Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

AutoEnrollment

Posted on 2007-10-11
7
Medium Priority
?
528 Views
Last Modified: 2008-10-05
I am recieving the following error on one of our domain controllers "Automatic certificate enrollment for local system failed to enroll for one Domain Controller certificate (0x80070005).  Access is denied." . As well if i try to open the Domain Security Policy, or Domain Controller security policy  i get the following Error Message."Failed to open group policy object. You may not have approperiate Rights". Any idea about this error and how to resolve them. i have another domain controller for the same domain and these errors do not show there.
0
Comment
Question by:Mohbakri
  • 3
  • 2
5 Comments
 
LVL 4

Expert Comment

by:DeanC30
ID: 20054987
You need to add the DC to the CERTSVC_DCOM_ACCESS group
0
 

Author Comment

by:Mohbakri
ID: 20055332
already done, but the error is still there.
0
 
LVL 4

Expert Comment

by:DeanC30
ID: 20055561
Have you rebooted the server after adding to group?
0
 

Author Comment

by:Mohbakri
ID: 20055564
ya.
0
 
LVL 4

Accepted Solution

by:
DeanC30 earned 2000 total points
ID: 20064320
From: http://support.microsoft.com/kb/294257

Group Policy Error:
Failed to open the Group Policy Object. You may not have appropriate rights.
CAUSE
This issue may occur if either of the following conditions exist: " The Domain Administrators group has been denied access to the GPO.  
" The primary domain controller (PDC) operations master (also known as flexible single master operations or FSMO) of your Windows 2000 domain is down

If you have a FSMO failure for Infrastructure master, this may explain why the DC is receiving the auto enroll error, even though you have 'added' it to the group.

Could you run a dcdiag from the DC and post results,

Cheers

Dean
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Numerous times I have been asked this questions that what is it that makes my machine log on so slow, there have been cases where computers took 23 minute exactly after taking password and getting to the desktop. Interesting thing was the fact th…
Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
This Micro Tutorial will teach you how to add a cinematic look to any film or video out there. There are very few simple steps that you will follow to do so. This will be demonstrated using Adobe Premiere Pro CS6.
Whether it be Exchange Server Crash Issues, Dirty Shutdown Errors or Failed to mount error, Stellar Phoenix Mailbox Exchange Recovery has always got your back. With the help of its easy to understand user interface and 3 simple steps recovery proced…

564 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question