Automatice Certificate Enrollment Failure



This post is intended for the TechNet managed news group monitors to resolve.

I have a Windows 2003 Server that is running as a AD/DC with Exchange 2003,
and IIS6.0. I installed the Certificate Authority services on this server
and issued a certificate. I am using this to enforce the use of SSL for my
Outlook WEB Access users. This is working as expected.

I have a second Windows 2003 Server that is running as a AD/DC and it has
all of the FSMO roles. Both servers are in the same domain. After
installing the CA on the first DC I am now getting the following error in the
event logs for my second DC:
"Automatic certificate enrollment for local system failed to enroll for one
Domain Controller certificate (0x80070005). Access is denied."

I have checked the Group Policy for the Domain Controllers and the
'Autoenrollment Settings Properties' are set to "Enroll certificates
automatically."

I have looked at the Certificate Authority 'Certificate Templates - Manage'
and the "Domain Controller Authentication" is set to 'Allow' for the Windows
2003 Server.

I have seen many posts regarding this issue but I am unable to determine a
solution to this issue. Please let me know your suggested resolution to this
issue.
--
Thanks in advance

westernwind
.



Relevant Pages

  • Site-tosite VPN Issue
    ... Windows Server 2003 domain controller ... Mixture of PCs running Windows 2000 Profressional with SP3 and Windows XP ... the VPN to the Windows Server 2003 domain controller. ... 12.7MB file from the server to the client PC. ...
    (microsoft.public.windows.server.networking)
  • Re: Need help configuring Wireless Connection profile
    ... and I can only use the intel OR windows utility, not both at the same time. ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless WPA2 ... SMALL BUSINESS SERVER: ... STEP #1 Install Certificate Services ...
    (microsoft.public.windowsxp.general)
  • Cannot sync Windows mobile with sbs2003 server
    ... Windows Mobile OS to the SBS2003 server at work so that he can read e-mails. ... What certificate do Microsoft recommend here, and where can this be bought? ...
    (microsoft.public.pocketpc)
  • RE: Internet Connection Wizard failing at Firewall Config and Secu
    ... You can use the Dcdiag.exe (Domain Controller Diagnostic Tool) included ... in Windows Support Tools to verify the AD status. ... Windows Server 2003 Active Directory Diagnostics, ...
    (microsoft.public.windows.server.sbs)
  • RE: Provide feedback to DC promotion/replacement
    ... one of the is reffering to a Windows 2000 ... As i sad in the previous posts, to rename a domain controller ... controllers in the domain must be running Windows Server 2003. ... a global catalog. ...
    (microsoft.public.windows.server.active_directory)

Loading