Cant request certificate on 2008 r2 domain controller through MMC


i added 2 domain controllers new child domain.  both 2008r2 , built using same automated build.   1 dc able access certificate enrollment policy through certificate mmc, pick domain controller template, , install domain controller cert.

when attempt same procedure on other server, see the  same enrollment policy listed, when choose next view available templates "enrollment error". "the specified network password not correct".  

i couple of stored events in application log

_____________________________________________________________________________________

certificate enrollment local system failed load policy policy servers id  {2194c258-e9fd-4265-80c3-415e2ba41553} (the specified network password not correct. 0x80070056 (win32: 86))

certificate enrollment local system failed because no valid policy can obtained policy servers id{2194c258-e9fd-4265-80c3-415e2ba41553}

______________________________________________________________________________________

when enter certutil -pulse get

______________________________________________________________________________________

certificate enrollment local system authenticated policy server {2194c258-e9fd-4265-80c3-415e2ba41553}

certificate enrollment local system load policy policy server {2194c258-e9fd-4265-80c3-415e2ba41553}

______________________________________________________________________________________

i have verified dc can ping ca. 

i have downloaded , ran dtcping validate dcom connection good

i have verified dc has root ca in trusted root, , subordinate in intermediate cas

when visually compare certs in trusted root , intermediate ca between 2 dcs, identical.   but, when compare using certutil -enterprise -viewstore root  dont see enterprise ca hosting template.

does have idea why im getting different results trying certutil -enterprise -viewstore root ?

thanks

i unable identify , resolve issue build.   demoted dc , rebuilt using same automated build.  issue resolved rebuild.

thanks suggestions



Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client