Jump to content

Recommended Posts

Posted

Hi all,

 

I'm getting a lot of these in my event logs;

 

Certificate enrollment for Local system failed to enroll for a DomainController certificate with request ID N/A from DHS-CORE.debenham-cc3.internal\debenham-cc3-DHS-CORE-CA (The RPC server is unavailable. 0x800706ba (WIN32: 1722 RPC_S_SERVER_UNAVAILABLE)).

 

I'm new to the school (it's always fun starting at a new place and finding the hidden messes in the background) and DHS-CORE doesn't exist as a server. I've never done anything with Certificate servers before so I don't really know too much about what does and doesn't need to be done. I've installed the Certification Authority role on another server, and now when running the Enterprise PKI snap in, I can see DHS-CORE all over the place in it. Do I simply delete references to it or do I need to setup another one first? Could I already have another one on the network somewhere and how would I know?

 

Thanks for anything.

 

Stuart

Posted (edited)

It sounds to me like someone setup DHS-CORE as a Certificate Authority, then decided to remove the role/server without properly cleaning all the references out of AD.

 

You'll need to go through your Active Directory schema and remove any references to DHS-CORE. See this guide on how to go about it, it's still relevant for 2008/2012: https://support.microsoft.com/en-us/kb/889250

 

You'd know if you had another CA, since there would be references to it all over AD like this one. Can I also suggest that if you're going to be setting up a new CA yourself, you do your research and properly plan it? Many people just go around sticking a CA on a DC and call it a day, when in actual fact you should be looking at offline Root CAs and things to keep it secure.

Edited by Blue_Cookeh
  • Thanks 1
Posted
It sounds to me like someone setup DHS-CORE as a Certificate Authority, then decided to remove the role/server without properly cleaning all the references out of AD.

 

I suspect they simply turned the server off and binned it without removing any roles.

 

You'll need to go through your Active Directory schema and remove any references to DHS-CORE. See this guide on how to go about it, it's still relevant for 2008/2012: https://support.microsoft.com/en-us/kb/889250

 

Can this potentially break anything? Or not as the server is off so it's already as broken as it's going to get?

 

You'd know if you had another CA, since there would be references to it all over AD like this one. Can I also suggest that if you're going to be setting up a new CA yourself, you do your research and properly plan it? Many people just go around sticking a CA on a DC and call it a day, when in actual fact you should be looking at offline Root CAs and things to keep it secure.

 

There are no references to any other servers, just a load of certificates with our school's name on from RM. The school was CC3 until a few years ago.

 

I've had a look around as to how to do it properly and it's a minefield! There's so much out there making it look very complicated and scary. Glad I've got the holidays to get it sorted.

 

Thank you for replying.

 

Stuart

Posted (edited)

If the server doesn't exist anymore, and there isn't a CA running the old one from DHS-CORE then it's unlikely to break anything as you said, AD is simply trying to refer machines to a CA that doesn't exist anymore. I've gone through the process to forcefully clean out a CA before and it didn't take too long, and nothing broke.

 

Not my fault yada yada yada if it breaks blah blah blah :p

Edited by Blue_Cookeh
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...