RE: Auto Enrollment not working for one DC



Hello,

Thank you for your post, and also thanks to Jorge's inputs.

Are there two DCs in the same domain, or DCs in different domains?

Please check the following:

1. Ensure the computer account of both DCs have full control to the Domain
Controller certificate template.

You can run certtmpl.msc on the CA server and then assign the permissions.

2. Generally, the new CERTSVC_DCOM_ACCESS security group should be
generated if the DC applies Windows Server 2003 SP1. Please check whether
this account exists.

If you can find it, we can have Certificate Services update the DCOM
security settings by running the following commands:

certutil -setreg SetupStatus -SETUP_DCOM_SECURITY_UPDATED_FLAG
net stop certsvc
net start certsvc

Hope this helps. Thanks!


Regards,
Joe Wu
Microsoft Online Partner Support

======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
======================================================


.



Relevant Pages

  • RE: Differnet language domain controllers in single domain
    ... > I understand your concern is that if you can install the DCs in English ... > language and then migrate the regional user accounts, ... > package to fulfill the function and Windows Server 2003 Multilingual is ... > Thanks & Regards ...
    (microsoft.public.windows.server.migration)
  • RE: Auto Enrollment not working for one DC
    ... a DC from the child domain WAS able to autoenroll from this CA. ... Are there two DCs in the same domain, ... the new CERTSVC_DCOM_ACCESS security group should be ... net start certsvc ...
    (microsoft.public.windows.server.active_directory)
  • RE: Forest, Domain, Certificate, CA, IAS/Radius, Issues
    ... Are these two related DCs Windows Server ... Ensure the domain account of both DCs have full control to the Domain ... Please check if you can manually request a Domain Controller certificate ... net start certsvc ...
    (microsoft.public.windows.server.networking)
  • Re: AD Question
    ... find records related to user logon/logoff ... You might check lastLogon attribute of the user object, ... replicated between dcs, so you will have to query all dcs in the user's ... Windows Server - Directory Services ...
    (microsoft.public.windows.server.active_directory)
  • Re: Upgrading to Windows Server 2008
    ... i hate OS upgrades. ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... Windows Server 2003 small network with 2 DCs, I manaed to setup a lab domain ...
    (microsoft.public.windows.server.active_directory)