Click here to get back home

Certificates are not published

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Certificates are not published Carma Trepp 10-17-2005
Posted by Carma Trepp on October 17, 2005, 3:31 pm
Please log in for more thread options
Hi all

I would like to enforce the auto enrollment on user certificates. But my
certificates are not published in the AD even the option "Publish
Certificate in Active Directory" is selected.

Thanks for any answers..

CA Server is Win2003


Posted by Paul Adare on October 17, 2005, 10:08 am
Please log in for more thread options
microsoft.public.windows.server.security news group, Carma Trepp

> Hi all
>
> I would like to enforce the auto enrollment on user certificates. But my
> certificates are not published in the AD even the option "Publish
> Certificate in Active Directory" is selected.
>

Check for errors in the event logs on the clients and the CA.

--
Paul Adare
MVP - Windows - Virtual Machine
http://www.identit.ca/blogs/paul/
"The English language, complete with irony, satire, and sarcasm, has
survived for centuries without smileys. Only the new crop of modern
computer geeks finds it impossible to detect a joke that is not clearly
labeled as such."
Ray Shea


Posted by Brian Komar [MVP] on October 17, 2005, 11:13 am
Please log in for more thread options
padare@newsguy.com says...
> microsoft.public.windows.server.security news group, Carma Trepp
>
> > Hi all
> >
> > I would like to enforce the auto enrollment on user certificates. But my
> > certificates are not published in the AD even the option "Publish
> > Certificate in Active Directory" is selected.
> >
>
> Check for errors in the event logs on the clients and the CA.
>
>
In addition, there are two other possibilities.
- See KB 281271 - Certification Authority configuration to publish
certificates in Active Directory of trusted domain

If the CA is in a different domain than the user's domain, it will not
have the necessary permissions to publish the certificate. The KB
article states what needs to be done.

Brian


Posted by Carma Trepp on October 18, 2005, 9:40 am
Please log in for more thread options
Brian Komar [MVP] wrote:

> In addition, there are two other possibilities.
> - See KB 281271 - Certification Authority configuration to publish
> certificates in Active Directory of trusted domain
>
> If the CA is in a different domain than the user's domain, it will not
> have the necessary permissions to publish the certificate. The KB
> article states what needs to be done.
>
> Brian

No CA specific errors are in the eventlog.
We have only one domain, and the CA is on one of the two DC`s. I really
think the CA have enough rights. The CA is also in the Cert Publishers
group.


Posted by Paul Adare on October 18, 2005, 4:33 am
Please log in for more thread options
microsoft.public.windows.server.security news group, Carma Trepp

> Brian Komar [MVP] wrote:
>
> > In addition, there are two other possibilities.
> > - See KB 281271 - Certification Authority configuration to publish
> > certificates in Active Directory of trusted domain
> >
> > If the CA is in a different domain than the user's domain, it will not
> > have the necessary permissions to publish the certificate. The KB
> > article states what needs to be done.
> >
> > Brian
>
> No CA specific errors are in the eventlog.
> We have only one domain, and the CA is on one of the two DC`s. I really
> think the CA have enough rights. The CA is also in the Cert Publishers
> group.

You've checked both the client and CA event logs? Have you actually
configured the templates to publish in AD? What certificate templates
are you using? What OS (Standard, Enterprise, etc.) are you running on
the CA?

--
Paul Adare
MVP - Windows - Virtual Machine
http://www.identit.ca/blogs/paul/
"The English language, complete with irony, satire, and sarcasm, has
survived for centuries without smileys. Only the new crop of modern
computer geeks finds it impossible to detect a joke that is not clearly
labeled as such."
Ray Shea


Similar ThreadsPosted
Published Certificates in Active Directory February 9, 2006, 6:53 pm
Certificates April 5, 2007, 5:38 pm
two CA certificates for IPSec or something... September 17, 2005, 3:58 pm
Certificates 802.1X Auth. November 21, 2005, 11:07 am
Removing CA certificates. December 22, 2005, 3:50 pm
Need some information about certificates March 9, 2006, 5:54 pm
EFS Certificates in AD 2003 June 30, 2006, 12:07 pm
Self Signed Certificates? September 28, 2006, 12:29 am
Third party DC certificates October 9, 2006, 7:43 am
two CA certificates for IPSec or something... February 16, 2007, 1:57 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap