|
Posted by Wibblet on December 6, 2006, 10:44 am
Please log in for more thread options
Hi
I have two domains, a parent and sub. My PKI is setup with an offline root
and an enterprise subordinae in the parent domain.
I have configured the permissions on the Sub ca, delegated control to the
cert publishers group from the parent domain to the child domain and runacls
cmd aswell.
I can request certs via the web interface. but when I try to request via the
mmc snapin in the sub-domain it says the general "no trusted ca's or no perms
or available ca's u have no perms.." message. This works for me if i am in
the parent domain.
I have checked the services container and the root CA is in the
"certification authorities container (no subca server tho), and the sub CA is
setup in the AIA and CDP.
Anything I am missing that you can see as is is frustrating. Trying to
request a RAS and IAS cert for a machine in the sub domain...
Cheers
Jonathan
|