Re: Autoenrollment error



Hi Matthew,

I appreciate your update and response, and I am glad to hear that the
problem has been fixed.

Please do not hesitate to post in this great newsgroup if you need any
assistance in the future. I look forward to working with you again.
Have a nice day!

Sincerely,
Tom Che
Microsoft Online Partner Support

--------------------
Date: Mon, 06 Feb 2006 08:05:59 -0600
From: Matthew Clark <MD-Clark@xxxxxxxxxxxxxx>
User-Agent: Thunderbird 1.5 (Windows/20051201)
MIME-Version: 1.0
Subject: Re: Autoenrollment error
References: <OMytfFCKGHA.2668@xxxxxxxxxxxxxxxxxxxx>
In-Reply-To: <OMytfFCKGHA.2668@xxxxxxxxxxxxxxxxxxxx>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Message-ID: <en7X1ZyKGHA.3164@xxxxxxxxxxxxxxxxxxxx>
Newsgroups: microsoft.public.windows.server.active_directory
NNTP-Posting-Host: matt.wiu.edu 143.43.192.31
Lines: 1
Path: TK2MSFTNGXA02.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP11.phx.gbl
Xref: TK2MSFTNGXA02.phx.gbl
microsoft.public.windows.server.active_directory:62970
X-Tomcat-NG: microsoft.public.windows.server.active_directory

I don't know how or why, but after having this error for EVER, We
finally got:

Event Type: Information
Event Source: AutoEnrollment
Event Category: None
Event ID: 19
Date: 2/2/2006
Time: 3:28:48 AM
User: N/A
Computer: xxxxxxxxxxx
Description:
Automatic certificate enrollment for local system successfully received
one Domain Controller certificate from certificate authority xx-AD_CA on
xxxxx.ad.xxxxx.edu.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

The only change I made was to make the Domain Controller group to the
CERTSVC_DCOM_ACCESS and waited a couple days. Certainly interesting..

Thanks!


Matthew Clark wrote:
I posted this in General with no response so I thought I might try here
as well...

I have a 2003 server that keeps getting the error -

Event Type: Error
Event Source: AutoEnrollment
Event Category: None
Event ID: 13
Date: 2/1/2006
Time: 11:28:51 AM
User: N/A
Computer: xxxxxxx
Description:
Automatic certificate enrollment for local system failed to enroll for
one
Domain Controller certificate (0x80070005). Access is denied.


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

I read in a couple places to try "certutil -setreg SetupStatus
-SETUP_DCOM_SECURITY_UPDATED_FLAG". I tried that and it produced the
error -

CertUtil: -setreg command FAILED: 0x80070002 (WIN32: 2)
CertUtil: The system cannot find the file specified.

Does anyone have a suggestion on where to go from here?

Thanks!


.



Relevant Pages

  • Re: Autoenrollment error
    ... Automatic certificate enrollment for local system successfully received one Domain Controller certificate from certificate authority xx-AD_CA on xxxxx.ad.xxxxx.edu. ... I read in a couple places to try "certutil -setreg SetupStatus ...
    (microsoft.public.windows.server.active_directory)
  • Re: After 30 mins, why cant my Laptop connect to my PC ? (unless I log off/on again)
    ... Windows cannot determine the user or computer name. ... see Help and Support Center at ... Automatic certificate enrollment for local system failed to contact ... or service was still using the registry during log off. ...
    (microsoft.public.windowsxp.general)
  • Re: After 30 mins, why cant my Laptop connect to my PC ? (unless I log off/on again)
    ... I am getting the following error messages in my application log: ... see Help and Support Center at ... Automatic certificate enrollment for local system failed to contact ... or service was still using the registry during log off. ...
    (microsoft.public.windowsxp.general)
  • Re: After 30 mins, why cant my Laptop connect to my PC ? (unless I log off/on again)
    ... Windows cannot determine the user or computer name. ... see Help and Support Center at ... Automatic certificate enrollment for local system failed to contact ... or service was still using the registry during log off. ...
    (microsoft.public.windowsxp.general)
  • Re: XMPP & Kerberos 5
    ... leave the local system. ... Kerberos password, which is only used for login-equivalent ... authentication and certificate generation, and their "email" password, ... Since no commonly-used XMPP clients support GSSAPI authentication, ...
    (comp.protocols.kerberos)

Loading