Solved

CA moved to another server - now errors

Posted on 2016-10-17
19
72 Views
Last Modified: 2016-10-31
Hi Experts,

we have moved our CA to another server.
Now I cannot open CERTSRV to sign a request.
Can you help me to find the error ?




Modul

IsapiModule



Benachrichtigung

ExecuteRequestHandler



Handler

ASPClassic



Fehlercode

0x800700aa





Angeforderte URL

http://s02dc:80/certsrv/Default.asp



Physikalischer Pfad

C:\Windows\system32\CertSrv\de-DE\Default.asp



Anmeldemethode

Negotiate
0
Comment
Question by:Eprs_Admin
  • 10
  • 8
19 Comments
 
LVL 6

Expert Comment

by:No More
ID: 41846359
Did you export CA database and export CA configuration from registry and then uninstall CA on old server ?

Did you then install CA on new server and import database and registry configuration to new server ?
0
 

Author Comment

by:Eprs_Admin
ID: 41846369
Hello,

yes we have exported the REG settings and the DB.
From the old server it is uninstalled
On the new server it is installed and REG settings imported as well the DB.
0
 
LVL 6

Expert Comment

by:No More
ID: 41846377
I forgot to mention , Do you have same name of the server ?



CA server 2003 to 2008 ?
0
 

Author Comment

by:Eprs_Admin
ID: 41846382
no its another name.
0
 
LVL 6

Expert Comment

by:No More
ID: 41846387
What I would remember, It has to be same name to get it to work

old server name move to new server
0
 

Author Comment

by:Eprs_Admin
ID: 41846393
but this is not possible.
I have another server with another name and I cannot change it.

So when I export the DB and the regisrty, why I need the same name ?
This makes no sense.
0
 
LVL 6

Accepted Solution

by:
No More earned 500 total points
ID: 41846409
Never mind that,

Look at this link , I believe this could sort you out
https://blogs.iis.net/webtopics/asp-500-error-and-error-code-0x800700aa-when-browsing-a-simple-asp-page
0
 

Author Comment

by:Eprs_Admin
ID: 41846416
I dont use McAffee, so this link is obsolete.
0
 
LVL 6

Expert Comment

by:No More
ID: 41846424
Read that article, it clearly tells you how to troubleshoot this issue
0
6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

 

Author Comment

by:Eprs_Admin
ID: 41846451
I have read all,  but this will not solve my case.
0
 
LVL 78

Expert Comment

by:David Johnson, CD, MVP
ID: 41846466
1. Did you create a capolicy.inf and put it in your windows folder.

More than likely your CA configuration is incorrect and pointing to the OLD servername.
0
 
LVL 6

Expert Comment

by:No More
ID: 41846472
@David
That was needed for 2003 server not 2008 what I would remember
0
 

Author Comment

by:Eprs_Admin
ID: 41846497
The regsettings are ok.
I dont have a ca policy....whats this ?
0
 

Author Comment

by:Eprs_Admin
ID: 41846530
Sorry your link was right.
In the past we had also McAffee.
Now the certsrv website works again.
0
 
LVL 6

Expert Comment

by:No More
ID: 41846570
So, I was right ?
0
 

Author Comment

by:Eprs_Admin
ID: 41846598
yes the IE starts again but still I cannot enter the CSR to get my certificate.

I get this error:
cert-error.JPG
0
 

Author Comment

by:Eprs_Admin
ID: 41846605
on EXCH2013 I have created a new cert request.
But when I enter this reqest to our CA I get this error:

WIN32: 13 Error
SOmething with wrong data.

My CA is running on WIN2008, is this a problem ?
0
 
LVL 6

Expert Comment

by:No More
ID: 41846661
Open certification authority and check if you have any certificates from old server there ,as they need to be revoked and new cert reissued from new CA

Also restart CA server

You need to check that you have correct CA certs on servers

Do you have public cert for your exchange server ?
0
 

Author Closing Comment

by:Eprs_Admin
ID: 41866498
it was something with our old security system from Kaspersky.
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Password hashing is better than message digests or encryption, and you should be using it instead of message digests or encryption.  Find out why and how in this article, which supplements the original article on PHP Client Registration, Login, Logo…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now