Solved

Automatic Certificate Enrollment Failed

Posted on 2009-03-30
6
704 Views
Last Modified: 2012-05-06
I seeing the following event in a number of our DC"s:

Event Type:      Error
Event Source:      AutoEnrollment
Event Category:      None
Event ID:      13
Date:            3/30/2009
Time:            3:02:39 AM
User:            N/A
Computer:      STERLINGPDC
Description:
Automatic certificate enrollment for local system failed to enroll for one Domain Controller certificate (0x80070005).  Access is denied.

I ran the GPUpdate.exe /force but that didn't work. Do you know why this started happening and how do I fix the problem.

Thanks for your help,
David


0
Comment
Question by:DBaldarelli
  • 3
  • 3
6 Comments
 
LVL 5

Expert Comment

by:gzarnick
ID: 24018096
0
 
LVL 5

Expert Comment

by:gzarnick
ID: 24018098
Run "certutil.exe -dsdel CAName"
0
 

Author Comment

by:DBaldarelli
ID: 24018144
Do I run this on the Domain Controllers showing the event or on the CA server?
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 5

Accepted Solution

by:
gzarnick earned 250 total points
ID: 24018218
I would run it on the CA server.  

Check that out.
http://support.microsoft.com/kb/927066

It seems that a client is trying to use multiple DNS suffixes.

Also, you're answer could be within here:

http://www.eventid.net/display.asp?eventid=13&eventno=2719&source=AutoEnrollment&phase=1
0
 

Author Comment

by:DBaldarelli
ID: 24018873
Article 927066 that you sent me solved my problem. The CERTSVC_DCOM_ACCESS group was not listed for Local or Remote Access. I also added Domain Controllers to the the CERTSVC_DCOM_ACCESS group. Thank you for your help.

David
0
 

Author Closing Comment

by:DBaldarelli
ID: 31564294
Thanks for your quick response.
David
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

by Batuhan Cetin Within the dynamic life of an IT administrator, we hold many information in our minds like user names, passwords, IDs, phone numbers, incomes, service tags, bills and the order from our wives to buy milk when coming back to home.…
I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…

790 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question