Re: AutoEnrollment DCs

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



If domain controllers need access to this interface to request certificates
from the certification authority, you must add the Domain Controllers
security group. You must do this because domain controllers are not part of
the Domain Computers security group.

See
http://support.microsoft.com/default.aspx?scid=kb;en-us;903220

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

"Leezy" <leezy@xxxxxxxx> wrote in message
news:OkJzDMYNIHA.5224@xxxxxxxxxxxxxxxxxxxxxxx
I am getting these 2 errors here on my server.

PDC has no problem with this, only 2nd DC has this error...

anyidea how to get rid of it ?



Thanks

leezy





Event Type: Error

Event Source: AutoEnrollment

Event Category: None

Event ID: 13

Date: 12/2/2007

Time: 11:23:00 PM

User: N/A

Computer: KNB-DC-02

Description:

Automatic certificate enrollment for local system failed to enroll for one
Domain Controller certificate (0x80070005). Access is denied.



Event Type: Error

Event Source: AutoEnrollment

Event Category: None

Event ID: 16

Date: 12/3/2007

Time: 7:22:59 AM

User: N/A

Computer: KNB-DC-02

Description:

Automatic certificate enrollment for local system failed to renew one
Domain Controller certificate (0x80070005). Access is denied.




.



Relevant Pages

  • Re: AutoEnrollment DCs
    ... ill let it be as long its not much problem to my server:) ... CERTSVC_DCOM_ACCESS security group? ... domain controllers need access to this interface to request certificates ... Automatic certificate enrollment for local system failed to enroll ...
    (microsoft.public.windows.server.active_directory)
  • Re: AutoEnrollment DCs
    ... Did you add the Domain Controllers security group to the CERTSVC_DCOM_ACCESS ... certification authority, you must add the Domain Controllers security group. ... the server holding the certificate? ...
    (microsoft.public.windows.server.active_directory)
  • Re: AutoEnrollment DCs
    ... it needs access to the certificate services and this ... MVP - Directory Services ... CERTSVC_DCOM_ACCESS security group? ... domain controllers need access to this interface to request certificates ...
    (microsoft.public.windows.server.active_directory)
  • AutoEnrollment problem
    ... a replicated version of AD and also running an Enterprise-level Certificate ... installed from the Windows Server CD. ... enroll and autoenroll for Domain ... Controllers and for ENTERPRISE DOMAIN CONTROLLERS). ...
    (microsoft.public.windows.server.security)
  • Re: AutoEnrollment DCs
    ... CERTSVC_DCOM_ACCESS security group? ... domain controllers need access to this interface to request certificates ... the server holding the certificate? ... Automatic certificate enrollment for local system failed to renew one ...
    (microsoft.public.windows.server.active_directory)