Solved

Domain CA won't issue certs

Posted on 2015-02-18
3
267 Views
Last Modified: 2015-02-18
Hello,

I was trying to make a new cert template today and it would only issue for 1 year out.  I noticed the root cert only had a date for a year out also.  So on the CA I clicked the Renew CA certificate.  This ran through without any issues.  Now when I try to request a new certificate it wont work.  It doesn't show any templates available.  If I click show all the computer certificate says "The permissions on this certificate authority do not allow the current user to enroll for certificates."  If you look at the attachment there is a little more to the error.   We didn't change anything except renewing the CA cert so I am not sure what broke.  I checked all the permissions I could find and don't see anything obvious.   Does anyone have anything to try?
Thanks in advanced.
cert-error.JPG
0
Comment
Question by:Tim Lewis
  • 2
3 Comments
 

Author Comment

by:Tim Lewis
ID: 40617728
other info... Windows 2008 R2 DC with 2008 AD.    Trying to request Public cert for web services on another windows 2008 R2 server.
0
 
LVL 30

Accepted Solution

by:
Rich Weissler earned 500 total points
ID: 40617862
First thought: within the CA MMC, for your CA, go to the Revoked Certificates, right click, all tasks, and Publish -- A New CRL.

If you open the properties of the CA, does it still show both the old and the new CA certificates in the general tab?

And just to double check... have you stopped and restarted the CA service?

And because changing the Root CA means a new root certificate has to be propagated thru your domain, have you tried a gpupdate /force on the web server?

I can't seem to force my test CA to renew, so I can't reproduce the problem... but still looking to see if I can find a more definitive solution.
0
 

Author Comment

by:Tim Lewis
ID: 40617931
awesome.  I published the new CRL and ran GPupdate /force on both machines and it seems to working now.  I am guessing it was the CRL since I restarted the server once already which should have forced the GPupdate anyway.  Thanks for the help.
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Interactive Script in Scheduled Task not running 8 31
RDS2012 vs RDS2008 4 39
Domain administrator account is locked out 31 60
Cleaning up a desktop after leaving a domain 3 27
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
A safe way to clean winsxs folder from your windows server 2008 R2 editions
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question