Re: understanding certificate autoenrollment



The system is running windows 2003 standard edition with SP1. This is a
domain controler.

I logged with a user account member of both Enterprise Admin &
Domain-Admin builtin groups.

<quote>FYI: The build in group
ENTERPRISE DOMAIN CONTROLLERS should have read and autoenroll, enroll
rights, that group covers all domain controllers within the
forest</quote>

Well but when i try to give read access to the Enterprise Domain
Controllers i receive a message error :

Unable to save permission changes to LDAP:
DomainName\DomainControlerAuthentication,CN=CertificateTemplate,CN=PublicKeyServices,CN=Services,CN=Configuration,DC=domain
A referral was returned from the server

So i am blocked at that point and i dont see what i can do as ther's
not even an article about that in the KB, i have tried to install and
reinstall the CA but no luck.

Thanks for your help.

.



Relevant Pages

  • Re: Installing Enterprise CA broke existing LDAP SSL on the DCs
    ... If you run certutil -dcinfo deleteBad it will drop all certs and request a ... an Enterprise CA was created on a member server for the ... A new group policy was created and linked to the Domain Controllers OU ... controllers via secure LDAP, and have been prompeted for a smart card. ...
    (microsoft.public.windows.server.active_directory)
  • Enterprise CA
    ... Reading some articles to keep my external OWA access secure, ... I have two Domain Controllers - one of them is a Enterprise Subordinate CA ... I've tried to use it as my Certificate Authority to validate external OWA ...
    (microsoft.public.win2000.security)
  • RE: DCpromo error; Policy problem ??
    ... my default domain controllers policy. ... I called our entrprise admins to try the EA account in my ... >Enterprise Domain Controllers group is added as well. ...
    (microsoft.public.win2000.group_policy)
  • RE: GrantPermissionOnAllGPOs.wsf
    ... I don't have that security group on our domain. ... jswift - Do you have the Enterprise Domain Controllers group in your Active ...
    (microsoft.public.windows.server.active_directory)
  • Re: SCECLI 1202 0x534 No mapping between account names and security IDs was done. *Fixed*
    ... but I logged into the DC with an Enterprise Admin and the ... One article said the Default Domain Controllers Policy lost its link to ... So I added it in again (giving me the same link twice). ... It says Cannont find Power Users ...
    (microsoft.public.windows.server.general)