Certification Authority remote calls problem

Certification Authority remote calls problem

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Certification Authority remote calls problem abolotnov 02-10-2006
Posted by on February 10, 2006, 11:41 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I hope I am targeting a proper group, if not, please suggest another
one.

I am trying to build a asp.net 2.0 web service that will request and
get certificates from three different MS CA services. The whole thing
is done with CERTCLIENTLib.CCertRequestClass and works fine as long as
the web service is located on the same machine with the CA.

My need is to make it call other CA's when I do my
CCertRequestClass.Submit().

As many of you probably guessed, I am getting this while error:

CCertRequest::Submit Access is denied. 0x80070005 (WIN32: 5)

Oh well, I tried to play with target CA security settings and DCOM
settings and turned audit for anything I could and did read everything
I could find on this error message. Nothing really helped.

It seems like the CA machine is just not letting the call to reach the
machine's DCOM. I could get this message in security event log:

Event Type:        Failure Audit
Event Source:        Security
Event Category:        Logon/Logoff
Event ID:        529
Date:                10.02.2006
Time:                19:38:02
User:                NT AUTHORITY\SYSTEM
Computer:        **********
Description:
Logon Failure:
        Reason:                Unknown user name or bad password
        User Name:        ************
        Domain:                *********
        Logon Type:        3
        Logon Process:        NtLmSsp
        Authentication Package:        NTLM
        Workstation Name:        **************
        Caller User Name:        -
        Caller Domain:        -
        Caller Logon ID:        -
        Caller Process ID:        -
        Transited Services:        -
        Source Network Address:        ***.**.***.**
        Source Port:        3766


-------------------------------------

The machines are not on the same domain - it's one of the requirements
to the whole thing.

Can someone suggest an approach or something to get it all to work or
shall I just forget about the idea?


Similar ThreadsPosted
Which certification authority to use July 18, 2005, 4:02 pm
Getting rid of my Certification Authority April 25, 2008, 3:56 pm
Microsoft Certification Authority May 17, 2006, 1:03 pm
The certification authority denied the request. October 11, 2005, 3:08 am
How to clean AD from enterprise certification authority July 10, 2006, 4:53 pm
Certification Authority cannot use certificate template June 12, 2007, 11:44 am
Certification Authority 0x8009480f error April 25, 2008, 9:15 am
Problem with certificate authority January 27, 2006, 9:03 am
Problem in Certificate Authority February 23, 2007, 4:09 am
Winlogon calls October 21, 2005, 12:18 am

The site map in XML format XML site map

Contact Us | Privacy Policy