Is Certificate Services Required for a Single Domain with Two DCs and a 3rd Party Exchange Certificate?

Posted on 2011-04-23
Last Modified: 2012-05-11
This probably seems like a bonehead question.  I am about to upgrade from Server 2003 to Server 2008 active directory and am clearing out a couple of Event Viewer errors. One is ID 13, Autoenrollment.  Apparently I am lacking the CERTSVC_DCOM_ACCESS security group.  We have a  third party certificate for our Exchange server.  Can I finesse this simply by installing Certificate Services and making sure this security group is created?  And adding the DCs, of course.  Or will this engender some configuration headaches that might interfere with our 3rd party certificate?
Question by:Herb-Avore
    LVL 12

    Accepted Solution

    normally exchange 2007 and above comes with certificate services for self-signed certificate that is integerated with AD, and internally used with mailbox users, if you have exchange 2007 and above, go to certificate website in exchaneg and make you requests for those cretificate and install them.

    Author Comment

    I may have found an MS support article that describes the problem and offers a solution.  ID 927066.  It says I need to run the following commands to create the missing security account. certutil -setreg SetupStatus -SETUP_DCOM_SECURITY_UPDATED_FLAG
    net stop certsvc
    net start certsvc

    I just have a lingering concern that this might interfere with the settings for the 3rd party Exchange certificate.  By the way, I looked for the the certificate web site in Exchange as you suggested but cannot find it.  Will keep looking.

    Featured Post

    Top 6 Sources for Identifying Threat Actor TTPs

    Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

    Join & Write a Comment

    Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
    The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
    This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
    This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

    745 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now