Jump to content

Recommended Posts

Posted

I upgraded our DC from 2003 to 2008 during summer (32bit, getting replaced next summer) and since then I've been getting CertificateServicesClient-AutoEnrollment errors in the Event Log (Event ID 64) with the following text: Certificate for local system with Thumbprint [40 digit hex thumbprint] is about to expire or already expired.. I followed the instructions to resolve the error here: Event ID 64 — AD CS Certification Authority Certificate and Chain Validation and found that the certificate in question had expired over 3 years ago:

Capture 1.JPG

 

The certificate has a parent TRCA certificate that expired back in April:

 

Capture 2.JPG

 

Whe I try to renew the child certificate I get the following error:

 

Capture 3.JPG

 

I then went to Server Manager > Roles and found that Active Directory Certificate Services is not installed. My question is this, If I add the ADCS role to the server will it pick up the existing certificates or will it get rid of them all? This is the screen on which I decided I'd better ask for help:

 

Capture 4.JPG

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...