AutoEnrollment

AutoEnrollment

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
AutoEnrollment Shawn Hayes 06-06-2006
Posted by =?Utf-8?B?U2hhd24gSGF5ZXM=?= on June 6, 2006, 4:56 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
We have a W2K3 SP1 Enterprise Root CA and a GPO established for Computer
account AutoEnrollment. The computers are not receiving Certificates and the
error message in the Eventlog reads

Soure:AutoEnrollment
EventID: 13

Automatic certificate enrollment for local system failed to enroll for one
Computer (Autoenrollment) certificate (0x80070005), Access is Denied.

I have verified permissions on the \Documents and Settings\All
Users\Application Data\Microsoft\Crypto\RSA\MachineKeys directory include
Administrator and System Full contol.

Thanks in advance for any suggestions.

Posted by Paul Adare on June 7, 2006, 7:06 am
If you were  Registered and logged in, you could reply and use other advanced thread options
microsoft.public.security news group, =?Utf-8?B?U2hhd24gSGF5ZXM=?=

> We have a W2K3 SP1 Enterprise Root CA and a GPO established for Computer
> account AutoEnrollment. The computers are not receiving Certificates and the
> error message in the Eventlog reads
>
> Soure:AutoEnrollment
> EventID: 13
>
> Automatic certificate enrollment for local system failed to enroll for one
> Computer (Autoenrollment) certificate (0x80070005), Access is Denied.
>
> I have verified permissions on the \Documents and Settings\All
> Users\Application Data\Microsoft\Crypto\RSA\MachineKeys directory include
> Administrator and System Full contol.
>
> Thanks in advance for any suggestions.
>

What SKU of Windows Server 2003 is your CA running, Web, Standard,
Enterprise or Data Centre? For autoenrollment you need to be running
Enterprise Edition or above.

--
Paul Adare - MVP Virtual Machines
It all began with Adam. He was the first man to tell a joke--or a lie.
How lucky Adam was. He knew when he said a good thing, nobody had said
it before. Adam was not alone in the Garden of Eden, however, and does
not deserve all the credit; much is due to Eve, the first woman, and
Satan, the first consultant." - Mark Twain

Posted by =?Utf-8?B?U2hhd24gSGF5ZXM=?= on June 7, 2006, 7:33 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks for the reply Paul. We have covered all the basics. The server is
running Enterprise edition.

Shawn

"Paul Adare" wrote:

> microsoft.public.security news group, =?Utf-8?B?U2hhd24gSGF5ZXM=?=
>
> > We have a W2K3 SP1 Enterprise Root CA and a GPO established for Computer
> > account AutoEnrollment. The computers are not receiving Certificates and
the
> > error message in the Eventlog reads
> >
> > Soure:AutoEnrollment
> > EventID: 13
> >
> > Automatic certificate enrollment for local system failed to enroll for one
> > Computer (Autoenrollment) certificate (0x80070005), Access is Denied.
> >
> > I have verified permissions on the \Documents and Settings\All
> > Users\Application Data\Microsoft\Crypto\RSA\MachineKeys directory include
> > Administrator and System Full contol.
> >
> > Thanks in advance for any suggestions.
> >
>
> What SKU of Windows Server 2003 is your CA running, Web, Standard,
> Enterprise or Data Centre? For autoenrollment you need to be running
> Enterprise Edition or above.
>
> --
> Paul Adare - MVP Virtual Machines
> It all began with Adam. He was the first man to tell a joke--or a lie.
> How lucky Adam was. He knew when he said a good thing, nobody had said
> it before. Adam was not alone in the Garden of Eden, however, and does
> not deserve all the credit; much is due to Eve, the first woman, and
> Satan, the first consultant." - Mark Twain
>

Posted by Paul Adare on June 7, 2006, 8:51 am
If you were  Registered and logged in, you could reply and use other advanced thread options
microsoft.public.security news group, =?Utf-8?B?U2hhd24gSGF5ZXM=?=

> Thanks for the reply Paul. We have covered all the basics. The server is
> running Enterprise edition.
>

What are the permissions on the template that you're having the trouble
with?

--
Paul Adare - MVP Virtual Machines
It all began with Adam. He was the first man to tell a joke--or a lie.
How lucky Adam was. He knew when he said a good thing, nobody had said
it before. Adam was not alone in the Garden of Eden, however, and does
not deserve all the credit; much is due to Eve, the first woman, and
Satan, the first consultant." - Mark Twain

Posted by =?Utf-8?B?U2hhd24gSGF5ZXM=?= on June 7, 2006, 9:13 am
If you were  Registered and logged in, you could reply and use other advanced thread options
It is the Computer(Autoenrollment) template permissions are:
Autenticated Users - Read
Domain Admins - Read, Write, Enroll
Domain Computers - Read, Enroll, Autoenroll
Enterprise Admins - Read, Write, Enroll


"Paul Adare" wrote:

> microsoft.public.security news group, =?Utf-8?B?U2hhd24gSGF5ZXM=?=
>
> > Thanks for the reply Paul. We have covered all the basics. The server is
> > running Enterprise edition.
> >
>
> What are the permissions on the template that you're having the trouble
> with?
>
> --
> Paul Adare - MVP Virtual Machines
> It all began with Adam. He was the first man to tell a joke--or a lie.
> How lucky Adam was. He knew when he said a good thing, nobody had said
> it before. Adam was not alone in the Garden of Eden, however, and does
> not deserve all the credit; much is due to Eve, the first woman, and
> Satan, the first consultant." - Mark Twain
>

Similar ThreadsPosted
CA Autoenrollment November 1, 2006, 3:37 pm
Re: Certificate Autoenrollment June 14, 2005, 4:20 pm
Domain Controller Autoenrollment Fails August 4, 2005, 10:42 pm
Question on autoenrollment process with revoked certificate. April 1, 2007, 4:01 am
Question on autoenrollment process with revoked certificate April 1, 2007, 2:03 pm
Microsoft PKI problem with domain controllers (autoenrollment) August 14, 2007, 4:53 am
Autoenrollment problems - Enrollment access is not allowed to this template computer September 1, 2006, 4:01 pm
Certificates, Autoenrollment, Credential Roaming and User's Personal Store April 29, 2008, 10:53 am

The site map in XML format XML site map

Contact Us | Privacy Policy