[Last Call] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 5555
  • Last Modified:

Certificate Services client auto-enrollment Event ID 6

This is a RODC MS Standard 2008 R2 server.
The error:
Automatic certificate enrollment for domain\user failed (0x8007003a) The specified server cannot perform the requested operation.
This is different than the Event ID 6 for RPC availability.

I have checked the certs and they appear fine but not sure if I am missing something.

Any help would be great because it is the RODC in my DMZ so many services outside rely on it for auth.

Kry
0
kryanC
Asked:
kryanC
  • 2
  • 2
1 Solution
 
MaheshArchitectCommented:
For auto-enrollment check that the certificate template is used by a CA and that the CA service is running on this machine and reachable via RPC
Just telnet CA server from RODC on TCP 135 and check if it succeed ?
Also ensure that High TCP ports are opened from RODC to CA server (1024-656535 or 49152-65535 if CA server is 2008 and above)

http://support.microsoft.com/kb/832017#method4

Mahesh
0
 
kryanCAuthor Commented:
Thanks, telnet was good and ports are opened. Not sure but thought about deleting 509 certs in registry. Thoughts?

Kry
0
 
MaheshArchitectCommented:
Not sure why you require certificate on RODC ?

Anyways, you can directly delete certificate from Certificate Personnel store on RODC

Also you can request certificate for user manually through Certificate MMC console \ personnel certificates on RODC

Just ensure that you have root ca certificate installed on RODC in Trusted root certification authorities

Mahesh
0
 
kryanCAuthor Commented:
Thanks that has cleared up the issues.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now