Improve company productivity with a Business Account.Sign Up


Problem with certificates after Issuing CA move to new server

Posted on 2009-04-14
Medium Priority
Last Modified: 2013-12-04
Currently I'm having an issue with a recently moved certificate services install.  The details for this CA are:

-Offline Root with Enterprise CA running Win2K3 R2 Enterprise.
-A simple domain structure with multiple DC's.  No trusts involved.
-Several certificate have been issued...all via AutoEnrollment.
-The original issuing CA had to be retired (old server) so I moved the issuing CA to a new server (actually a VM running on ESX).
-Domain controllers and RADIUS servers have also been moved to new hardware.  Server have been renamed in all cases to match new naming convention.
-I've followed all published Microsoft procedures for this move.
-Some certificates that were issued contain the name of a an old domain controller in the certificate request attributes cdc.
-It is these certificates that are having a problem authenticated users/devices.

RADIUS is setup and working properly.  I think the issue is the certificate request attribute.  Is there any way to change this without reissueing a new certificate?  What is the recommended or best practice method for resolving this for all issued certificates?

Thanks for your help.
Question by:Sagiman75
  • 3
  • 3
LVL 31

Expert Comment

ID: 24141139
If your new CA is handling other certificate requests okay:

From CA:
certutil -dcinfo DeleteBad
certutil -pulse

From DC:
gpupdate /force

If still having problems - your new CA has a new name, correct?  You didn't try restoring old to this one, this is a new setup, correct (old one was just taken offline and retired)?

Author Comment

ID: 24141690
Thanks for the reply.

The issuing CA server was moved to new hardware with a new name.  I followed a Microsoft document that explains the process step by step.  The CA itself was not named after the server.  I backed up the database and registry and was able t successfully restore to the new server with a different host name.  I've changed the CRL publication to reflect both the old LDAP location (so existing certs could see it) and the new LDAP location which contains the name of my new issuing CA.

I've fixed the RADIUS issue...that was my mistake.  The access point was still configured to look at the old RADIUS servers to authenticate user certificates.  The problem I'm seeing now is that autoenrollment of RAS and IAS  Server Authentication template certificates are not working properly.  I see both new DCs (which are also RADIUS servers) listed in the issued certificates folder in the Certifcate Authority snap-in with all appropriate certificates (Domain Controller, RAS and IAS, and Domain E-mail Replication).  When I look at computer certs for my RADIUS servers they do not see the RAS and IAS certs...just the other two.  I've selected Automatically Enroll Certificates but the cert is still not listed.  As such...I'm getting a lot of errors in my system event log from IAS.

Any ideas how to get my RAS and IAS cert installed on my RADIUS servers?

Thanks again!
LVL 31

Expert Comment

ID: 24148092
Usually we create a Certificate Signing Request (CSR) file from the server and submit that to the CA using http://caservername/certsrv and selecting the first option twice, then filling out that page to submit the CSR to get the cert, then install that on the server.

We don't do autoenrollment because we want to know what servers are specifically being assigned certs from our certificate operations team.

Anyways, you might want to check out the Certificate Templates MMC and verify the security permissions for that template have read, enroll, and autoenroll for the proper group for your servers.  Then doublecheck Certification Authorities MMC - Certificate TEmplates folder to make sure that the template is assigned to the CA, if not then issue the template and wait a few minutes.

You can also try issuing the command from the CA
certutil -pulse
to readvertise autoenrollment notifications

You can also try from the requesting servers:
gpupdate /force
Worried about phishing attacks?

90% of attacks start with a phish. It’s critical that IT admins and MSSPs have the right security in place to protect their end users from these phishing attacks. Check out our latest feature brief for tips and tricks to keep your employees off a hackers line!


Author Comment

ID: 24148545
Thanks again.

Our PKI is pretty small.  It was setup to allow for Windows Mobile bar code scanners and laptops to access the network as securely as possible.  At this time that is all we use it for.  The Autoenrollment makes it easy on our very small IT dept.  (there are only 3 of us).

Would Autoenrollment be affected by the CRL not being published correctly?  In the properties of the issuing CA I have added an ldap location for the old CA server (using the old CA server name) in the extensions tab and selected the location for publishing CRL's and Delta CRL's.  There is also a CDP for ldap with the new CA server name, an HTTP location, and the default C:\Windows\System32 location.  If I force a publication of the revocation list I see an error in the application log (Event ID 74) which says the certificate could not be published to the ldap directory.  If I browse to the ldap location using ADSIEdit I can see the CA and the publish date and time reflect the latest publication.   I can see this being a problem for existing certificates since they all point to the old CRL location but I can't see how that would affect Autoenrollment.

I did try your suggestions for getting the certs to autoenroll.  Permissions are correct.  The RADIUS servers are members of the appropriate group with read, enroll, and autoenroll permissions.  The template has been assigned to the CA.  I believe that is the case anyway.  If I open the CA MMC and browse to Certificate Templates the RAS and IAS Server Authentication template is shown.  What is really odd to me is both RADIUS servers have been issued the certificate from the template.  I can see both server names in the Issued Certificates folder.  But if I open the certificates mmc on the RADIUS server and browse to personal/certificates folder I only see two from the directory email replication template and the other from the domain controller auth template.  I've tried the gpudate /force command on both RADIUS servers.  I've rebooted both RADIUS servers.  I also tried the certutil -pulse command on the CA server.  And still...the RAS and IAS issued certs are not showing up in the certificates mmc on each server.

LVL 31

Accepted Solution

Paranormastic earned 2000 total points
ID: 24150007
Would Autoenrollment be affected by the CRL not being published correctly?
--Yes, this can cause problems if the CRL is not avaiable upon installation.  However, as long as at least one of the CDP is valid then you should be in good shape.

You can use the command 'certutil -dspublish FILE.crl' to point to the crl to publish to AD/LDAP.

in the certificates mmc try selecing View - Options - Show physical stores.  Then take another look.

Also, if you have the DC Auth certificate - that has the server auth. key usage.  If that's all you need, then you might already be set if you can use that.  Otherwise, I would suggest using the certificate mmc and use the certificate request wizard there to get a cert, or use IIS or something to make a CSR to process on the certsrv page.

Author Comment

ID: 24168316
Things are working again but it took me exporting the issued cert from my CA and installing it manually on each of my RADIUS servers.  I'm not sure why that is but authentication is working again and that was my main issue.  Thanks for the help with this problem.

Featured Post

The 14th Annual Expert Award Winners

The results are in! Meet the top members of our 2017 Expert Awards. Congratulations to all who qualified!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

No security measures warrant 100% as a "silver bullet". The truth is we also cannot assume anything but a defensive and vigilance posture. Adopt no trust by default and reveal in assumption. Only assume anonymity or invisibility in the reverse. Safe…
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
The video will let you know the exact process to import OST/PST files to the cloud based Office 365 mailboxes. Using Kernel Import PST to Office 365 tool, one can quickly import numerous OST/PST files to Office 365. Besides this, the tool also comes…
Free Data Recovery software is an advanced solution from Kernel Tools to recover data and files such as documents, emails, database, media and pictures, etc. It supports recovery from physical & logical drive after a hard disk crash, accidental/inte…

585 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question