Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , , , ,

Sponsored Links



Domain certificate error

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 29-01-2010
jithurbide@gmail.com
 
Posts: n/a
Domain certificate error

Hello,

I have installed a entreprise CA on my new domain. I see that all my
DC recieved a Domain Controler certificate except one.

If I check the log I can see two event :

First : Eventid 6 :

Automatic certificate enrollment for local system failed (0x800706ba)
The RPC server is unavailable.

Second : EventID 13 :

Certificate enrollment for Local system failed to enroll for a
DomainController certificate with request ID N/A from
DCSHDCT02.mydomaint.local\mydomain-DCSHDCT02-CA (The RPC server is
unavailable. 0x800706ba (WIN32: 1722)).

The message seems to be clear, but if i try to do a telnet one
DCSHDCT02 I can see a connection! Then, I can say the RPC server is on
and working well.

Can anybody help me?
Reply With Quote
  #2  
Old 29-01-2010
Ace Fekay [MVP-DS, MCT]
 
Posts: n/a
Re: Domain certificate error

It's more than just telnet. The RPC server is unavailable message simply
means it either cannot fully communicate with the necessary ports to the
server, DNS cannot resolve all necessary records (SRV and "A" records), or
the server is completely down. Since you can telnet, then it's indicating
the server is up but there are possibly some firewall ports blocked. Within
a private infrastructure, it is assumed that all ports are allowed and
opened between all servers and workstations.

I remember you said you 'changed your firewall strategy' in another thread
regarding your Sites issues. What exactly is your new strategy?
Reply With Quote
  #3  
Old 31-01-2010
Jorge Silva
 
Posts: n/a
Re: Domain certificate error

Hi
To test do a SMB connection: "\\CAName.yourdomain.tld" from that DC. IF it
asks for authentication credentials, you may have a FW issue, name
resolution problems (from CA side or DC side). A workaround for this may be
to cache the credentials on DC side (using the option save the credentials
when you're doing the SMB connection).
Reply With Quote
  #4  
Old 01-02-2010
Julien
 
Posts: n/a
Re: Domain certificate error

Ok fist I have block all trafics execpt for AD port. But, I discover that
with winsows 2008 r2 Ad need to have a range of port open. Then I open IP
communication between all DC! Then, I can say that it's not a problem with
my firewall!
Reply With Quote
  #5  
Old 01-02-2010
Julien
 
Posts: n/a
Re: Domain certificate error

Hello,

You say :

> To test do a SMB connection: "\\CAName.yourdomain.tld" from that DC.


What is the CAName ? My computer name ? like dcshdct02 ? or the name I can
see on the Certification authority MMC?

I can browse the CA with the comupter name \\dcshdct02 but not the name I
see on the CA MMC.

Julien


Reply With Quote
  #6  
Old 01-02-2010
Ace Fekay [MVP-DS, MCT]
 
Posts: n/a
Re: Domain certificate error

There are numerous ports that AD needs, as you know. Usually we just open it
up wide open and let it have everything, otherwise if you try to make port
exceptions in a firewall, it turns it into Swiss cheese anyway.

Can you post exactly what ports you opened up? Also, if you followed an
article on what ports to open, can you post the article you followed?
Reply With Quote
  #7  
Old 01-02-2010
Ace Fekay [MVP-DS, MCT]
 
Posts: n/a
Re: Domain certificate error

The CAName is the computer name of your CA (Certificate Authority) server.

Is dcshdct02 the name of the CA? If so, what do you mean by can't browse by
the name in the CA MMC console? what name is that?
Reply With Quote
  #8  
Old 02-02-2010
Julien Ithurbide
 
Posts: n/a
First I have open the port TCP/UDP:

1025
1030
123
135
139
3268
389
445
49155
49159
88
53
750

But now, I have open all TCP/UDP trafic !!!!!

In fact, the computer name is dcshdct02, but if I open the certification
authority MMC, the name of the server is : mydomain-DCSHDCT02-CA.
Reply With Quote
  #9  
Old 02-02-2010
Ace Fekay [MVP-DS, MCT]
 
Posts: n/a
That's good you opened all traffic. There are more ports that are required
than you posted. That was why you got the errors. You were missing the
Service ports.

For more information on ports required, please read the following to
understand better what ports AD requires. It's not as simple as the ports
you mentioned. That was why I was saying it is easier just to allow ALL
ports, for after all, if it is an internal private network, you are safe
anyway.

Paul Bergson's Blog on AD Replication and Firewall Ports

Restricting Active Directory replication traffic and client RPC
....Restricting Active Directory replication traffic and client RPC traffic
to a ... unique port, and you restart the Netlogon service on the domain
controller. ...
http://support.microsoft.com/kb/224196

How to restrict FRS replication traffic to a specific static port - How to
restrict FRS replication traffic to a specific static port ... Windows
2000-based domain controllers and servers use FRS to replicate system policy
....
http://support.microsoft.com/kb/319553

Network Ports Used by Key Microsoft Server Products - You can also restrict
the range of ports that RPC dynamically assigns to a small range, .....
Windows domain controllers use the SMTP service for intersite ...
http://www.microsoft.com/smallbusine...s_ms_prod.mspx

That appears to be the CA name you gave it, not the computer name.

