|
| |||||||||
| Tags: 0x800706ba, active directory, certificate, domain certificate, entreprise |
![]() |
| | Thread Tools | Search this Thread |
|
#1
| |||
| |||
| Domain certificate error
Hello, I have installed a entreprise CA on my new domain. I see that all my DC recieved a Domain Controler certificate except one. If I check the log I can see two event : First : Eventid 6 : Automatic certificate enrollment for local system failed (0x800706ba) The RPC server is unavailable. Second : EventID 13 : Certificate enrollment for Local system failed to enroll for a DomainController certificate with request ID N/A from DCSHDCT02.mydomaint.local\mydomain-DCSHDCT02-CA (The RPC server is unavailable. 0x800706ba (WIN32: 1722)). The message seems to be clear, but if i try to do a telnet one DCSHDCT02 I can see a connection! Then, I can say the RPC server is on and working well. Can anybody help me? |
|
#2
| |||
| |||
| Re: Domain certificate error
It's more than just telnet. The RPC server is unavailable message simply means it either cannot fully communicate with the necessary ports to the server, DNS cannot resolve all necessary records (SRV and "A" records), or the server is completely down. Since you can telnet, then it's indicating the server is up but there are possibly some firewall ports blocked. Within a private infrastructure, it is assumed that all ports are allowed and opened between all servers and workstations. I remember you said you 'changed your firewall strategy' in another thread regarding your Sites issues. What exactly is your new strategy? |
|
#3
| |||
| |||
| Re: Domain certificate error
Hi To test do a SMB connection: "\\CAName.yourdomain.tld" from that DC. IF it asks for authentication credentials, you may have a FW issue, name resolution problems (from CA side or DC side). A workaround for this may be to cache the credentials on DC side (using the option save the credentials when you're doing the SMB connection). |
|
#4
| |||
| |||
| Re: Domain certificate error
Ok fist I have block all trafics execpt for AD port. But, I discover that with winsows 2008 r2 Ad need to have a range of port open. Then I open IP communication between all DC! Then, I can say that it's not a problem with my firewall! |
|
#5
| |||
| |||
| Re: Domain certificate error
Hello, You say : > To test do a SMB connection: "\\CAName.yourdomain.tld" from that DC. What is the CAName ? My computer name ? like dcshdct02 ? or the name I can see on the Certification authority MMC? I can browse the CA with the comupter name \\dcshdct02 but not the name I see on the CA MMC. Julien |
|
#6
| |||
| |||
| Re: Domain certificate error
There are numerous ports that AD needs, as you know. Usually we just open it up wide open and let it have everything, otherwise if you try to make port exceptions in a firewall, it turns it into Swiss cheese anyway. Can you post exactly what ports you opened up? Also, if you followed an article on what ports to open, can you post the article you followed? |
|
#7
| |||
| |||
| Re: Domain certificate error
The CAName is the computer name of your CA (Certificate Authority) server. Is dcshdct02 the name of the CA? If so, what do you mean by can't browse by the name in the CA MMC console? what name is that? |
|
#8
| |||
| |||
|
First I have open the port TCP/UDP: 1025 1030 123 135 139 3268 389 445 49155 49159 88 53 750 But now, I have open all TCP/UDP trafic !!!!! In fact, the computer name is dcshdct02, but if I open the certification authority MMC, the name of the server is : mydomain-DCSHDCT02-CA. |
|
#9
| |||
| |||
|
That's good you opened all traffic. There are more ports that are required than you posted. That was why you got the errors. You were missing the Service ports. For more information on ports required, please read the following to understand better what ports AD requires. It's not as simple as the ports you mentioned. That was why I was saying it is easier just to allow ALL ports, for after all, if it is an internal private network, you are safe anyway. Paul Bergson's Blog on AD Replication and Firewall Ports Restricting Active Directory replication traffic and client RPC ....Restricting Active Directory replication traffic and client RPC traffic to a ... unique port, and you restart the Netlogon service on the domain controller. ... http://support.microsoft.com/kb/224196 How to restrict FRS replication traffic to a specific static port - How to restrict FRS replication traffic to a specific static port ... Windows 2000-based domain controllers and servers use FRS to replicate system policy .... http://support.microsoft.com/kb/319553 Network Ports Used by Key Microsoft Server Products - You can also restrict the range of ports that RPC dynamically assigns to a small range, ..... Windows domain controllers use the SMTP service for intersite ... http://www.microsoft.com/smallbusine...s_ms_prod.mspx That appears to be the CA name you gave it, not the computer name. Yes, test the connection using \\dcshdct02 |
|
#10
| |||
| |||
| Re: Domain certificate error
Can you connect to the CA using a browser? If you can, you can request a cert. https://dcshdct02 or http://dcshdct02 Also, you said that you've opened the firewall up wide open, correct? That should have alleviated the RPC errors. However, if it didn't resolve the errors, then something else is going on. It could be using the wrong DNS, multihomed DC (more than one NIC and/or RRAS is installed on a DC) which will cause these problems, too, due to incorrect DNS lookups, which will stop GPOs from applying, among other things. Can you post an ipconfig /all from the DC, as well as any EventID# errors (App, System, FRS, Dir Service logs)? |
|
#11
| |||
| |||
| Re: Domain certificate error
Is the CA service started? Did you test SMB from that DC? IS that DC passing through ISA? IF yes, can you disable the RPC filter for that rule and test again? You may need to reboot the DC twice until that error goes away. |
|
#12
| |||
| |||
| Re: Domain certificate error
This is my ipconfig : ---------------------------------------------------------------------------------------------- ipconfig /all Windows IP Configuration Host Name . . . . . . . . . . . . : DCITDCT01 Primary Dns Suffix . . . . . . . : mydomain.local Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No DNS Suffix Search List. . . . . . : mydomain.local Ethernet adDCter Local Area Connection: Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network Connection Physical Address. . . . . . . . . : 00-0C-29-72-A4-A4 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes IPv4 Address. . . . . . . . . . . : 192.168.11.14(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : 192.168.11.254 DNS Servers . . . . . . . . . . . : 192.168.11.14 192.168.30.2 127.0.0.1 NetBIOS over Tcpip. . . . . . . . : Enabled Tunnel adDCter isatDC.{6DE906DB-E4F6-45A1-A6D3-A5B10F2663BA}: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Microsoft ISATDC AdDCter Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adDCter Local Area Connection* 11: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes ------------------------------------------------------------------------------------------------------------- Here are my application log error : ------------------------------------------------------------------------------------------------------------- Log Name: DCplication Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment Date: 10.02.2010 05:42:07 Event ID: 6 Task Category: None Level: Error Keywords: Classic User: N/A Computer: DCITDCT01.mydomain.local Description: Automatic certificate enrollment for local system failed (0x800706ba) The RPC server is unavailable. .. Event Xml: <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"> <System> <Provider Name="Microsoft-Windows-CertificateServicesClient-AutoEnrollment" Guid="{F0DB7EF8-B6F3-4005-9937-FEB77B9E1B43}" EventSourceName="AutoEnrollment" /> <EventID Qualifiers="16384">6</EventID> <Version>0</Version> <Level>2</Level> <Task>0</Task> <Opcode>0</Opcode> <Keywords>0x80000000000000</Keywords> <TimeCreated SystemTime="2010-02-10T04:42:07.000000000Z" /> <EventRecordID>2334</EventRecordID> <Correlation /> <Execution ProcessID="0" ThreadID="0" /> <Channel>DCplication</Channel> <Computer>DCITDCT01.mydomain.local</Computer> <Security /> </System> <EventData> <Data Name="Context">local system</Data> <Data Name="ErrorCode">0x800706ba</Data> <Data Name="ErrorMsg">The RPC server is unavailable. </Data> </EventData> </Event> Log Name: DCplication Source: Microsoft-Windows-CertificateServicesClient-CertEnroll Date: 10.02.2010 05:42:07 Event ID: 13 Task Category: None Level: Error |
|
#13
| |||
| |||
|
Yes, I did. I test smb connection form and to my dc. No, we don't use ISA! I'll try this, this night, but if I remember well I already reboot it more thant twice. Ok, do that, can you also explain these 2 DNS entries: 192.168.30.2 127.0.0.1 |
|
#14
| |||
| |||
| Re: Domain certificate error
ok simple 127.0.0.1 I have delete ... I don't know why is here. 192.168.30.2 is my central site and my fist DC on my domain. I have a lot of site and this address is the ranch for my central offices. |
|
#15
| |||
| |||
|
Ok, - Did you also test SMB from the CA to the DC? - Can you ping from both sides (DC and CA) to each other? - Did you already reboot the DC 2? Hold on... If you're going to reboot the CA... 1St the CA, after the CA is up, do 2 reboots with a logon between them on the DC. Another thing, please check if you have any thyrd party FW installed on the DC and CA. For instance, some antivirus have additional products that provides FW capabilities. |
![]() |
|
| Thread Tools | Search this Thread |
| |
Similar Threads for: "Domain certificate error" | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Unable to install the security certificate while logged in as a domain user | Harinadhar | Networking & Security | 4 | 23-03-2011 09:16 PM |
| how to distribute/trust a certificate throughout the whole domain | Doug P | Active Directory | 1 | 02-06-2009 06:58 AM |
| Auto enrollment Domain Certificate not working (error 13) | Cristian | Windows Security | 0 | 04-03-2009 07:20 PM |
| Auto enrollment Domain Certificate not working (error 13) | Cristian | Active Directory | 2 | 04-03-2009 07:16 PM |
| How to request multiple domain certificate from local in house CA | Imran | Windows Security | 4 | 11-11-2008 03:35 PM |