newpersn Posted July 24, 2017 Posted July 24, 2017 Since we lost our main PDC (thanks to Ramsonware) we been having random problems with dcs (event log with errors pointing to certificate errors) I noticed we are not running any certificate services roles on any dc. Do I need to re install this roll on our new pdc?
Blue_Cookeh Posted July 24, 2017 Posted July 24, 2017 (edited) You don’t NEED certificate services. You only need it if you’re running your own PKI for internal web services, SCCM, DirectAccess etc. It sounds like you need to clean stale DC entries and seize FSMO roles. FYI there’s no such thing as a PDC anymore. https://www.petri.com/delete_failed_dcs_from_ad https://support.microsoft.com/en-us/help/255504/using-ntdsutil-exe-to-transfer-or-seize-fsmo-roles-to-a-domain-control Edited July 24, 2017 by Blue_Cookeh 2
newpersn Posted July 25, 2017 Author Posted July 25, 2017 What about these in my event viewer? DCOM was unable to communicate with the computer pdc using any of the configured protocols; requested by PID 1f10 (C:\Windows\system32\taskhostw.exe). Certificate enrollment for Local system failed to enroll for a DomainController certificate with request ID N/A from pdc.\ Root Certification Authority (The RPC server is unavailable. 0x800706ba (WIN32: 1722 RPC_S_SERVER_UNAVAILABLE)). Certificate enrollment for Local system failed in authentication to all urls for enrollment server associated with policy id: {C9829EC7-EBCD-456F-8380-346D5A1EABB3} (The RPC server is unavailable. 0x800706ba (WIN32: 1722 RPC_S_SERVER_UNAVAILABLE)). Failed to enroll for template: DomainController Automatic certificate enrollment for local system failed (0x800706ba) The RPC server is unavailable.
Domino Posted July 25, 2017 Posted July 25, 2017 Sounds like you *were* running a certificate server - is there a GPO with certificate auto enrollment settings in?
newpersn Posted July 25, 2017 Author Posted July 25, 2017 Sounds like you *were* running a certificate server - is there a GPO with certificate auto enrollment settings in? Just looked though our default domain policy and yes there is settings for Auto Enrollment (2 certs have expired and 1 is our current ISP filtering)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now