Problesm with a CA Server and site - Certsrv enrolment issues
i stood windows 2008 r2 entr sp1 ca server multi domain forest. iis , certificates not area of expertise.
the forest structure empty root resource , user domains. the servers in resource domain.
the system worked stopped working, not entirely sure when use function little. when try request cert via https://servername.fqdn/certsrv page 401 “unauthorized: access denied due invalid credentials”. there nothing wrong credentials i’m offering, i’m using domain administrator account. additionally account i’m using member of ca managers global group.
additionally have set system via gpo auto enroll certificate requests forest computer systems, have log web site , manually issue them.
i’ve spent of day going 1 kb article , nothing seems working. when enter in https://server.fqdn/test/, iis 7 picture.
if try change security settings on certsrv site in iis manager, options grayed out.
at point i'm @ loss try or how thing fixed.
- bryan
arlington va
please note,
out of domain within same forest need "universal group".
out of domain & out of forest mean cross forest need "domain local group".
there agudlp come picture.
____________________________________________________________________________________________
do have local admin access on iis server ?
you find guide below link cross forest ca.
http://www.microsoft.com/en-us/download/details.aspx?displaylang=en&id=17877
in addition check aia/cdp & pki health.
http://blogs.technet.com/b/pki/archive/2011/02/28/quick-check-on-adcs-health-using-enterprise-pki-tool-pkiview.aspx
see blog cdp/deltarl issue on 2008/2008r2.
-biswajit
best regards biswajit biswas disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights. mcp 2003,mcsa 2003, mcsa:m 2003, ccna, mcts, enterprise admin
Windows Server > Security
Comments
Post a Comment