Yes, test the connection using \\dcshdct02
Reply With Quote
  #10  
Old 08-02-2010
Ace Fekay [MVP-DS, MCT]
 
Posts: n/a
Re: Domain certificate error

Can you connect to the CA using a browser? If you can, you can request a
cert.

https://dcshdct02
or
http://dcshdct02

Also, you said that you've opened the firewall up wide open, correct? That
should have alleviated the RPC errors. However, if it didn't resolve the
errors, then something else is going on. It could be using the wrong DNS,
multihomed DC (more than one NIC and/or RRAS is installed on a DC) which
will cause these problems, too, due to incorrect DNS lookups, which will
stop GPOs from applying, among other things.

Can you post an ipconfig /all from the DC, as well as any EventID# errors
(App, System, FRS, Dir Service logs)?
Reply With Quote
  #11  
Old 10-02-2010
Jorge Silva
 
Posts: n/a
Re: Domain certificate error

Is the CA service started?
Did you test SMB from that DC?
IS that DC passing through ISA? IF yes, can you disable the RPC filter for
that rule and test again? You may need to reboot the DC twice until that
error goes away.
Reply With Quote
  #12  
Old 10-02-2010
Julien Ithurbide
 
Posts: n/a
Re: Domain certificate error

This is my ipconfig :

----------------------------------------------------------------------------------------------

ipconfig /all

Windows IP Configuration

Host Name . . . . . . . . . . . . : DCITDCT01
Primary Dns Suffix . . . . . . . : mydomain.local
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : mydomain.local

Ethernet adDCter Local Area Connection:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network
Connection
Physical Address. . . . . . . . . : 00-0C-29-72-A4-A4
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv4 Address. . . . . . . . . . . : 192.168.11.14(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.11.254
DNS Servers . . . . . . . . . . . : 192.168.11.14
192.168.30.2
127.0.0.1
NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adDCter isatDC.{6DE906DB-E4F6-45A1-A6D3-A5B10F2663BA}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATDC AdDCter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adDCter Local Area Connection* 11:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

-------------------------------------------------------------------------------------------------------------

Here are my application log error :

-------------------------------------------------------------------------------------------------------------

Log Name: DCplication
Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Date: 10.02.2010 05:42:07
Event ID: 6
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: DCITDCT01.mydomain.local
Description:
Automatic certificate enrollment for local system failed (0x800706ba) The
RPC server is unavailable.
..
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider
Name="Microsoft-Windows-CertificateServicesClient-AutoEnrollment"
Guid="{F0DB7EF8-B6F3-4005-9937-FEB77B9E1B43}"
EventSourceName="AutoEnrollment" />
<EventID Qualifiers="16384">6</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2010-02-10T04:42:07.000000000Z" />
<EventRecordID>2334</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>DCplication</Channel>
<Computer>DCITDCT01.mydomain.local</Computer>
<Security />
</System>
<EventData>
<Data Name="Context">local system</Data>
<Data Name="ErrorCode">0x800706ba</Data>
<Data Name="ErrorMsg">The RPC server is unavailable.
</Data>
</EventData>
</Event>

Log Name: DCplication
Source: Microsoft-Windows-CertificateServicesClient-CertEnroll
Date: 10.02.2010 05:42:07
Event ID: 13
Task Category: None
Level: Error
Reply With Quote
  #13  
Old 10-02-2010
Julien Ithurbide
 
Posts: n/a
Yes, I did. I test smb connection form and to my dc.

No, we don't use ISA!

I'll try this, this night, but if I remember well I already reboot it more
thant twice.

Ok, do that, can you also explain these 2 DNS entries:
192.168.30.2
127.0.0.1
Reply With Quote
  #14  
Old 10-02-2010
Julien Ithurbide
 
Posts: n/a
Re: Domain certificate error

ok simple 127.0.0.1 I have delete ... I don't know why is here.

192.168.30.2 is my central site and my fist DC on my domain.

I have a lot of site and this address is the ranch for my central offices.
Reply With Quote
  #15  
Old 11-02-2010
Jorge Silva
 
Posts: n/a
Ok,
- Did you also test SMB from the CA to the DC?
- Can you ping from both sides (DC and CA) to each other?
- Did you already reboot the DC 2?

Hold on...
If you're going to reboot the CA...
1St the CA, after the CA is up, do 2 reboots with a logon between them on
the DC.

Another thing, please check if you have any thyrd party FW installed on the
DC and CA. For instance, some antivirus have additional products that
provides FW capabilities.
Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Domain certificate error"
Thread Thread Starter Forum Replies Last Post
Unable to install the security certificate while logged in as a domain user Harinadhar Networking & Security 4 23-03-2011 09:16 PM
how to distribute/trust a certificate throughout the whole domain Doug P Active Directory 1 02-06-2009 06:58 AM
Auto enrollment Domain Certificate not working (error 13) Cristian Windows Security 0 04-03-2009 07:20 PM
Auto enrollment Domain Certificate not working (error 13) Cristian Active Directory 2 04-03-2009 07:16 PM
How to request multiple domain certificate from local in house CA Imran Windows Security 4 11-11-2008 03:35 PM


All times are GMT +5.5. The time now is 10:42 PM.