Click here to get back home

Automatic certificate enrollment for local system failed

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Automatic certificate enrollment for local system failed Ross 08-03-2006
Posted by Ross on August 3, 2006, 10:22 am
Please log in for more thread options
Hi Guys,

We have 2 Win2003 Domain Controlers with SP1 installed - dc01 and dc02.
On dc01, I have installed the certificate service and configured Certificate
autoenrollment through Group Policy.

Every thing has been working fine for almost one year.
However, recently, the dc02 gets an error in the event viewer for every 8
hours:

Event Type: Error
Event Source: AutoEnrollment
Event Category: None
Event ID: 13
Description:
Automatic certificate enrollment for local system failed to enroll for one
Domain Controller certificate (0x80070005). Access is denied.
Access is denied.

Any idea would be appreciated,
Ross



Posted by Jorge Silva on August 3, 2006, 6:38 pm
Please log in for more thread options
Hi

check here
Description of the changes to DCOM security settings after you install
Windows Server 2003 Service Pack 1
http://support.microsoft.com/kb/903220/en-us

--
I hope that the information above helps you

Good Luck
Jorge Silva
MCSA
Systems Administrator

> Hi Guys,
>
> We have 2 Win2003 Domain Controlers with SP1 installed - dc01 and dc02.
> On dc01, I have installed the certificate service and configured
> Certificate autoenrollment through Group Policy.
>
> Every thing has been working fine for almost one year.
> However, recently, the dc02 gets an error in the event viewer for every 8
> hours:
>
> Event Type: Error
> Event Source: AutoEnrollment
> Event Category: None
> Event ID: 13
> Description:
> Automatic certificate enrollment for local system failed to enroll for one
> Domain Controller certificate (0x80070005). Access is denied.
> Access is denied.
>
> Any idea would be appreciated,
> Ross
>



Posted by c-shape on June 16, 2008, 6:37 pm
Please log in for more thread options

Jorge Silva;2072740 Wrote:
> Hi
>
> check here
> Description of the changes to DCOM security settings after you install
> Windows Server 2003 Service Pack 1
> http://support.microsoft.com/kb/903220/en-us
>
> --
> I hope that the information above helps you
>
> Good Luck
> Jorge Silva
> MCSA
> Systems Administrator
>
> > Hi Guys,
> >
> > We have 2 Win2003 Domain Controlers with SP1 installed - dc01 and
> dc02.
> > On dc01, I have installed the certificate service and configured
> > Certificate autoenrollment through Group Policy.
> >
> > Every thing has been working fine for almost one year.
> > However, recently, the dc02 gets an error in the event viewer for
> every 8
> > hours:
> >
> > Event Type: Error
> > Event Source: AutoEnrollment
> > Event Category: None
> > Event ID: 13
> > Description:
> > Automatic certificate enrollment for local system failed to enroll
> for one
> > Domain Controller certificate (0x80070005). Access is denied.
> > Access is denied.
> >
> > Any idea would be appreciated,
> > Ross
> >


Does this info works if you have SP2 instead of SP1? I'm getting that
same error too, but with SP2 on it.


--
c-shape
------------------------------------------------------------------------
c-shape's Profile: http://forums.techarena.in/member.php?userid=51562
View this thread: http://forums.techarena.in/showthread.php?t=562306

http://forums.techarena.in


Posted by Brian Komar \(MVP\) on June 17, 2008, 8:04 am
Please log in for more thread options
Yes, if you did not do it for SP1, then the same issue will exist in SP2
Brian

>
> Jorge Silva;2072740 Wrote:
>> Hi
>>
>> check here
>> Description of the changes to DCOM security settings after you install
>> Windows Server 2003 Service Pack 1
>> http://support.microsoft.com/kb/903220/en-us
>>
>> --
>> I hope that the information above helps you
>>
>> Good Luck
>> Jorge Silva
>> MCSA
>> Systems Administrator
>>
>> > Hi Guys,
>> >
>> > We have 2 Win2003 Domain Controlers with SP1 installed - dc01 and
>> dc02.
>> > On dc01, I have installed the certificate service and configured
>> > Certificate autoenrollment through Group Policy.
>> >
>> > Every thing has been working fine for almost one year.
>> > However, recently, the dc02 gets an error in the event viewer for
>> every 8
>> > hours:
>> >
>> > Event Type: Error
>> > Event Source: AutoEnrollment
>> > Event Category: None
>> > Event ID: 13
>> > Description:
>> > Automatic certificate enrollment for local system failed to enroll
>> for one
>> > Domain Controller certificate (0x80070005). Access is denied.
>> > Access is denied.
>> >
>> > Any idea would be appreciated,
>> > Ross
>> >
>
>
> Does this info works if you have SP2 instead of SP1? I'm getting that
> same error too, but with SP2 on it.
>
>
> --
> c-shape
> ------------------------------------------------------------------------
> c-shape's Profile: http://forums.techarena.in/member.php?userid=51562
> View this thread: http://forums.techarena.in/showthread.php?t=562306
>
> http://forums.techarena.in
>


Similar ThreadsPosted
Automatic certificate enrollment for local system failed after upgrading member server to domain controller August 25, 2005, 6:11 pm
Automatic Certificate Enrollment Problems April 5, 2006, 11:45 am
OpenRowset : DSN : file-system permissions : Local System March 14, 2008, 10:23 am
Problems setting up automatic certificate requests July 25, 2005, 8:39 am
automatic certificate request GPO VS Auto enroll February 19, 2008, 1:50 pm
"No Certificate Templates Could Be Found" Error Message When User Requests Certificate from CA Web Enrollment Pages September 21, 2006, 1:31 pm
Problem when requesting a certificate to IIS server (certificate web enrollment) October 4, 2005, 9:50 am
Is local system account member of local Administrators group? June 21, 2005, 11:33 am
Problem when requesting a certificate with IIS (certificate web enrollment) October 4, 2005, 9:45 am
Re-enrollment of Certificate on Win 2000 June 27, 2005, 3:26 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap