Cannot Request Certificate

Cannot Request Certificate

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Cannot Request Certificate scottflower 02-27-2007
Posted by on February 27, 2007, 7:45 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Clients in a child domain cannot request certificates from the issuing
CA which is located in the root domain.

I get the error The wizard cannot be started because of one or more of
the following conditions:
-There are no trusted certification authorities (CAs) available.
-You do not have permission to request certificates from the available
CAs
-The avaiable CAs issue certificates for which you do not have
permission.

Clients in the root domain can request new certificates.

Permissions on the CA are set that Authenticated Users can request
certificates.

The setup is all Win2003 Servers/AD and XpSP2 Clients


Posted by Nick Domukhovsky on February 28, 2007, 2:48 am
If you were  Registered and logged in, you could reply and use other advanced thread options
scottflower@btinternet.com
> Clients in a child domain cannot request certificates from the issuing
> CA which is located in the root domain.
>
> I get the error The wizard cannot be started because of one or more of
> the following conditions:
> -There are no trusted certification authorities (CAs) available.
Have you intsalled rootCA certificate on the clients? This computers are
in another domain and I think they can't locate rootCA certificate via
LDAP url.

I recommend you try yhis steps:

1. Aquire root certificate and copy it to client computer. Doble click
on it. If you see, that there is no trust to this certificate, then

2. Run certutil -url <cert file name>. Select checkbox "Certs (from AIA)
" and press Retrive button. Look for any errors. Do the same for the
option "CRLs (from CDP)"

3. If somewhere was error post them here :) I'll try to help to correct
them.

If there was no errors, then please give more information about your AD
topology and PKI.



>

--
With best regards
Nickolay Domukhovsky, MCSA

Posted by on February 28, 2007, 4:48 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> scottflo...@btinternet.com> Clients in a child domain cannot request
certificates from the issuing
> > CA which is located in the root domain.
>
> > I get the error The wizard cannot be started because of one or more of
> > the following conditions:
> > -There are no trusted certification authorities (CAs) available.
>
> Have you intsalled rootCA certificate on the clients? This computers are
> in another domain and I think they can't locate rootCA certificate via
> LDAP url.
>
> I recommend you try yhis steps:
>
> 1. Aquire root certificate and copy it to client computer. Doble click
> on it. If you see, that there is no trust to this certificate, then
>
> 2. Run certutil -url <cert file name>. Select checkbox "Certs (from AIA)
> " and press Retrive button. Look for any errors. Do the same for the
> option "CRLs (from CDP)"
>
> 3. If somewhere was error post them here :) I'll try to help to correct
> them.
>
> If there was no errors, then please give more information about your AD
> topology and PKI.
>
>
>
> --
> With best regards
> Nickolay Domukhovsky, MCSA

Both Cert and CRLs show a status of failed, double clicking the URL in
the Retrieval Tool Window give the error "Error retrieving URL: Error
0x80072ee5 (WIN32:12005)

I can open both the Cert and CRL via a browser.

The AD infrastructure consists of a root domain and two child
domains.

The PKI infrastructure is

An offline Root CA
An Enterprise Subordinate CA in the Root domain

I can request a certificate for a Root level account from anywhere in
the forest, I cannot request a certificate from anywhere in the forest
with an account from either child domain.

Thanks
Scott


Posted by on February 28, 2007, 5:27 am
If you were  Registered and logged in, you could reply and use other advanced thread options
On Feb 28, 9:48 am, scottflo...@btinternet.com wrote:
>
>
>
>
>
> > scottflo...@btinternet.com> Clients in a child domain cannot request
certificates from the issuing
> > > CA which is located in the root domain.
>
> > > I get the error The wizard cannot be started because of one or more of
> > > the following conditions:
> > > -There are no trusted certification authorities (CAs) available.
>
> > Have you intsalled rootCA certificate on the clients? This computers are
> > in another domain and I think they can't locate rootCA certificate via
> > LDAP url.
>
> > I recommend you try yhis steps:
>
> > 1. Aquire root certificate and copy it to client computer. Doble click
> > on it. If you see, that there is no trust to this certificate, then
>
> > 2. Run certutil -url <cert file name>. Select checkbox "Certs (from AIA)
> > " and press Retrive button. Look for any errors. Do the same for the
> > option "CRLs (from CDP)"
>
> > 3. If somewhere was error post them here :) I'll try to help to correct
> > them.
>
> > If there was no errors, then please give more information about your AD
> > topology and PKI.
>
> > --
> > With best regards
> > Nickolay Domukhovsky, MCSA
>
> Both Cert and CRLs show a status of failed, double clicking the URL in
> the Retrieval Tool Window give the error "Error retrieving URL: Error
> 0x80072ee5 (WIN32:12005)
>
> I can open both the Cert and CRL via a browser.
>
> The AD infrastructure consists of a root domain and two child
> domains.
>
> The PKI infrastructure is
>
> An offline Root CA
> An Enterprise Subordinate CA in the Root domain
>
> I can request a certificate for a Root level account from anywhere in
> the forest, I cannot request a certificate from anywhere in the forest
> with an account from either child domain.
>
> Thanks
> Scott- Hide quoted text -
>
> - Show quoted text -

Apologies,

Correction to the previous submission, the Certutil tests do work
fine, I had a typo error in the string.


Posted by Nick Domukhovsky on February 28, 2007, 8:43 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I think this would help: http://support.microsoft.com/kb/281271


--
With best regards
Nickolay Domukhovsky, MCSA

Similar ThreadsPosted
LDAPS--certificate request February 3, 2006, 12:44 pm
Certificate Request Question March 3, 2006, 10:31 am
Certificate request only 2 years December 5, 2007, 9:59 am
Permissions requried to request a certificate. September 8, 2008, 9:07 pm
Automatic Certificate Request Setup Wizard May 24, 2006, 4:41 am
MS PKI: Special Subject Fields in certificate Request September 24, 2007, 6:04 am
How to request client certificate, non domain computers December 5, 2007, 9:39 am
Certificate Enrollment API: Request on behalf of another user February 13, 2008, 9:02 pm
how to issue certificates based on the content of certificate request January 25, 2008, 5:28 pm
Certificate request file syntex for critical extensions February 27, 2008, 12:29 pm

The site map in XML format XML site map

Contact Us | Privacy Policy