Solved

Certificate auto-enrollment has not been enabled.

Posted on 2014-10-21
4
469 Views
Last Modified: 2014-11-06
I was in the process of demoting and decommissioning an old 2003 Domain Controller when I determined is was the certificate authority for this domain.  This network has two 2008 R2 DC's functioning so I decided to move that role to one of those servers.

I followed the migration procedures detailed in this TechNet article and all seemed to be fine until I tried to verify the migration by launching the certmgr and requesting to  automatically enroll and retrieve certificates.

http://technet.microsoft.com/en-us/library/ee126140(v=ws.10).aspx

The results seem to indicate Certificate Auto-Enrollment has not been enabled.

When I select the option to Show All Templates, all options are greyed out - status:  Unavailable.  Did I miss something?

Any thoughts would be greatly appreciated.  Thank you
0
Comment
Question by:LenCepeda
  • 2
  • 2
4 Comments
 
LVL 9

Expert Comment

by:RantCan
Comment Utility
Have you verified the services are started?
0
 

Author Comment

by:LenCepeda
Comment Utility
Yes, I verified the AD Certificate Services are running.
0
 
LVL 9

Accepted Solution

by:
RantCan earned 500 total points
Comment Utility
Can you upload the C:\windows\certocm.log file?
0
 

Author Closing Comment

by:LenCepeda
Comment Utility
I believe I needed to wait for the changes to take effect.  I rebooted the server waited a few hours and all was in order
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

To effectively work with Diskpart on a Server Core, it is necessary to write some small batch script's, because you can't execute diskpart in a remote powershell session. To get startet, place the Diskpart batch script's into a share on your loca…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now