Access Denied accessing Certificate Services from local system

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Oren Novotny (osn_at_NOpo.SPcwru.AMedu)
Date: 12/17/04


Date: Fri, 17 Dec 2004 18:16:28 -0500

I have a problem with Certificate Services and after googling for several
days I still can't find an answer. I have a Win2k3 native domain; the
Enterprise Root CA is a member server; I have domain group policy set to
autoenroll for user/machine certificates. All other machines in the domain
get their certificates and I can see that they were issued from the CA MMC.

On one of the DC's though, I get constant Autoenroll errors (event id 13)
and if I use the Certificates MMC to manually request a cert for the
machine, I get an access denied.

Further, I'm getting occiasional userenv errors; they'll usually last
several days at a time and then mysteriously stop (I'm not sure if this is
related). Dcdiag and NetDiag pass on both DC's, though if I go to the DFS
SYSVOL share from a member server, I get access denied.

I tried setting full auditing on the CA server but I can't find any denied
in there.

I'd appreciate any help in resolving these issues.

Thanks!
--Oren



Relevant Pages

  • Authentication and KDC Problems
    ... I have a 2k3 native domain with 2 DCs. ... reinstalled on a member server on the domain. ... I deleted all certificates ...
    (microsoft.public.windows.server.general)
  • Re: Authentication and KDC Problems
    ... uninstalled and reinstalled on a member server on the domain. ... I deleted all certificates ... one) and a member server (as I don't know if uninstalling this will cause ... I am still experiencing some odd authentication problems. ...
    (microsoft.public.windows.server.general)
  • Re: How to fix broken security in Windows 2000?
    ... explicitly identify the missing certificates using SFC or some other tool. ... it turns out Windows 2000 doesn't support that feature after ... all W2K machines have the problem seems to be holding up (and I have not yet ...
    (microsoft.public.win2000.windows_update)
  • Re: How to fix broken security in Windows 2000?
    ... explicitly identify the missing certificates using SFC or some other tool. ... it turns out Windows 2000 doesn't support that feature after ... all W2K machines have the problem seems to be holding up (and I have not yet ...
    (microsoft.public.windowsupdate)
  • Re: How to fix broken security in Windows 2000?
    ... explicitly identify the missing certificates using SFC or some other tool. ... it turns out Windows 2000 doesn't support that feature after ... all W2K machines have the problem seems to be holding up (and I have not yet ...
    (microsoft.public.security)