Re: Publish Certificates in AD - parent\child domain



I don't know for sure if this will help but make sure you read the whole KB
as there is a different procedure under Windows 2000 domains and Windows
Server 2003 domains that have been upgraded from Windows 2000 in which case
the Cert Publishers group is a domain global group instead of domain local
group. --- Steve


"Barna8us" <notachance_2@xxxxxxxxxxx> wrote in message
news:1144188816.517684.93890@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I am trying to work through this MS article on how to allow child
domain users to get certificates and have them published in AD from a
parent domain: http://support.microsoft.com/?kbid=281271

But am stuck on line 5a: "Click Next, click Add, and then add the Cert
Publishers group from the parent domain."

The Cert Publishers group is a built-in security group of the parent
domain. I cannot add it from the child domain - cannot be found in the
delegation wizard from the child domain. I thought this was the way
it was supposed to be anyway - that built-in groups from a parent
domain were not available to assign permissions to in the child domain.
But, that is the way this article explains how to do it....

Any insight is appreciated.

Thanks!

B



.



Relevant Pages

  • Re: Checlist For Domain & Forest Raise
    ... WE have removd all windows nt PDC +BDC & Exchannge 5.5 from ad, ... scenario is we have Parent & child domain enviroment. ... now we have planning to RAISE Domain & Forest level to Windows 2003, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Child domain
    ... will there be any issues if the parent domain is a windows 2000 domain ... >> i need to created a child domain for my company. ... i have delegated control to the child domain under dns ... > Microsoft Windows MVP - Windows Server - Directory Services ...
    (microsoft.public.win2000.dns)
  • New domain question
    ... we have a parent, child domain here ... Should I upgrade to Windows 2003 now? ...
    (microsoft.public.win2000.active_directory)
  • Can’t ping parent domain name?
    ... We have a Windows 2000 AD domain cityname-tn.org located at city hall. ... We have a Windows 2000 AD Child domain electric.cityname-tn.org ... located at the electric department. ... except the child domain can?t find domain controllers for the parent ...
    (microsoft.public.win2000.dns)
  • RE: NT4 Migration path
    ... the best migration path for this kind of setup? ... ADMT to migrate the original two Windows NT to the two child domain ... Is it possible to move all my users and nt/2000 server and nt/xp ...
    (microsoft.public.windows.server.migration)