Problesm with a CA Server and site - Certsrv enrolment issues


i stood windows 2008 r2 entr sp1 ca server multi domain forest.  iis , certificates not area of expertise.

the forest structure empty root resource , user domains.  the servers in resource  domain. 

the system worked stopped working, not entirely sure when use function little.  when try request cert via https://servername.fqdn/certsrv page 401 “unauthorized: access denied due invalid credentials”.  there nothing wrong credentials i’m offering, i’m using domain administrator account.  additionally account i’m using member of ca managers global group.

additionally have set system via gpo auto enroll certificate requests forest computer systems, have log web site , manually issue them.

i’ve spent of day going 1 kb article , nothing seems working.  when enter in https://server.fqdn/test/, iis 7 picture.

if try change security settings on certsrv site in iis manager, options grayed out.

at point i'm @ loss try or how thing fixed.

- bryan

arlington va

please note,

out of domain within same forest need "universal group".

out of domain & out of forest mean cross forest need "domain local group".

there agudlp come picture.

____________________________________________________________________________________________

do have local admin access on iis server ?

you find guide below link cross forest ca.

http://www.microsoft.com/en-us/download/details.aspx?displaylang=en&id=17877

in addition check aia/cdp & pki health.

http://blogs.technet.com/b/pki/archive/2011/02/28/quick-check-on-adcs-health-using-enterprise-pki-tool-pkiview.aspx

see blog cdp/deltarl issue on 2008/2008r2.

http://social.technet.microsoft.com/wiki/contents/articles/21018.pkiview-msc-unable-to-download-cdp-delta-crl.aspx

-biswajit


best regards biswajit biswas disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights. mcp 2003,mcsa 2003, mcsa:m 2003, ccna, mcts, enterprise admin







Windows Server  >  Security



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file