|
| ||||||||||
| Tags: certificate, certificate enrollment, domain controller, local system, sp1, windows 2003 server |
![]() |
| | Thread Tools | Search this Thread |
|
#1
| |||
| |||
| Automatic certificate enrollment for local system failed
But now, after a year, we started getting error on second domain and this occurs every 8 hours. This is what I can see in the event viewer: Quote:
|
|
#2
| |||
| |||
|
Windows 2K3 Server with SP1 has introduces few enhanced default security settings for the DCOM protocol that provides an administrator independent control over local and remote permissions for starting COM servers, activating COM server settings, and accessing COM servers. You can get more info and solutions about this at http://support.microsoft.com/kb/903220/en-us |
|
#3
| |||
| |||
|
Naturally, if I try to add the CERTSVC_DCOM_ACCESS group using the method suggested in the Microsoft KB article (http://support.microsoft.com/kb/903220/en-us): certutil –setreg SetupStatus –SETUP_DCOM_SECURITY_UPDATED_FLAGI get the following error on each DC because I have no certificate services on those or on any other member server: C:\>certutil -setreg SetupStatus -SETUP_DCOM_SECURITY_UPDATED_FLAGEvery post I have read so far seems to assume that those with this problem *have* certificate services installed somewhere and that isn't necessarily true. When Win2003 SP1 is installed, is it supposed to automatically add the CERTSVC_DCOM_ACCESS groupto DCs regardless of whether there are any Cert Servers, or is it a pre-requisite of the service pack that I first have installed a Cert Server? |
|
#4
| |||
| |||
| Re: Automatic certificate enrollment for local system failed
I am receiving a similar error, and also have not installed Certificate Services... is this required.. I would guess if i do not have it (CA) installed I would just communicate with my DC (between DC), non-encrypted. |
![]() |
|
| Thread Tools | Search this Thread |
| |
Similar Threads for: "Automatic certificate enrollment for local system failed" | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Certificate authentication failed error how to fix that | Rounder1 | Networking & Security | 12 | 08-01-2012 11:05 AM |
| Windows 2003 Server CA Problem and Automatic certificate enrollment | pac0124 | Windows Server Help | 5 | 16-08-2011 12:50 PM |
| How to request multiple domain certificate from local in house CA | Saphire | Windows Security | 1 | 11-11-2008 02:35 PM |
| IAS and RAS server certificate enrollment | AngerEyes | Windows Security | 3 | 27-05-2008 11:56 PM |
| Automatic certificate enrollment for local system failed after upgrading member server to domain controller | Arch Willingham | Windows Server Help | 4 | 29-08-2005 02:47 AM |