Re: Autoenrollment error
- From: Matthew Clark <MD-Clark@xxxxxxxxxxxxxx>
- Date: Fri, 03 Feb 2006 07:47:31 -0600
I tried #5 earlier. Domain Users and Domain Computers were members of the group, and I added Domain Controllers, but it didn't seem to solve the problem. I'll run through the rest today and see if any of them work.
Thanks!
Ace Fekay [MVP] wrote:
In news:P309fQHKGHA.3680@xxxxxxxxxxxxxxxxxxxxx,.
Tom Che [MSFT] <v-tomche@xxxxxxxxxxxxxxxxxxxx> stated, which I commented on below:Hi Matthew,
Thanks for your posting.
I suggest you may refer to the following steps to troubleshoot the
Event ID 13 AutoEnrollment error:
BTW, you got an error when you try to use the following command maybe
because the server is not a CA:
"certutil -setreg SetupStatus -SETUP_DCOM_SECURITY_UPDATED_FLAG"
1) Follow KB889101(Release notes for Windows Server 2003 Service Pack
1, Part:
Certificate Services: Effects of security enhancements to the DCOM
protocol)
2) Right click on Certficate Authority in the MMC on the Enterprise
CA. Checked if security authenticated users has read and enroll
permission.
3) Checked if Enterprise Admins has Full Control to
HKLM/System/CurrentControlSet/Services/CertSvc/Security and a read
ACE to CN=SubCA,CN=CertificateTemplates,CN=Public Key
Services,CN=Services,CN=Configuration.
4) Check DCOM configuration on the DC through DCOMCNFG command.
Component Services - > Computers -> My Computer -> Properties ->
Default Properties) "Enable Distributed COM on this computer"
5) There is a group that is created called CERTSVC_DCOM_ACCESS.
Checked in AD Users and Computers to verify that the members are
Domain Users, Domain Computers, and Domain Controllers.
6) Error can also occur if all other domain controllers in the forest
do not have permissions of Enroll, Change, Read. In order to
troubleshoot, open the Certificate Template MMC, Right click on the
Certificate you wish to assign permission and click Properties. In
the security tab, added Domain Computers group from each domain with
the permissions of Enroll, Change and Read.
Tom,
This actually helped me when I had a similar issue. Possiblity #5 above was what helped.
- Follow-Ups:
- Re: Autoenrollment error
- From: Tom Che [MSFT]
- Re: Autoenrollment error
- From: Ace Fekay [MVP]
- Re: Autoenrollment error
- References:
- Autoenrollment error
- From: Matthew Clark
- RE: Autoenrollment error
- From: Tom Che [MSFT]
- Re: Autoenrollment error
- From: Ace Fekay [MVP]
- Autoenrollment error
- Prev by Date: Re: Error in Trusting the W2K3 domain from NT 4.0
- Next by Date: Re: Autoenrollment error
- Previous by thread: Re: Autoenrollment error
- Next by thread: Re: Autoenrollment error
- Index(es):
Relevant Pages
|
Loading