Subordinate CAs issuing multiple certificates through auto-enrollment


i have offline root ca; , 2 subordinate cas (one in hq , 1 in dr) both running , active services installed directly on them.

i have configured group policy auto-enroll using these 2 servers; , have configured 2003 certificate template (copy of computer template) client authentication used wireless access.

when apply policy, find computers enrolling mutliple times in "issued certificates" store; in local store see 1 certificate; , have enabled in template feature "do not automatically reenroll if duplicate certificate exists in active directory" some how has not prevented re-enrolling , disaster both sub-cas re-enrolling each computer, computer getting 1 certificate each subordinate ca.

this urgent, ideas helpful


+--+--+--+--+--+--+--+--+--+--+ hany elkady infrastructure consultant +--+--+--+--+--+--+--+--+--+--+


ok, have figured out. searches in future...

  1. windows xp incompatible windows 2008 r2 gpos , breaks lots of things if gpo created 2008 r2 if forest 2008 or 2003
  2. windows xp needs hotfix allow enrol 2003/2008 templates (i.e. version 2 & 3) if hotfix not installed, facing above; computer enrolles in 1 subca , not able save certificate because doesn't understand hash algorithim; requests second subca, , same thing happens again. next time user logs in or pulse happen, same process repeated. along subcas have been issuing certificates no problems computer has not been reading them.
  3. i have not enabled again ad checking or saving, , have wait until deploy hotfix through sccm first before can that; in meantime, have created 2 group policies, 1 allowing windows vista & 7 machines autoenroll normal 2003 certs; , other xp machines allow them pick standard computer certificate.

n.b. looking again, hotfix xp , 2003 machines can found @ kb968730


+--+--+--+--+--+--+--+--+--+--+ hany elkady infrastructure consultant +--+--+--+--+--+--+--+--+--+--+



Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client