Re: Strange; setting up CA for DC IPsec- how did the DCs autoenroll?



A couple of things.
The Domain Controller certificate is a version 1 certificate template, and will deploy automatically using Automatic Certificate Request Settings. DCs are hard coded to request this certificate (if available).
- You are a bit mistaken on the functionality of the standard edition SKU and enterprise CAs. You will be unable to deploy *any* certificates based on version 2 certificate templates. So there would be no auto-requests as you describe waiting for approval.
Brian

"Thomas H" <ThomasH@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:BC848406-4C5F-46C6-BB83-CF58683E091C@xxxxxxxxxxxxxxxx
So I'm in "virtual land" because I want to enable IPSec communication between
our intersite DCs. My sandbox is all Windows 2003 server R2 SE SP2, and has
4 DCs, 2 sites, and a member server. I built an enterprise root CA on the
member server. I had to manually add the Domain Controllers group to the
member server's local CERTSVC_DCOM_ACCESS group. I rebooted all the DCs, and
went off to read some documentation on how to set up IPSec.

I came back to the CA that I built (again, on 2k3 SE R2 SP2), and just
started poking around. Somehow, in the "Issued Certificates" node, two of my
DCs had certificates!

I went to one of the DCs, and loaded the Certificates snap-in for the local
computer (the DC), and sure enough, there was a Domain Controller certificate
in the Personal\Certificates node. I went to the Application event log on the
DC, and saw an Information message from the AutoEnrollment source, saying
"Automatic certificate enrollment for local system successfully received one
Domain Controller certificate from certificate authority mytestca1 on
mytestca1.mytest.local."

However, I didn't set up any automatic requests in group policy yet!
Everything is still at its defaults (not even SCW has been run yet in my test
domain). Plus, since the root CA I set up was Standard Edition and not
Enterprise Edition, I didn't think anything could auto-enroll (just
auto-request, and I'd have to manually approve it).

Anyone seen this before? Are DCs magically allowed to auto-enroll by default?

Thanks!


.



Relevant Pages

  • Re: several annoying error message in all the domain controllers
    ... This looks like a problem with the auto enrollment of the DCs with your ... > Our Windows 2003 Native domain controllers are getting several ANNOYING ... Automatic certificate enrollment for local system failed to ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD PKI question
    ... my problem is not to generate the new CRL... ... certificate is revoked between 2 downloads. ... This certificate was issued by Microsoft Certificate ... So I assume that the DCs will not download the new CRL file more than ...
    (microsoft.public.windows.server.networking)
  • Event-ID:20 KDC certificate was once valid, but now is invalid
    ... bekomme auf meinen beiden 2003 DCs immer wieder folgende ... "The currently selected KDC certificate was once valid, ... The DCs should then ... so dass die DCs auch kein neues Zertifikat bekommen können. ...
    (microsoft.public.de.german.windows.server.active_directory)
  • Re: LDAP over Secure Sockets Layer (SSL) will be unavailable at this t
    ... Unfortunately I'm not a WinCA guy at all (we use external certs for our DCs) and I'm not an RODC guy either so I don't know any of the particulars regarding how this is supposed to work. ... "the permissions on the certificate template do not allow for this type of ... Running at server 2003 operational level. ...
    (microsoft.public.windows.server.active_directory)
  • Event-ID:20 KDC certificate was once valid, but now is invalid
    ... bekomme auf meinen beiden 2003 DCs immer wieder folgende ... "The currently selected KDC certificate was once valid, ... The DCs should then ... so dass die DCs auch kein neues Zertifikat bekommen können. ...
    (microsoft.public.de.german.windows.server.active_directory)