XP unable to get a machine certificate from domain

I have an XP PC that is unable to get a machine certificate from the domain. All other machines are ok. If I try to request a new certifiacate from the domain, I get the following:

The wizard cannot be started because of one of the following conditions:
-There are no trusted CAs available
-You do not have permissions to request certificates from the available CSs
-The available CAs issue certificates for which you do not have permissions

I have removed the machine from the domain, deleted the machine account, and re added it, but still no certificate.

One thing I have seen is that Extensible Authentication Protocol Service service failed to start. The service did not respond to the start or control request in a timely fashion.

I don't know if this service failed to start because there is no certificate, or if there is no certificate because EAPS failed to start, or if this is unrelated

Any help would be great!

Thanks
Jim
jimxoxAsked:
Who is Participating?

[Webinar] Streamline your web hosting managementRegister Today

x
 
Rich WeisslerConnect With a Mentor Professional Troublemaker^h^h^h^h^hshooterCommented:
Are there any other error messages showing up in the Event Viewer log?  Especially System and Application?  

There are some conditions under which 'rebuild the laptop' may be the ultimate answer, but lets rule out everything else first.   It's a laptop, so some strange low probability issues may be at play.

Confirm there isn't anything strange in the c:\windows\system32\drivers\etc\hosts file
Confirm ipconfig /all has all the stuff you EXPECT to be there... especially DNS entries.
If your workstations are able to connect to the CA server via http/https -- make certain the laptop does.  (Windows CA frequently have a website available for web enrollment... it will just be useful to make certain the laptop is correctly resolving the CA, and rule out IP connectivity issues.)
Double check the firewall settings to ensure they meet your corporate standards.  Make certain there aren't any non-supported extra firewalls (Zone Alarm, for example) in the way.
0
 
Rich WeisslerProfessional Troublemaker^h^h^h^h^hshooterCommented:
Confirm network connectivity to the Certificate Authority server?
Do you have any errors on your Certificate Authority machine?
The other machines in your environment which are okay... are any of them also Windows XP?  (Or just Vista and Win7?)
0
 
jimxoxAuthor Commented:
I am too low down the food chain in this organisation to be allowed access to the CA server, so am unable to check that.

All machines are XP - our beloved corporate dictators do not allow any modern OS
0
Never miss a deadline with monday.com

The revolutionary project management tool is here!   Plan visually with a single glance and make sure your projects get done.

 
Rich WeisslerProfessional Troublemaker^h^h^h^h^hshooterCommented:
Ah.  Understood.  
I strongly suspect EAP is failing due to the lack of a certificate rather than the reverse.  

Ping the CA to see if it is down.
or If you have another new workstation you can test with, see if the problem repeats on a different machine.  

If this has worked for you in the past, unless someone has made a change on the CA, it's probably not a lack of permissions or not having the right template installed.  Once this is set up, I don't think there are very many moving parts that can break.
0
 
jimxoxAuthor Commented:
I can delete and request / renew certificates on other machines, so I can only assume that the issue is with the single laptop and not the CA server, or connectivity to the CA server.
Requested assistance further up the food chain - their response was "rebuild the laptop" - helpful! Laptop's owner's response to that was not repeatable   ;o)

Tried to do some experiments on my own working laptop. EAPS and certificates to do not appear to have a relationship on my PC. Can delete my machine certificate, and EAPS starts / stops no problem. Can also disable EAPS, and can still delete / renew / request certificates - Think the whole EAPS may have just been a red herring!

May try to reinstall SP3 on to XP to see if that has any affect, but to be honest, I am just guessing now
0
 
jimxoxAuthor Commented:
Please award points to Razmus for his help, however have no given up on the issue and decide not to waste any more time on the issue and just rebuild the laptop

Thanks Razmus!
0
All Courses

From novice to tech pro — start learning today.