Avatar of marek1712
marek1712
Flag for Poland asked on

CertificationAuthority - lots of Event 22

Fellow Experts, I need help.

Long story short - I've recovered domain controller from the crash and some time after the operation CertificateAuthority started making errors (Event ID: 22, just like below). Unfortunately we have only one server and had to put everything in one box.

Active Directory Certificate Services could not process request REQUEST_NO due to an error: ERROR 0xc8000152 (ESE: -338).  The request was for DOMAIN\user_account.  Additional information: An error has been encountered while analyzing the request.
...or the last message may be: Error Verifying Request Signature.
I'm not sure about the exact message as I'm not using English Windows.
It happens for user accounts as well as computer accounts.

I've checked MS KB about the issue (with verifying certificates and generating new CRL list) and it seems everything is fine...
What may be other steps to look for?

In the worst case scenario I can decommission CA and start from scratch as it's not yet widely used (only for RemoteApp).
Windows Server 2008Active DirectoryMicrosoft Server OS

Avatar of undefined
Last Comment
marek1712

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
Leon Fester

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
marek1712

ASKER
Yes, that was the Technet article I've seen. And the results were positive...
I have to admit I had some problems with AD, but it seems they're resolved by now - no reports of inconsistencies or any other errors...
marek1712

ASKER
I've followed KB889250 (yes, I know it's for Win2000 and 2003) and decommissioned the server (couldn't event manually request new certificates).
Then I've set it up from scratch and it seems to work properly now. I just have to replace few RemoteApp .rdp files located on some computers.
Anyway - since your suggestion was correct - I'm closing the question.
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23