Clients no longer pick up the Root CA as a trusted root authority

Clients no longer pick up the Root CA as a trusted root authority

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Clients no longer pick up the Root CA as a trusted root authority JG 06-06-2006
Posted by JG on June 6, 2006, 6:59 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi
I have an offline root CA running on windows 2003 sp1 standard and 2
issuing enterprise CAs running windows 2003 sp1 enterprise which are
part of our company domain (2000 with 2003 schema extensions).
I went through the standard procedure of publishing the offline root
certificate into Active Directory / its also available from an online
web page as is the crl.
Looking ADSI EDIT i can see the CDP and AIA entries for my offline root
server and issuing ca as i would expect.

When a new client pc is added to the domain it should get our company
root certificate added to its trusted root authority list. This did
work for the first few months after the certificate hierarchy was
installed but now does not seem to work.

Any ideas why a root certificate would no longer auto publish to a
machine in the domain ?

I read a microsoft article about if you disallow authenticated users
from a certificate template this can cause problems for certificate
requests (resolution is to add the ca machine account with permissions
- doesnt seem relevant as im not issuing a cert to the client so doesnt
seem relevant.


Similar ThreadsPosted
Root certificate authority no longer added to client machines December 15, 2006, 8:15 am
Options for Deploying Root and Int Certs to clients not part of do April 29, 2007, 1:50 pm
Updating Trusted Root CA May 6, 2008, 4:31 pm
Renaming a Certificate Root authority June 28, 2006, 5:16 pm
Trusting Certs from Non Trusted root March 23, 2007, 6:38 pm
Convert Enterprise Root CA to Standalone Root CA and create new Subordinate CAs March 19, 2008, 1:45 am
Migrating from single enterprise root CA to different root CA May 11, 2007, 6:43 am
Win2k3 Certificates not accepted as Trusted Authority August 1, 2008, 6:40 am
root ca December 1, 2005, 8:57 am
Root Ca on VM December 5, 2005, 10:23 am

The site map in XML format XML site map

Contact Us | Privacy Policy