Solved

Computer certificates enrolling multiple times

Posted on 2013-06-12
4
800 Views
Last Modified: 2013-07-03
I am having an issue with a 2008 R2 Standard Enterprise CA where computer accounts are being issued multiple certificates. Auto-enrollment is configured via group policy. The template in use is "Copy of Workstation Authentication". "Publish certificate in Active Directory" and "Do not automatically reenroll if a duplicate certificate exists in Active Directory" are both enabled on the template. It is not a widespread issue but there are usually a few a day, but not for the same computer day after day.

It may not be at all related but the event application log for this CA server frequently has the following logged:

Event 77: Classic, CertificationAuthority

The "Windows default" Policy Module logged the following warning: The Active Directory connection to CASERVER.DOMAIN.COM has been reestablished to CASERVER.DOMAIN.COM.

Your assistance is greatly appreciated.
0
Comment
Question by:cberrymd
  • 2
  • 2
4 Comments
 
LVL 18

Expert Comment

by:irweazelwallis
ID: 39270894
i have the same issue but i don't have that warning in my event logs
0
 
LVL 18

Expert Comment

by:irweazelwallis
ID: 39270970
my problem was that i had the Session Host Server authentication setting enabled and this causes the problem i.e. when a background refresh happens it generates a new certificate
0
 

Accepted Solution

by:
cberrymd earned 0 total points
ID: 39284614
Issue resolved by removing "Publish in DS" for workstation/computer/server templates and increasing server resources to improve performance. AD CS probably issued multiple certs due to poor connectivity with revocation information.
0
 

Author Closing Comment

by:cberrymd
ID: 39295998
No answers provided. EE community did not assist.
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A safe way to clean winsxs folder from your windows server 2008 R2 editions
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

827 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question