CA autoenroll not working


hi,

i´m having hard time find solution problem. first of bit background description bigger picture i´m doing.

i have 3 domain controllers: 2x windows server 2003r2 sp2 (ad1, ad2) , 1x windows server 2012 (ad3). pdc , fsmo roles @ windows server 2003r2. migration proccess server 2012 next mission after getting pki work.

i have 3 ca servers: (offline root ca - non-domain; issuing ca - domain, revocation ca/ocsp - domain). server 2012.

the problem autoenroll computer , user turned on , rsop can see gpo working. happening when use gpupdate /force (or restart) no certificate requested. @ same time when i´m using mmc , request certificate manually working , certificate requested. have tried turn off firewalls computers. can´t see denial cisco firewall traffic allowed. client computer have tried certutil -pulse no use. event viewer showing me: 

certificate enrollment domain\user authenticated policy server event id 65
certificate enrollment domain\user load policy policy server event id 64

i have done same thing , policy in many organisations , working charm. don´t undestand wrong or missing. there can monitor wrong.

any appriciated,

taavi

hi!

the problem has found solution! our management team large turned out cisco asa problem. everyhting started work right after cisco asa firmware upgrade done latest version. have 2 other cisco asa firewalls in other location have penultimate firmware version , there autoenrollment not working means must latest 1 work. seems changed in rpc protocol or somewhere else cisco can´t handle if use any-any rules , turn security layers off! checked wireshark , tcp dumps network devices have between machine , servers , turned out cisco asa problem point between machines , servers. lost ca respond packages. though let past request package machine! weird situation , lot of time waste @ last solution in network device :)

hope in future!



Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client