Click here to get back home

2003 Domain Controller not requesting certificate

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
2003 Domain Controller not requesting certificate jdc4357 05-31-2006
Posted by jdc4357 on May 31, 2006, 2:53 pm
Please log in for more thread options
Hi,
I can't seem to get my win2003 dc to request a certificate. Heres what I've
done so far in a test environment.

Installed 2003 Enterprise SP1 and called it adstest-ca in the workgroup
"workgroup". Installed certificate services as a standalone root ca. (IIS
is not installed) Deleted the CRL and AIA distribution points (execpt local)
as best practices recommends for an offline root ca. (Why don't we want a crl
for a root ca? What if my subordiante ca get compromised, how am I going to
revoke its cert besides rebuilding). I ran certutil.exe -setreg ca\DSConfigDN
CN=Configuration,DC=adstest,DC=contoso,DC=com to ensure correct revocation
and chain building as done by the PKI example for contoso. Restarted
certificate services.

Installed 2003 Enterprise SP1 and called it adstest-ent-ca and joined it to
the "adstest" windows 2003 domain. Installed certificate services as a
subordinate enterprise ca. (IIS is not installed) Requested certificate from
adstest-ca (rootca) and installed it on adstest-ent-ca. Restarted cert
services on adstest-ent-ca. So far no problems except it says that it
couldn't verify the cert because there was no crl. (But it worked anyway).

Now I thought I would reboot the domain controller and it would
automatically request the certificate, but it hasn't happened. In a previous
test, I just installed 2003 Enterprise SP1 and installed a Enterprise Root CA
and it requested it fine. But for some reason it's not working this way.

Any information on what to do next or any information at all would be
greatly appreciated!!!
Thanks,
jamie


Similar ThreadsPosted
Windows 2003 Domain Controller (Open Port 593) December 18, 2006, 4:48 pm
2003 Domain Controller event id when an account is locked ? January 3, 2007, 4:16 am
Automatic certificate enrollment for local system failed after upgrading member server to domain controller August 25, 2005, 6:11 pm
Problem when requesting a certificate to IIS server (certificate web enrollment) October 4, 2005, 9:50 am
Problem when requesting a certificate with IIS (certificate web enrollment) October 4, 2005, 9:45 am
RPC Server Unavailable When Requesting Computer Certificate September 16, 2005, 12:07 pm
Windows 2003 - Child domain cannot request certificate from root domain January 11, 2008, 11:41 am
Unable to download ActiveX Control when requesting a Certificate January 31, 2007, 12:20 pm
Domain Controller That Service a DMZ October 29, 2005, 9:58 pm
Domain Controller Security January 13, 2006, 4:43 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap