Re: Installing Enterprise Root CA
- From: pzbowen@xxxxxxxxx
- Date: 6 Mar 2007 12:17:41 -0800
On Mar 6, 1:55 pm, Brian Komar [MVP] <bko...@xxxxxxxxxxxxxxxxx> wrote:
pzbo...@xxxxxxxxx says...
I have Windows Server 2003 R2 Standard Edition installed. It is the
only machine in the domain currently (this is a test environment). I
have installed AD, DNS, DHCP, and IIS sucessfully. Now I want to
install an Enterprise Root CA.
I cannot seem to get this working. Everytime I try to install
Certificate Services from the Add/Remove Windows Components wizard,
the two enterprise CA options are disbled. I have tried this logged
in as both "Administrator" as well as another account that is in the
Enterprise Admins and Domain Admins groups. The built-in
Administrators group has both Domain Admins and Enterprise Admins as
members.
Is there any reason that an Enterprise root CA should not be able to
be installed on a PDC or on 2003 R2 Standard Edition?
To install an enterprise CA, you must be a member of the
enterprise admins group, and you must make sure that
your account is a member of the local Administrators
group at the CA.
It is really not recommended to install a CA on a DC,
but It sounds like something is not translating. Try
adding the exact account to the local Administrators
group
That was exactly the problem. Appears that nested groups do not work
right.
Thanks.
Peter
.
- Follow-Ups:
- Re: Installing Enterprise Root CA
- From: Brian Komar [MVP]
- Re: Installing Enterprise Root CA
- References:
- Installing Enterprise Root CA
- From: pzbowen
- Re: Installing Enterprise Root CA
- From: Brian Komar [MVP]
- Installing Enterprise Root CA
- Prev by Date: Re: Where is Local Group Assignment Stored?
- Next by Date: Re: Where is Local Group Assignment Stored?
- Previous by thread: Re: Installing Enterprise Root CA
- Next by thread: Re: Installing Enterprise Root CA
- Index(es):
Relevant Pages
|