Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Certificate service will not stay started for Windows 2003 Server

Posted on 2008-10-23
7
Medium Priority
?
14,409 Views
Last Modified: 2010-06-30
I have a Windows 2003 server that is running Certificate services. I recently renewed the certificate. The CertSvc will not stay started. I can start the service without an error but when I refresh the page the service is stopped again. I receive the following logs:

Event Type:      Error
Event Source:      CertSvc
Event Category:      None
Event ID:      58
Date:            10/23/2008
Time:            10:04:03 AM
User:            N/A
Computer:      EXCHANGE01
Description:
A certificate in the chain for CA certificate 0 for  has expired.  A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. 0x800b0101 (-2146762495).

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Event Type:      Error
Event Source:      CertSvc
Event Category:      None
Event ID:      100
Date:            10/23/2008
Time:            10:04:03 AM
User:            N/A
Computer:      EXCHANGE01
Description:
Certificate Services did not start: Could not load or verify the current CA certificate.  A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. 0x800b0101 (-2146762495).

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Event Type:      Error
Event Source:      Service Control Manager
Event Category:      None
Event ID:      7024
Date:            10/23/2008
Time:            10:06:28 AM
User:            N/A
Computer:      EXCHANGE01
Description:
The Certificate Services service terminated with service-specific error 2148204801 (0x800B0101).

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Any help would be appreciated.
0
Comment
Question by:robertsgroup33
  • 4
  • 3
7 Comments
 
LVL 15

Accepted Solution

by:
pcsmitpra earned 2000 total points
ID: 22786388
You have to renew CA certificate. go ahead.
0
 

Author Comment

by:robertsgroup33
ID: 22786405
I have already done that.
0
 
LVL 15

Expert Comment

by:pcsmitpra
ID: 22786677
Did you check the CA's root signing certificate? (and all the other certificates up the signing chain?)
Try to identify by modifying the following error details with yours:
C:\>certutil -error 2148204801 0x800b0101 (-2146762495) -- 2148204801 (-2146762495)


0
Get your Conversational Ransomware Defense e‑book

This e-book gives you an insight into the ransomware threat and reviews the fundamentals of top-notch ransomware preparedness and recovery. To help you protect yourself and your organization. The initial infection may be inevitable, so the best protection is to be fully prepared.

 

Author Comment

by:robertsgroup33
ID: 22786834
This is what I get.

C:\>certutil -error 2148204801
0x800b0101 (-2146762495) -- 2148204801 (-2146762495)
Error message text: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file
.
CertUtil: -error command completed successfully.
0
 
LVL 15

Expert Comment

by:pcsmitpra
ID: 22787040
It makes sure, one or more certificate has been expired.  You may find that now. and need to replace same.
0
 

Author Comment

by:robertsgroup33
ID: 22787114
I have renewed all certs.
0
 

Author Comment

by:robertsgroup33
ID: 22787682
I renewed the cert again in the CA snap in and it looks like its working now.
0

Featured Post

Fill in the form and get your FREE NFR key NOW!

Veeam is happy to provide a FREE NFR server license to certified engineers, trainers, and bloggers.  It allows for the non‑production use of Veeam Agent for Microsoft Windows. This license is valid for five workstations and two servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Want to know how to use Exchange Server Eseutil command? Go through this article as it gives you the know-how.
On September 18, Experts Exchange launched the first installment of the Help Bell, a new feature for Premium Members, Team Accounts, and Qualified Experts. The Help Bell will serve as an additional tool to help teams increase question visibility.
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…
Suggested Courses

879 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question