Solved

Unable to browse to our Certificate Authority website

Posted on 2013-01-08
9
1,049 Views
Last Modified: 2013-01-19
I am in the middle of renewing our Exchange certificate. When I browse to http://localhost/certserv, IE tells me that the website can't be displayed.
More specifically, when I browse to that site via IIS, I receive the error below.
My IIS expertice is limited so I don't want to start to change how the modules are handled etc without knowing exactly what I'm doing.

Thanks for your input!

Error Summary
HTTP Error 500.0 - Internal Server Error
The page cannot be displayed because an internal server error has occurred. Detailed Error InformationModule IsapiModule
Notification ExecuteRequestHandler
Handler AboMapperCustom-17386171
Error Code 0x800700c1
Requested URL http://192.168.**.**:80/CertSrv
Physical Path C:\Windows\system32\CertSrv\en-US
Logon Method Negotiate
Logon User *******\*****
0
Comment
Question by:mark-199
  • 6
  • 2
9 Comments
 
LVL 33

Expert Comment

by:Busbar
ID: 38753870
are you sure that Classic ASP is enabled ?!
0
 
LVL 19

Expert Comment

by:Kash
ID: 38754095
is it something like this >> http://forums.iis.net/t/1144489.aspx
0
 

Author Comment

by:mark-199
ID: 38754182
I don't think so. I don't actually get the options below in IIS7 manager; I don't see 'Advanced settings' anywhere with the Application Pool selected as described in the article.
Could that have something to do with IIS7 running on Server 2008R2?

Any other suggestions anyone?
0
 

Author Comment

by:mark-199
ID: 38758029
I have tried mapping script points to the ISAPI .dll in Handler Mappings. There are still a few sources that don't have a specific file assigned to them such as AboMapperCustom-1738171, AboMapperCustom-17386187, OPTIONSVerbHandler, TRACEVerbHandler and StaticFile.
The simply have a * path.

Checking the default application pool, which is the one certsrv uses, 32bit application is set to false (and so are all the other pools).

Two things I have noticed when comparing IIS on a CA which has the certsrv site working with our IIS setup is that:
•there is no .ASP section in the certsrv configuration pane and
•when trying to enable HTTPS it says: 'The Site does not have a secure binding (HTTPS) and cannot accept SSL connections

Is there an easy way to repair certsrv or IIS?

In the worst case scenario, can I just setup a new CA server?

Thanks
0
Promote certifications in your email signature

Has your company recently won an award or achieved a certification? They'll no doubt want to show it off. Email signature images used to promote certifications & awards can instantly establish credibility with a recipient and provide you with numerous benefits.

 
LVL 33

Expert Comment

by:Busbar
ID: 38758046
uninstall the web enrollment role and IIS then reinstall them again, you can always install new CA server.
0
 

Author Comment

by:mark-199
ID: 38767316
New developments:
I played around a bit more with the Handler Mappings and assigned .NET Classic mode to the certsrv site.
I was then able to access the website but got the following error:
'No certificate templates could be found. You do not have permission to request a certificate from this CA, or an error occured while accessing the Active Directory'.

Any further suggestions are appreciated.
0
 

Author Comment

by:mark-199
ID: 38767356
Some more info:I can only access the site through IIS manager (not by opening a browser session outside IIS) and HTTPS access also isn't working at this stage... (page cannot be displayed).
0
 

Accepted Solution

by:
mark-199 earned 0 total points
ID: 38774227
Thank you all for your help with this. I couldn't fix the issue in the end... it boiled down to the account not having sufficient permissions. We ended up assigning the computer account full permissions and were able to renew the certificate through the local certificate store on the CA.
I might start a new post with more specific error messages.
0
 

Author Closing Comment

by:mark-199
ID: 38796042
I implemented a workaround to the issue myself.
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Resolve Outlook connectivity issues after moving mailbox to new Exchange 2016 server
Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now