Click here to get back home

Cannot manage Entreprise CA that is in parent domain from child domain

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Cannot manage Entreprise CA that is in parent domain from child domain tomer_k 05-07-2008
Posted by tomer_k on May 7, 2008, 4:03 am
Please log in for more thread options

Hi,
I have a premission problem with my forest.
I have a parent domain: Father.com and a child domain:
Child.father.com.
I want to be able to manage the CA that is in the Father using MMC.
I can retarget but when i try to manage i get: " Access is denied.
0x80070005"
I've giving a full control permissions to the user in the child domain
from the parent CA.
Both domains are windows 2003 Enterprise.
I have also a windows 2000 domain controler, so the functional level is
windows 2000 native.

Any one have ideas how to solve this?

10x,
Tomer.


--
tomer_k
------------------------------------------------------------------------
tomer_k's Profile: http://forums.techarena.in/member.php?userid=48458
View this thread: http://forums.techarena.in/showthread.php?t=963312

http://forums.techarena.in


Posted by Brian Komar \(MVP\) on May 7, 2008, 7:29 am
Please log in for more thread options
You simply do not have permissions set correctly
A group containing the user must be assigned the Manage CA permission on the
CA in the Certification Authority console.
Brian

>
> Hi,
> I have a premission problem with my forest.
> I have a parent domain: Father.com and a child domain:
> Child.father.com.
> I want to be able to manage the CA that is in the Father using MMC.
> I can retarget but when i try to manage i get: " Access is denied.
> 0x80070005"
> I've giving a full control permissions to the user in the child domain
> from the parent CA.
> Both domains are windows 2003 Enterprise.
> I have also a windows 2000 domain controler, so the functional level is
> windows 2000 native.
>
> Any one have ideas how to solve this?
>
> 10x,
> Tomer.
>
>
> --
> tomer_k
> ------------------------------------------------------------------------
> tomer_k's Profile: http://forums.techarena.in/member.php?userid=48458
> View this thread: http://forums.techarena.in/showthread.php?t=963312
>
> http://forums.techarena.in
>


Posted by tomer_k on May 7, 2008, 11:43 am
Please log in for more thread options

Thanks for your replay,

I gave permissions not the group but directly to user in the child
domain.
I cannot add a user from a sub-domain to a group in the parent domain
because the functional level is windows 2000 native.

Tomer.


--
tomer_k
------------------------------------------------------------------------
tomer_k's Profile: http://forums.techarena.in/member.php?userid=48458
View this thread: http://forums.techarena.in/showthread.php?t=963312

http://forums.techarena.in


Similar ThreadsPosted
Publish Certificates in AD - parent\child domain April 4, 2006, 6:13 pm
Windows 2003 - Child domain cannot request certificate from root domain January 11, 2008, 11:41 am
Windows 2003, Domain Controllers & "Manage auditing and security November 1, 2006, 4:43 pm
Request Cert via certificates MMC snapin with CA in parent domain December 6, 2006, 10:44 am
Child domain laptops autoenrolling user certs but not computer certs May 21, 2008, 4:19 pm
Allow app as user at child root read-only to all child AD objects August 9, 2006, 9:22 pm
Allowing a Domain User Admin Rights to a Couple of Domain Servers June 29, 2005, 8:13 pm
Adding another domain users to your local domain admin group December 28, 2005, 12:19 pm
domain access control for local user of domain computer? April 3, 2008, 5:14 pm
ENTERPRISE DOMAIN CONTROLLERS Vs Domain Group Domain Controllers December 30, 2005, 3:08 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap