Results 1 to 4 of 4

Thread: Enterprise Root Certification Authority not trusted

  1. #1
    Join Date
    Jan 2006
    Posts
    181

    Enterprise Root Certification Authority not trusted

    I have Windos 2000 active directory domain in which I have installed Enterprise Subordinate CA and Enterprise Root on Windows server 2003. But the problem is with the enterprise root certificate which is not able to publish in the active directory as some client machines are getting SSL warning "the certificate cannot be verified up to a trusted certification authority". If i check the certification path then the root certificate is showing a red X and the status is "This CA Root certificate is not trusted because it is not in the Trusted Root Certification Authorities store." The option to "send request immediately to an online certification authority" is also grayed out in IIS. When I checked the application log then it was showing some warning which is listed below:

    Event ID: 103
    Source: CertSvc
    Description: Certificate Services temporarily added the root certificate of certificate chain 0 to the downloaded Enterprise Root store. If this problem persists, publishing the root certificate to the Active Directory may be necessary.

    Event ID: 103
    Source: CertSvc
    Description: Certificate Services could not publish a Certificate for request 2 to the following location on server dc1.channeladvisor.com: CN=DC ,OU=Domain Controllers,DC=mydomain,DC=com. Insufficient access rights to perform the operation. 0x80072098 (WIN32: 8344). ldap: 0x32: 00002098: SecErr: DSID-03150646, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0.

    Any suggestions appreciated.

  2. #2
    Join Date
    Feb 2006
    Posts
    185

    Re: Enterprise Root Certification Authority not trusted

    Can you try to manually add the certificate or you could also try to use GPO to distribute it to solve the issue.

  3. #3
    Join Date
    Jan 2006
    Posts
    181

    Re: Enterprise Root Certification Authority not trusted

    I have already added the root certificate to the "Public Key Policies/Trusted Root Certification Authorities" GPO which is for the domain and it has solved the issue for me. Thanks for the suggestions. But I am still just wondering why Active Directory did not pblish the new CA as trusted automatically?

  4. #4
    Join Date
    Feb 2006
    Posts
    185

    Re: Enterprise Root Certification Authority not trusted

    I think that it should work but in some cases it would not because of some glitch at the time of process. I think that sometimes it is difficult to say that without full admin access to your system and ability to reproduce the problem lies where excatly.

Similar Threads

  1. Replies: 4
    Last Post: 07-04-2011, 10:16 AM
  2. Trusted Root Certification Authorities
    By Gerardo in forum Windows Vista Network
    Replies: 6
    Last Post: 04-08-2009, 03:58 PM
  3. Replies: 2
    Last Post: 05-03-2009, 05:12 AM
  4. Certificate Authority Not Trusted
    By Mintoo in forum Active Directory
    Replies: 3
    Last Post: 15-07-2008, 02:10 PM
  5. Certification Authority
    By timB in forum Windows Server Help
    Replies: 8
    Last Post: 14-09-2007, 01:23 AM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,516,718.93818 seconds with 17 queries