Auto enrollment Domain Certificate not working (error 13)

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi we have problem with getting the domain controller to get Certs.

The error in the log is Error 13

If we manually try to get a cert from a dc(Certificate Enrollment,Domain
Controller) we get the result "The RPC server is unavailable" (and error 13
is logged in the event log)

(like many other) And we found a(many) tip to run:

certutil -setreg SetupStatus -SETUP_DCOM_SECURITY_UPDATED_FLAG
net stop certsvc
net start certsvc

It reports that the old value was 6003 and so on. And the new value is 4003.
Restart certsvc and when it started and we run the command above it says
that it's old value is 6003 again (If we don't restart the service it says
that its 4003)

The Group exists in the domain and the domain controllers are added. But if
we look in the Component manager the Certsvc_dcom_access group doesn't exist
under "Com Security"- "Access Permission" or "Launch and Activation
Permission". I have tried to add it myself but with no difference. (I removed
it again because it didn't work.And the article I found kb 927066 specified
that it would be there when we ran the above command.)

Now we think we have tried all the solutions in the world with no different
results..

Thanks for the help..// Cristian

Ps. The system is CertSvc=Windows 2008 Std (DC and Exchange server) This one
actually have a Domain Cert issued also.
then we have 1 windows 2008 std as DC and 1 Windows 2003 std as DC Both
without a Certificate
.



Relevant Pages

  • Re: Best Practice approach in Replacing an Enterprise CA
    ... reinstalling on another server. ... Autoenrollment for the Domain Controller certificate did not occur anymore, ... cert on the personal store issued by the previous ent root CA. ...
    (microsoft.public.windows.server.security)
  • Auto enrollment Domain Certificate not working (error 13)
    ... Hi we have problem with getting the domain controller to get Certs. ... If we manually try to get a cert from a dc(Certificate Enrollment,Domain ... net start certsvc ... Restart certsvc and when it started and we run the command above it says ...
    (microsoft.public.security)
  • Re: Manually removing cert server from AD
    ... I don't think cert is required for AD services except you have applications ... that requires certificate to use AD for authentication. ... server wont cause some authentication issues for my existing AD ... system failed to enroll for one Domain Controller certificate ...
    (microsoft.public.windows.server.active_directory)
  • Re: Manually removing cert server from AD
    ... Maybe i should ask it this way - is a cert server required for AD services? ... system failed to enroll for one Domain Controller certificate ... and TS servers and see that they have a local computer certificate ...
    (microsoft.public.windows.server.active_directory)
  • Re: dcdiag - advertising errors on newley promoted domain controller
    ... The existing domain controller in the same site had a journal wrap ... Alias and glue records for forest GUIDs from server: ... From a command prompt try and see if you get any additional ...
    (microsoft.public.windows.server.active_directory)