troubleshooting Question

Automatic certificate enrollment for local system failed (0x800b0101)

Avatar of tfinding
tfindingFlag for United Kingdom of Great Britain and Northern Ireland asked on
Windows Server 2008Active DirectorySecuritySSL / HTTPS
6 Comments1 Solution8170 ViewsLast Modified:
Hello

One of clients has a very simple domain, with 2 x W2008 R2 Domain Controllers and an Exchange Server 2010 server.

For some reason the Exchange server is the Certification Authority and 2 of the certificates expired in December 2015.

The Domain Controller now gets;

  -  Event ID: 64 - Certificate for local system with Thumbprint xxxxxxxxxx  is about to expire or already expired
  -  Event ID: 6 - Automatic certificate enrollment for local system failed (0x800b0101) A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
  -  Event ID: 13 - Certificate enrollment for Local system failed to enroll for a DomainControllerAuthentication certificate with request ID N/A from "ServerName01-CA" (A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. 0x800b0101 (-2146762495)).

and the same Event ID: 13 for a "DirectoryEmailReplication" certificate.

It seems relatively simple, that the certs have expired and, as we can't renew, we have to create new ones, but I'm unsure how to go about this.

Any pointers would be appreciated.

Thanks in advance.
ASKER CERTIFIED SOLUTION
tfinding

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 1 Answer and 6 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 6 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros