Certificate Authority -Issuing CA gives error Operation Aborted 0x80004004


i have offline root ca, , issuing ca. on issuing ca run command prompt:

certutil -url "http://mypki.domain.com/pki/caroot-caissue-ca.crl

it opens url retrieval tool , says crls cdp failed.

i have checked permissions , correct.

ocsp failed, , aia fails.

base crl , delta crl state "ok"

the caroot-caissue-ca.crl @ url, caroot-caissue-ca+.crl not.

when try publish crl it says "the user name or password incorrent. 0x8007052e (win32:1326 error_logon_failure)

when try publish delta crl , says "operation aborted 0x80004004 (22147467260 e_abort)"

in event viewer, see event 4625 when attempted, subject blank, account name name of server$, logon type 3 , status 0xc000006d sub status 0x0. security id: null sid

i have reset domain membership, synced fine seems. authentication package ntlm.. source port 49376, nothing else showing on event.


david baur

hi,

》》when try to publish crl it says "the user name or password incorrent. 0x8007052e (win32:1326 error_logon_failure)

when try to publish delta crl , says "operation aborted 0x80004004 (22147467260 e_abort)"

according error message,please check permission publishing crl , network connectivity file location,you follow these steps:

confirm active directory crl distribution point permissions

confirm active directory crl distribution point permissions:

  1. on computer has active directory management tools installed, click start, point to administrative tools, , click active directory sites , services.
  2. on the view menu, click show services node.
  3. double-click services, , double-click public key services.
  4. right-click aia, , click properties.
  5. click the security tab, , confirm the ca has write permission location.

confirm file location crl distribution point permissions

confirm file location crl distribution point permissions:

  1. click start, type file share address using publish crls , press enter.
  2. right-click the file share, , click properties.
  3. click the security tab, , confirm the ca has write permission location.

check network connectivity

determine if there network connectivity problem between ca , domain controller:

  1. open command prompt window on computer hosting ca.
  2. type ping <server_fqdn> and press enter, where server_fqdn is qualified domain name (fqdn) of domain controller. 
  3. at command prompt, type ping <ip_address>, where <ip_address> is ip address of domain controller, , press enter.
  4. if can connect domain controller ip address not fqdn, indicates possible issue domain name system (dns) host name resolution.
  5. if cannot connect domain controller ip address, indicates possible issue network connectivity. check , resolve hardware problems, such malfunctioning network card or disconnected network cable, event log errors relating firewall configuration internet protocol security (ipsec) configuration.


confirm validity of configured crl distribution points

confirm validity of configured crl distribution points:

  1. click start, point to administrative tools, , click certification authority.
  2. right-click name of ca, , click properties.
  3. click the extensions tab. note crl distribution point locations which the publish crls location check box selected.

can determine configured crl distribution point urls opening command prompt window on ca and running following command: certutil -getreg ca\crlpublicationurls.


best regards
cartman
please remember mark replies answers if help. if have feedback technet subscriber support, contact tnmff@microsoft.com




Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client