Service computers (the computer group)" - read, enroll and autoenroll

By the way, I tried to manually enroll for a computer certificate based on
the default template, but I get the same error as I did with the customized
computer certificate template.

Regards,
Anette

"Paul Adare" <padare@xxxxxxxxxxx> wrote in message
news:MPG.1e89c5b0a397a48d98a07e@xxxxxxxxxxxxxxxxxxxxxxx
In article <uFpiwfOTGHA.4452@xxxxxxxxxxxxxxxxxxxx>, in the
microsoft.public.windows.server.security news group, Anette Andresen
<anette_andresen@xxxxxxxxxxx> says...

I have a windows server 2003 domain with an enterprise issuing CA. The CA
is
set up to allow autoenrollment of computer certificates to a number of
computers in our domain. The computers are given the read, enroll and
autoenroll rights on the computer certificate template. The computer
certificate template is enabled on the issuing CA, and the security on
the
CA allows the computers to request certificates. All the other computers
except the CA itself have been able to automatically (or manually)
request
certificates, and the CA has signed the requests. However, the CA
computer
itself tries to request a computer certificate using autoenrollment every
eight hour, but the CA denies the request with the following Request
Status
Code message: "The permissions on this certification authority do not
allow
the current user to enroll for certificates" and the following Request
Disposition Message: "Denied by Policy Module". When trying to manully
enroll for a computer certificate using certificate manager mmc, I am
able
to open the certificate request wizard and complete the steps there, but
after finishing the wizard I receive the message: "The certification
authority denied the request. The permissions on this certification
authority do not allow the current user to enroll for certificates."

Do anyone know how to solve this problem? Is there some setting I have
forgotten? Or isn't it possible to issue a computer certificate to an
enterprise CA?

Since you've enabled the Autoenroll permission on the template you're
obviously not using the default Computer certificate template as that is
a V1 template and only V2 templates support autoenrollment.
What _exactly_ are the permissions on the V2 template?

--
Paul Adare - MVP Virtual Machines
It all began with Adam. He was the first man to tell a joke--or a lie.
How lucky Adam was. He knew when he said a good thing, nobody had said
it before. Adam was not alone in the Garden of Eden, however, and does
not deserve all the credit; much is due to Eve, the first woman, and
Satan, the first consultant." - Mark Twain


.



Relevant Pages

  • Re: How to renew a certificate programmicaly
    ... Name 2 extension must contain a UPN entry, ... Please notice that the application> policy restriction is "Enrollment Agent" and that the "old certificate" does> not have this application policy. ... > I cannot see this template in the MMC snapin, I guess it is because it has> "X number of authotized signatures" and "Subject details supply in request". ...
    (microsoft.public.platformsdk.security)
  • Re: Certificates for l2tp VPN
    ... "IPSec offline request" template, the certificate is in the Local ... canīt install the correct certificate to make it work. ...
    (microsoft.public.win2000.security)
  • Re: Computer and User Certificates Issues
    ... You created a custom V2 template but is this CA running Windows Server ... > Can you request any certificate at all via the mmc snapin for either user ... > users have the allow permission for request certificates. ... I have also tried manually enrolling for a computer certificate ...
    (microsoft.public.security)
  • Re: Certification Authority cannot use certificate template
    ... certificate request wizard in IIS Manager. ... Also, at the CA, ensure that the Web server certificate template is ...
    (microsoft.public.security)
  • Re: Create a computer certificate for non-connected machine?
    ... Are you saying I should request on my inside-the-network PC and export ... Would that mean if I already have a computer certificate on the ... inside of the network it would be identical when imported on the ...
    (microsoft.public.security)