Jump to content

Recommended Posts

Posted

We have installed a 2008 r2 server as CA in our domain, and are having problems issuing certificates to our 2003 domain controllers.

 

The root certificate is fine, everyone gets it. But the computer certificate for domain controllers is a whole other story.

 

On our 2008 domain controllers, i can use the wizard when adding certificates in mmc, and request from there. Then the certificate for the DC is issued correctly, and placed correctly.

 

But this option does not work on our 2003 domain controllers, i get the error:

 

The wizard cannot be started because of one or more of the following reasons:

- There are no trusted certification authorities (CAs) available.

- You do not have the permissions to request certificates from the available CAs.

- The available CAs issue certificates for wich you do not have permission.

 

I have checked everything i can think of, and can't find anything wrong. Besides, would i not get the same error on our 2008 DCs if there wasn't any CAs available or there was something wrong with the permissions?

 

If i use Web enrollment, it doesn't work at all, on both 2008 and 2003. I can create a certificate request, and select "domain controller" for the template. But the thing puts the certificate in the personal user store, not in the computer store. And the static information when looking at the details for the certificate is different than the certificate that was issued to a 2008 DC with the wizard. It's like the server issues different certificates through different templates, when all i'm using is the default template.

 

Excuse me for sounding like a total newbie at this, but i am. I just got this task thrown at me, with the order to make it work, because no one else dared to touch our old CA who was failing. Only problem is that my level of skill in this particular field is more or less none :p

 

Please ask if you are wondering about anything, and i'll try to provide as much information as possible. I am desperate to make this work!

  • 2 weeks later...
Posted

Ok, firstly, as you say AD CS isn't something to be taken lightly and needs a good amount of planning to ensure that everything works as it should.

 

In you case I'm going to guess that your CA doesn't currently have the certificates configured for use with 2003. This is because Windows Vista/2008 and later use a newer version of the certificate templates.

 

You will need to go into your CA and either enable or configure a certificate template based on Version 2 for use with Windows Server 2003 and Windows XP. I've not got a CA I can connect to at the moment to give exact details on how to accomplish this but if you don't find it let me know and I'll dig out a guide for you.

Posted
Ok, firstly, as you say AD CS isn't something to be taken lightly and needs a good amount of planning to ensure that everything works as it should.

 

In you case I'm going to guess that your CA doesn't currently have the certificates configured for use with 2003. This is because Windows Vista/2008 and later use a newer version of the certificate templates.

 

You will need to go into your CA and either enable or configure a certificate template based on Version 2 for use with Windows Server 2003 and Windows XP. I've not got a CA I can connect to at the moment to give exact details on how to accomplish this but if you don't find it let me know and I'll dig out a guide for you.

 

Thanks for the reply! After i posted my thread, i managed to google myself to the answer you gave here. Seems like it's only the DC template that doesn't work in 2003. A regular computer certificate from the CA installs just fine on 2003 and xp.

 

If i choose manage on my templates folder i get a list of already ready templates to use. Is it not possible to create a new template from scratch? There is another DC template already there, wich is possible to edit. But i can't get it to show on the list of templates i'm able to issue, why is that?

Posted

Just to throw another thing into the mix, I had the same issue a couple of weeks ago and it was a permissions issue.

 

You need to make sure that the AD security group CERTSRV_DCOM_ACCESS has the following members: Domain users, Domain Computers, and Domain Controllers. The DC group is not always a member so won't hae permission to get the certificate.

Posted
Just to throw another thing into the mix, I had the same issue a couple of weeks ago and it was a permissions issue.

 

You need to make sure that the AD security group CERTSRV_DCOM_ACCESS has the following members: Domain users, Domain Computers, and Domain Controllers. The DC group is not always a member so won't hae permission to get the certificate.

 

Aye, i did check this, and the groups were missing. But i have added them.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...