help! domain controller won't renew certificate

Tech-Archive recommends: Fix windows errors by optimizing your registry



A year ago, I set up a wireless network using PEAP authentication in
accordance with the instructions in Microsoft's document "Securing
Wireless LANS with PEAP and passwords". Everything worked fine for a
year. Now, user attempts to connect are all being rejected. The only
message I've seen that was at all helpful in the event log, along with
endless messages telling me logons were rejected was one suggesting
there is a kerberos problem somewhere, and I should check my public
key infrastructure. I fired up the certification authority MMC snap
in, and lo and behold, the certificate for the domain controller that
hosts IAS just expired. (It's the same server that hosts the
certification authority). I can't figure out how to get it to renew.
I tried rebooting the server, that didn't help.

Some app note I found on MS's web site suggests there may be a group
policy preventing autoenrollment, but it doesn't say specifically how
to fix it.

One other thing I discovered is if, in the clients, you configure the
wireless network not to validate your server certificate, you're in.

BTW, the expiration period for the certificate I generated in the
process of following the WLAN setup instructions is 25 years, I don't
recall ever generating a certificate that expired in a year.

Anyone have any clue how to get this domain controller to renew its
cert, so clients can connect without disabling 1/2 the authentication?

.



Relevant Pages

  • RE: Public Folder in Exchange - SSL certificate server name incorr
    ... Your latest instructions have fixed the problem. ... > This newsgroup only focuses on SBS technical issues. ... we should run CEICW to generate a certificate to ... Restart the IIS Admin service in the services mmc. ...
    (microsoft.public.windows.server.sbs)
  • Re: 802.1x wireless lan how to?
    ... had on the methodology. ... methodology that doesn't affect the operation of the wireless network. ... it seems that if you have a certificate issue while everything ... My laptop does not have a domain account ...
    (microsoft.public.windows.server.sbs)
  • Re: RPC over HTTP
    ... I changed the certificate and then used the instructions as you said. ... Do I need to have certificate services running on the exchange server? ... The instructions say to enable mutual authentication. ...
    (microsoft.public.windows.server.sbs)
  • RE: Connecting to AD on port 636
    ... I followed what instructions I found ... you need the implementation of the PKI infrastructure. ... > would need an enterprise CA or stand alone CA that can publish SSL ... > certificate for LDAP i.e. LDAP SSL. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Public Folder in Exchange - SSL certificate server name incorr
    ... The only "difference" between your helpful instructions and what I saw on ... I have 2 NICs in my server, but instead of 2 certificates to ... > For Error message "The SSL certificate server name is incorrect, ... Restart the IIS Admin service in the services mmc. ...
    (microsoft.public.windows.server.sbs)