Server 2012 R2 - "Cross forest enrollment is not enabled"
hi,
i trying issue certificates forest, following guides microsoft. have 2 way trust between domains, , running on server 2012 r2 (and functional levels 2012 r2 well). however, certificate requests denied error "denied policy module 0x8007202b, requester's active directory object not in current forest. cross forest enrollment not enabled".
how enable it? according research, should on default (and can't turn off matter) in version of 2012 r2 (using standard).
thanks,
elizabeth.
it not on default.
please check whitepaper details:
https://technet.microsoft.com/en-us/library/ff955845(v=ws.10).aspx
you have missed:
- ldap referrals
- publication of ca certificates in resource forest
- inclusion of issuing ca computer accounts in cert publishers group
- verification urls in cdp/aia accessible resource forest
- permissions configured enable read , enroll permissions groups in resource forest
brian
Windows Server > Security
Comments
Post a Comment