Click here to get back home

Removing CA Objects from AD

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Removing CA Objects from AD Billy 08-10-2005
Get Chitika Premium
Posted by Billy on August 10, 2005, 10:51 am
Please log in for more thread options
My master DC crashed and had to be rebuilt - it was originally set up as a
certificate server, I have not re-installed certificate services and not
wish to if I can get away with it. - however I am getting an warning in my
event log
Source: Winlogon
Category: None
Event ID: 1010
Automatic enrollment against the certification authority 'myservername' for
a certificate of type DomainController has failed (0x800706ba) The RPC
server is unavailable. - Another certification authority will be tried.

The only issues I can see is that I can no longer get OWA (it is an
exchange server also) Clients accessing OWA did have to do a HTTPS
connection after I had set up the CA.

So basically what I am asking is how to overcome this by manually removing
the CA object left in Active Directory?

BillyJ




Posted by S. Pidgorny on August 10, 2005, 8:47 pm
Please log in for more thread options
Remove the CA object from Active Directory sites and Services?

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

> My master DC crashed and had to be rebuilt - it was originally set up as a
> certificate server, I have not re-installed certificate services and not
> wish to if I can get away with it. - however I am getting an warning in my
> event log
> Source: Winlogon
> Category: None
> Event ID: 1010
> Automatic enrollment against the certification authority 'myservername'
for
> a certificate of type DomainController has failed (0x800706ba) The RPC
> server is unavailable. - Another certification authority will be tried.
>
> The only issues I can see is that I can no longer get OWA (it is an
> exchange server also) Clients accessing OWA did have to do a HTTPS
> connection after I had set up the CA.
>
> So basically what I am asking is how to overcome this by manually removing
> the CA object left in Active Directory?
>
> BillyJ
>
>




Posted by Billy on August 10, 2005, 2:25 pm
Please log in for more thread options
hi
Can you clarify - the server that crashed has been rebuilt using the same
name and is now back onto the domain and re-assgined its position within AD
sites & services?

Billyj



> Remove the CA object from Active Directory sites and Services?
>
> --
> Svyatoslav Pidgorny, MS MVP - Security, MCSE
> -= F1 is the key =-
>
>> My master DC crashed and had to be rebuilt - it was originally set up as
>> a
>> certificate server, I have not re-installed certificate services and not
>> wish to if I can get away with it. - however I am getting an warning in
>> my
>> event log
>> Source: Winlogon
>> Category: None
>> Event ID: 1010
>> Automatic enrollment against the certification authority 'myservername'
> for
>> a certificate of type DomainController has failed (0x800706ba) The RPC
>> server is unavailable. - Another certification authority will be tried.
>>
>> The only issues I can see is that I can no longer get OWA (it is an
>> exchange server also) Clients accessing OWA did have to do a HTTPS
>> connection after I had set up the CA.
>>
>> So basically what I am asking is how to overcome this by manually
>> removing
>> the CA object left in Active Directory?
>>
>> BillyJ
>>
>>
>
>




Posted by S. Pidgorny on August 11, 2005, 7:43 pm
Please log in for more thread options
I think after the crash the previous CA information is still stored in the
AD - under Services, that is.
Fore detailed information, see "How to decommission a Windows enterprise
certification authority and how to remove all related objects from Windows
Server 2003 and from Windows 2000 Server" -
http://support.microsoft.com/?id=889250, and the removing objects part in
it.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

> hi
> Can you clarify - the server that crashed has been rebuilt using the same
> name and is now back onto the domain and re-assgined its position within
AD
> sites & services?
>
> Billyj
>
>
>
> > Remove the CA object from Active Directory sites and Services?
> >
> > --
> > Svyatoslav Pidgorny, MS MVP - Security, MCSE
> > -= F1 is the key =-
> >
> >> My master DC crashed and had to be rebuilt - it was originally set up
as
> >> a
> >> certificate server, I have not re-installed certificate services and
not
> >> wish to if I can get away with it. - however I am getting an warning in
> >> my
> >> event log
> >> Source: Winlogon
> >> Category: None
> >> Event ID: 1010
> >> Automatic enrollment against the certification authority 'myservername'
> > for
> >> a certificate of type DomainController has failed (0x800706ba) The RPC
> >> server is unavailable. - Another certification authority will be tried.
> >>
> >> The only issues I can see is that I can no longer get OWA (it is an
> >> exchange server also) Clients accessing OWA did have to do a HTTPS
> >> connection after I had set up the CA.
> >>
> >> So basically what I am asking is how to overcome this by manually
> >> removing
> >> the CA object left in Active Directory?
> >>
> >> BillyJ
> >>
> >>
> >
> >
>
>




Similar ThreadsPosted
Security on printer objects and the Printers web November 30, 2005, 4:53 pm
How to search the properties of all the DCOM objects on a machine at once December 18, 2005, 7:17 pm
How to automatically inherit permission entries on child objects? January 21, 2006, 7:43 am
W2003 PKI: Publish certificates onto user objects in active directory December 14, 2005, 1:04 pm
Removing CA certificates. December 22, 2005, 3:50 pm
Re: Removing CA Authority September 26, 2006, 3:05 pm
Re: Removing CA - Question October 21, 2008, 5:13 am
Re: Removing CA - Question October 21, 2008, 8:17 am
Win2k3 SP1- Removing Ctrl+Alt Del June 28, 2005, 1:55 pm
Removing System SID from ACLs August 8, 2006, 2:40 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap