Re: enabling LDAP over SSL: Enterprise CA in separate AD tree



In article <1155938181.499119.108510@xxxxxxxxxxxxxxxxxxxxxxxxxxx>,
mtw@xxxxxxx says...
I've enabled Read and Enroll for Computer, Domain Controller, and
Domain Controller Authentication for the domain B domain controllers
group, plus Autoenroll for D.C. Authentication. When I submit an
Automatic Certificate Request and run gpupdate, I now don't get a
success message in the event log.

LDAP over SSL still works, however I fear that if I reboot the DC in
domain B it will stop working.

Run certutil -dcinfo for each domain. This will report back to you
- What DCs have certs
- What certs each DC has
- Whether the certs are valid
Brian
.



Relevant Pages

  • Re: Cached credentials on work laptop
    ... Interactive logon: Number of previous logons to cache (in case domain ... Require Domain controller authentication to unlock ...
    (microsoft.public.windows.server.active_directory)
  • RE: Certificate Problem - Smart Card Logon
    ... Is your Domain Controller being issued the Domain Controller Authentication ... Authentication template which is a version 2 template for 2003 Domain ... and "Update certificates that use the certificate templates". ...
    (microsoft.public.win2000.security)
  • Re: ca eventlog errors
    ... While the error messages may not be causing showstopper issues, ... When the error message states "...when processing requires Active Directory ... Check the CA cert and one of the issued certs to see if any of them have ... >> Since you installed it on a domain controller it would have made more ...
    (microsoft.public.windows.server.security)