Solved

Automatic Certificate Enrollment Failed

Posted on 2009-03-30
6
703 Views
Last Modified: 2012-05-06
I seeing the following event in a number of our DC"s:

Event Type:      Error
Event Source:      AutoEnrollment
Event Category:      None
Event ID:      13
Date:            3/30/2009
Time:            3:02:39 AM
User:            N/A
Computer:      STERLINGPDC
Description:
Automatic certificate enrollment for local system failed to enroll for one Domain Controller certificate (0x80070005).  Access is denied.

I ran the GPUpdate.exe /force but that didn't work. Do you know why this started happening and how do I fix the problem.

Thanks for your help,
David


0
Comment
Question by:DBaldarelli
  • 3
  • 3
6 Comments
 
LVL 5

Expert Comment

by:gzarnick
ID: 24018096
0
 
LVL 5

Expert Comment

by:gzarnick
ID: 24018098
Run "certutil.exe -dsdel CAName"
0
 

Author Comment

by:DBaldarelli
ID: 24018144
Do I run this on the Domain Controllers showing the event or on the CA server?
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 5

Accepted Solution

by:
gzarnick earned 250 total points
ID: 24018218
I would run it on the CA server.  

Check that out.
http://support.microsoft.com/kb/927066

It seems that a client is trying to use multiple DNS suffixes.

Also, you're answer could be within here:

http://www.eventid.net/display.asp?eventid=13&eventno=2719&source=AutoEnrollment&phase=1
0
 

Author Comment

by:DBaldarelli
ID: 24018873
Article 927066 that you sent me solved my problem. The CERTSVC_DCOM_ACCESS group was not listed for Local or Remote Access. I also added Domain Controllers to the the CERTSVC_DCOM_ACCESS group. Thank you for your help.

David
0
 

Author Closing Comment

by:DBaldarelli
ID: 31564294
Thanks for your quick response.
David
0

Featured Post

Live: Real-Time Solutions, Start Here

Receive instant 1:1 support from technology experts, using our real-time conversation and whiteboard interface. Your first 5 minutes are always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question