[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

CA Server Issue - CAS Crashed/RADIUS Errors

Posted on 2012-03-11
3
Medium Priority
?
655 Views
Last Modified: 2012-03-13
Hi Guys

I've run into a bit of an issue, my CA server crashed (No backup!)  a while back and I thought there wouldn't be any issues, but a few days back the certificate on the PDC expired and now any user trying to connect to the wireless is unable too, due to the RADIUS. It seems that because the certificate expired the RADIUS server has stopped working.

Any idea what the best solution is to get the wireless working again?
Setting up another CA?
Setting up a self signed certificate (using IIS) for the RADIUS?
If I do not setup another CA will there be any further consequences? All servers have been popping up auto enrollment certificate errors.

Any feedback will be great. Thanks!
0
Comment
Question by:YOlanie_Visser
  • 2
3 Comments
 
LVL 26

Accepted Solution

by:
Leon Fester earned 2000 total points
ID: 37706922
It's hard to rebuild a CA, especially if you didn't back it up properly.
A self signed cert does not offer the same solutions as a CA would and you'd probably get some issues because the CRL cannot be completed.

I'd suggest deleting the OLD CA information, and then rebuild your CA and you can then reissues your certs the "normal" way.

This is what you needed to do before the CA fell over.
http://blogs.technet.com/b/pki/archive/2010/04/20/disaster-recovery-procedures-for-the-active-directory-certificate-services-adcs.aspx

These are the instructions you're looking for:
Basically, remove broken CA.
Install new CA.
Re-issue certs, your Servers should automatically enroll once the CA is present, so possibly only your RADIUS server may need a manual re-issue.

You should start with removing the decommissioned CA from your domain.
http://support.microsoft.com/kb/889250

Have a read about CA's and decide if you still don't need it.
http://www.kurtdillard.com/StudyGuides/70-640/6.html

How to install a CA
http://technet.microsoft.com/en-us/library/aa998956(v=exchg.65).aspx
0
 

Author Comment

by:YOlanie_Visser
ID: 37714191
dvt_localboy

I'm in the process of doing the cleanup, any idea how I will work around the RADIUS issue? Could I use a self signed cert just for the RADIUS? That would be the only reason why I would setup another CA,,,
0
 
LVL 26

Expert Comment

by:Leon Fester
ID: 37714633
No a self signed certificate in the Radius server won't help you.
The simple reason: the Certificate Authority for that self signed certificate will not be found.

You also need to remember that the basis of PKI is that there is always an Authority that can verify a the validity of a certificate. Have a look at a valid certificate and check out the Certificate Path....it's needed for establishing if your Certificate is valid.
http://technet.microsoft.com/en-us/library/cc731853.aspx

Reasons for installing a CA
http://technet.microsoft.com/en-us/library/cc776679(v=ws.10).aspx

Additional reading that may interest you:
http://social.technet.microsoft.com/wiki/contents/articles/987.windows-pki-documentation-reference-and-library.aspx
http://technet.microsoft.com/en-us/library/cc772670(v=ws.10).aspx
http://www.trainsignal.com/blog/active-directory-certificate-services
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…
Is your data getting by on basic protection measures? In today’s climate of debilitating malware and ransomware—like WannaCry—that may not be enough. You need to establish more than basics, like a recovery plan that protects both data and endpoints.…

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question