Server 2012 R2 - "Cross forest enrollment is not enabled"


hi,

i trying issue certificates forest, following guides microsoft. have 2 way trust between domains, , running on server 2012 r2 (and functional levels 2012 r2 well). however, certificate requests denied error "denied policy module 0x8007202b, requester's active directory object not in current forest. cross forest enrollment not enabled".

how enable it? according research, should on default (and can't turn off matter) in version of 2012 r2 (using standard).

thanks,

elizabeth.

it not on default.

please check whitepaper details:

https://technet.microsoft.com/en-us/library/ff955845(v=ws.10).aspx

you have missed:

- ldap referrals

- publication of ca certificates in resource forest

- inclusion of issuing ca computer accounts in cert publishers group

- verification urls in cdp/aia accessible resource forest

- permissions configured enable read , enroll permissions groups in resource forest

brian



Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client