Solved

Certificate auto-enrollment has not been enabled.

Posted on 2014-10-21
4
591 Views
Last Modified: 2014-11-06
I was in the process of demoting and decommissioning an old 2003 Domain Controller when I determined is was the certificate authority for this domain.  This network has two 2008 R2 DC's functioning so I decided to move that role to one of those servers.

I followed the migration procedures detailed in this TechNet article and all seemed to be fine until I tried to verify the migration by launching the certmgr and requesting to  automatically enroll and retrieve certificates.

http://technet.microsoft.com/en-us/library/ee126140(v=ws.10).aspx

The results seem to indicate Certificate Auto-Enrollment has not been enabled.

When I select the option to Show All Templates, all options are greyed out - status:  Unavailable.  Did I miss something?

Any thoughts would be greatly appreciated.  Thank you
0
Comment
Question by:LenCepeda
  • 2
  • 2
4 Comments
 
LVL 9

Expert Comment

by:RantCan
ID: 40395551
Have you verified the services are started?
0
 

Author Comment

by:LenCepeda
ID: 40395702
Yes, I verified the AD Certificate Services are running.
0
 
LVL 9

Accepted Solution

by:
RantCan earned 500 total points
ID: 40395907
Can you upload the C:\windows\certocm.log file?
0
 

Author Closing Comment

by:LenCepeda
ID: 40427005
I believe I needed to wait for the changes to take effect.  I rebooted the server waited a few hours and all was in order
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
NTP problem 24 73
AD Account lockout 11 61
How to eliminate the special character - and goto next in powershell 6 53
Unable to hit site 2 23
On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question