Hello,

I've just installed our first Enterprise Root CA on one of our DC's running
W2K3 Standard SP2. On another DC I'm trying to request a computer
certificate, but am having trouble. When I go to the web page to request an
advanced cert I am given the option of Administrator/Basic EFS/EFS Recovery
Agent/User/Subordinate CA/Web Server. Am I missing something? I need a
computer certificate becuase this DC is also my RADIUS server and I need a
cert inorder to setup PEAP.

Thanks!

RE: Certificate Help by heath

heath
Wed Jul 09 13:32:04 PDT 2008

Just tried requesting a computer certificate from a domain member server
through the MMC and it worked no problem. When I try this same process from
the other DC I select to request a Domain Controller certificate but am
presented with an error at the end of the wizard...

The request failed because of one of the following conditions....
-The certificate request was submitted to a CA that is not started
-You do not have the permissions to request certificates from the available
CA's

I'm logged on as a user with domain admin and enterprise admin privledges.




"doubleH" wrote:

> Hello,
>
> I've just installed our first Enterprise Root CA on one of our DC's running
> W2K3 Standard SP2. On another DC I'm trying to request a computer
> certificate, but am having trouble. When I go to the web page to request an
> advanced cert I am given the option of Administrator/Basic EFS/EFS Recovery
> Agent/User/Subordinate CA/Web Server. Am I missing something? I need a
> computer certificate becuase this DC is also my RADIUS server and I need a
> cert inorder to setup PEAP.
>
> Thanks!

RE: Certificate Help by v-mileli

v-mileli
Thu Jul 10 03:21:00 PDT 2008

Hello,

Thanks for your post.

To get things clear in my head, please answer the following question:

1. On the DC that encountered the error, can you request any other
certificates successfully such as a user certificate via MMC?


If you receive the same error just like the one when you request the Domain
Controller, you can refer to the following troubleshooting steps:

1. Check DCOM configuration on the CA through running "DCOMCNFG" in the
command prompt. Right Click Component Services ---> Computers ---> My
Computer ---> Properties and check whether "Enable Distributed COM on this
computer" is selected in the Default Properties tab


2. There is a group that is created called CERTSVC_DCOM_ACCESS. Checked in
AD Users and Computers to verify that the members are Domain Users, Domain
Computers.

927066 Error message when a client computer requests a certificate
from a computer that is running Windows Server 2003 with Service Pack 1:
"The wizard cannot be started because of one or more of the following
conditions"
http://support.microsoft.com/kb/927066


3. Ensure the Domain Controllers group and Domain Admins group have the
read and enroll permissions on the Domain Controller template.

For your reference:

889101 Release notes for Windows Server 2003 Service Pack 1--->
Certificate Services: Effects of security enhancements to the DCOM protocol
http://support.microsoft.com/kb/889101

Hope it helps.


Sincerely,
Miles Li

Microsoft Online Partner Support
Microsoft Global Technical Support Center

Get Secure! - www.microsoft.com/security
=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.


RE: Certificate Help by heath

heath
Thu Jul 10 10:02:04 PDT 2008

All i had to do was put the Domain Controllers group inside the
CERTSVC_DCOM_ACCESS group and reboot the domain controller...

http://support.microsoft.com/kb/903220/en-us

Thanks


"Miles Li [MSFT]" wrote:

> Hello,
>
> Thanks for your post.
>
> To get things clear in my head, please answer the following question:
>
> 1. On the DC that encountered the error, can you request any other
> certificates successfully such as a user certificate via MMC?
>
>
> If you receive the same error just like the one when you request the Domain
> Controller, you can refer to the following troubleshooting steps:
>
> 1. Check DCOM configuration on the CA through running "DCOMCNFG" in the
> command prompt. Right Click Component Services ---> Computers ---> My
> Computer ---> Properties and check whether "Enable Distributed COM on this
> computer" is selected in the Default Properties tab
>
>
> 2. There is a group that is created called CERTSVC_DCOM_ACCESS. Checked in
> AD Users and Computers to verify that the members are Domain Users, Domain
> Computers.
>
> 927066 Error message when a client computer requests a certificate
> from a computer that is running Windows Server 2003 with Service Pack 1:
> "The wizard cannot be started because of one or more of the following
> conditions"
> http://support.microsoft.com/kb/927066
>
>
> 3. Ensure the Domain Controllers group and Domain Admins group have the
> read and enroll p