Certificate Request Problem

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



I am attempting to implement L2TP VPN services on our SBS2K3 network,
but having difficulty requesting computer certificates on the clients.

So far, I have successfully installed Certificate Services on the
server and created an enteprise root CA, and created a domain
controller certificate. On each client I have created an MMC console
for both Certificates (Local Computer) and Certificates (Current User).

Whenever I attempt to create a new computer certificate on a client, I
encounter the error "The certificate request failed. The RPC server is
unavailable". This is accompanied by a 10009 event in the client event
log, stating "DCOM was unable to communicate with the computer
<servername>.<domain> using any of the configured protocols".

On the server, I can see ISA 2004 reporting connections opening and
closing apparently normally, so I suspect it is not a firewall issue.
However, I see 3 events in the server's event log corresponding to each
certificate request, all of which are ID 537 describing a logon failure
for the client computer with:

Reason: "An error occurred during logon"
User name: <computer name>
Domain: <domain name>
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name: -
Status Code: 0xC00002EE
Substatus Code: 0x0

Can anyone shed any light on why this is happening, and how to resolve
it?

Strangely, I can request a *user* certificate without problem on any
client.

Server is SBS2K3 + SP1, with ISA 2004 + SP2.

--
Regards,
Steve.
.



Relevant Pages

  • RE: Unable to unwrap a symmetric key using the private key of an X.509
    ... When I create my own certificate and install it in the stores, ... my client application that is consuming my WSE enabled webservice receives ... <request signatureOptions="IncludeAddressing, IncludeTimestamp, ... <response signatureOptions="IncludeAddressing, IncludeTimestamp, ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: Unable to authenticate via kerberos to IIS site accepting clie
    ... the dialog for selecting a certificate, IE accesses the page with integrated ... authenticated user" have no relation to the size of the request. ... Client Certificates are negotiated before server even sees the data, ... and Kerberos protocol of Integrated Authentication can affect the size ...
    (microsoft.public.inetserver.iis.security)
  • Re: Checkpoint smart defance as IPS
    ... *any* SSL/TLS communication without tampering anything on the client ... website a client visits on-the-fly. ... don't have private key for the certificate on that website. ...
    (Security-Basics)
  • Re: Windows 2003 + Certificate Store + AcquireCredentialsHandle + SEC_E_UNKNOWN_CREDENTIALS
    ... >The client sends a PKCS#10 request to the CA. ... >certificate, such as the subject name, any extensions, and the public key. ... the client, before the client sends the request to the CA. ...
    (microsoft.public.platformsdk.security)
  • Re: CERTCA Web Sote Broken!
    ... If you apply hotfix Q323172 to both your client and CA web site, ... > certificate on my IIS server and encountered an infinite loop of page ... Click advanced certificate request ... After you have completed filling in your personal data, ...
    (microsoft.public.win2000.security)