Re: Certificate Template Creation



what I would do is this:

1. tear down the CA you have on the domain controller.
2. on your Enterprise server, install Virtual Server, then build a VM running Enterprise (you are licensed for up to 4!) to be your standalone, offline rootCA
3. copy that VM once all patched and happy and run sysprep on it to create a second VM to be your Enterprise CA. Configure it to integrate with AD and publish CRL's and AIA to AD.
4. create your certificate template on the Enterprise CA


"RAZ" <RAZ@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:87679F36-478C-4C06-A4E6-2D1BC59F4AD8@xxxxxxxxxxxxxxxx
We have a small domain with two Win2K3 servers. My so called PDC is our
Certificate Authority. This server is Standard edition. My other domain
controller is receiving autoenrollment events in the event viewer with the
following message:
"Automatic certificate enrollment for local system failed to enroll for one
Domain Controller certificate (0x80070005). Access is denied."
The second domain controller is Win2K3 Enterprise edition. I tried
installing a new smart card certificate template but learned I can't do that
with the PDC because it is standard edition which won't allow V2 template
creation.
How can I solve this issue? Is it wise to have more then one certificate
authority on a small domain?



.



Relevant Pages

  • Re: Autoenrollment Failure (0x80070005) - Additional help reqd.
    ... reboot the server right now, I have to wait till 8 hours are passed by. ... > apply the fix recommended. ... > One of the DCs is also a Certificate Server. ... >>> I have an Enterprise Root CA, which resides on the first domain controller ...
    (microsoft.public.windows.server.active_directory)
  • Re: Autoenrollment of Certificates
    ... This newsgroup only focuses on SBS technical issues. ... Did you install CA on the SBS Server? ... | events which led up to the point where a new certificate was created ...
    (microsoft.public.windows.server.sbs)
  • Autoenrollment Failure (0x80070005) - Additional help reqd.
    ... apply the fix recommended. ... One of the DCs is also a Certificate Server. ... >> has successfully obtained a 'Domain Controller' certificate. ...
    (microsoft.public.windows.server.active_directory)
  • Re: error 2042
    ... "Jorge Silva" wrote: ... Restart the server. ... If the domain controller that you are demoting is a DNS server or global ... -Dont forget to export the *EFS* certificate. ...
    (microsoft.public.windows.server.active_directory)
  • PLEASE HELP: Autoenrollment Failure (0x80070005) for Additional Domain Controller W2K3
    ... Server 2003 Active Directory network. ... SERVER01 and this Domain Controller ... has successfully obtained a 'Domain Controller' certificate. ...
    (microsoft.public.windows.server.active_directory)