Computer and User Certificates Issues

Computer and User Certificates Issues

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Computer and User Certificates Issues William Teller 09-22-2005
Posted by =?Utf-8?B?V2lsbGlhbSBUZWxsZXI= on September 22, 2005, 9:39 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

I have setup a Windows Server 2003 box in a test environment as a RADIUS
Server using IAS to familiarise with Wireless Networking Authentication (we
are intending to deploy some Windows 2003 systems as RADIUS Servers in the
near future). The authentication method that I am hoping to use is EAP-TLS,
which I understand requires User and Computer Certificates. Hence, I
installed a CA on the Server, and duplicated the User and Computer
Certificate Templates, changing only the Expiration Times. Both Templates
have Authenticated Users with Read Access, Domain Admins with Full Access.
The new User Template has Domain Users with Enroll and AutoEnroll Access and
the same for Computer Template except for Domain Computers group. We have
configured the Domain Level GPO to grant Automatic Certificate Enrollment.
However, when computers in the test environment update Group Policy they all
contain the following events:

Event Type:        Error
Event Source:        AutoEnrollment
Event Category:        None
Event ID:        13
Date:                22/09/2005
Time:                9:54:16 PM
User:                N/A
Computer:        EPT-101
Description:
Automatic certificate enrollment for local system failed to enroll for one
LFN Computer certificate (0x80070005). Access is denied.


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type:        Error
Event Source:        AutoEnrollment
Event Category:        None
Event ID:        13
Date:                22/09/2005
Time:                10:09:49 PM
User:                N/A
Computer:        EPT-201
Description:
Automatic certificate enrollment for local system failed to enroll for one
LFN Computer certificate (0x80070005). Access is denied.


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Where have I gone wrong? These are XP SP2 clients, I previously tried
enabling detailed Enrollment Logging but the additional events provided no
extra information.

Thank-you in advance for all corresspondence,

William Teller

Posted by =?Utf-8?B?Sm9lIE5hdWdodGVu?= on September 22, 2005, 2:18 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
There are two things I would check.

Check your the Windows Firewall settings on the XP SP2 machine. The
Firewall might be blocking the Certificate enrollment.

Also check the subject name settings on the certificate templates that you
have AutoEnroll enabled. See this KB
http://support.microsoft.com/default.aspx?scid=kb;en-us;330238

Joe Naughten
"William Teller" wrote:

> Hello,
>
> I have setup a Windows Server 2003 box in a test environment as a RADIUS
> Server using IAS to familiarise with Wireless Networking Authentication (we
> are intending to deploy some Windows 2003 systems as RADIUS Servers in the
> near future). The authentication method that I am hoping to use is EAP-TLS,
> which I understand requires User and Computer Certificates. Hence, I
> installed a CA on the Server, and duplicated the User and Computer
> Certificate Templates, changing only the Expiration Times. Both Templates
> have Authenticated Users with Read Access, Domain Admins with Full Access.
> The new User Template has Domain Users with Enroll and AutoEnroll Access and
> the same for Computer Template except for Domain Computers group. We have
> configured the Domain Level GPO to grant Automatic Certificate Enrollment.
> However, when computers in the test environment update Group Policy they all
> contain the following events:
>
> Event Type:        Error
> Event Source:        AutoEnrollment
> Event Category:        None
> Event ID:        13
> Date:                22/09/2005
> Time:                9:54:16 PM
> User:                N/A
> Computer:        EPT-101
> Description:
> Automatic certificate enrollment for local system failed to enroll for one
> LFN Computer certificate (0x80070005). Access is denied.
>
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
> Event Type:        Error
> Event Source:        AutoEnrollment
> Event Category:        None
> Event ID:        13
> Date:                22/09/2005
> Time:                10:09:49 PM
> User:                N/A
> Computer:        EPT-201
> Description:
> Automatic certificate enrollment for local system failed to enroll for one
> LFN Computer certificate (0x80070005). Access is denied.
>
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
> Where have I gone wrong? These are XP SP2 clients, I previously tried
> enabling detailed Enrollment Logging but the additional events provided no
> extra information.
>
> Thank-you in advance for all corresspondence,
>
> William Teller

Posted by Steven L Umbach on September 23, 2005, 1:44 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Check your duplicate template for the computer certificate and verify that
domain computers group has read, enroll, and autoenroll permissions. On your
CA use the Management Console for Certificate Authority and look in the
failed requests folder to see if you find anything there that may have more
details on the reason the autoenroll failed. Try requesting a computer
certificate manually on one of the computers while logged on as a local
administrator using the mmc snapin for computer certificates to see if that
works or not. You would need to go to the personal folder, right click and
select all tasks - request new certificate. --- Steve


> Hello,
>
> I have setup a Windows Server 2003 box in a test environment as a RADIUS
> Server using IAS to familiarise with Wireless Networking Authentication
> (we
> are intending to deploy some Windows 2003 systems as RADIUS Servers in the
> near future). The authentication method that I am hoping to use is
> EAP-TLS,
> which I understand requires User and Computer Certificates. Hence, I
> installed a CA on the Server, and duplicated the User and Computer
> Certificate Templates, changing only the Expiration Times. Both Templates
> have Authenticated Users with Read Access, Domain Admins with Full Access.
> The new User Template has Domain Users with Enroll and AutoEnroll Access
> and
> the same for Computer Template except for Domain Computers group. We have
> configured the Domain Level GPO to grant Automatic Certificate Enrollment.
> However, when computers in the test environment update Group Policy they
> all
> contain the following events:
>
> Event Type: Error
> Event Source: AutoEnrollment
> Event Category: None
> Event ID: 13
> Date: 22/09/2005
> Time: 9:54:16 PM
> User: N/A
> Computer: EPT-101
> Description:
> Automatic certificate enrollment for local system failed to enroll for one
> LFN Computer certificate (0x80070005). Access is denied.
>
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
> Event Type: Error
> Event Source: AutoEnrollment
> Event Category: None
> Event ID: 13
> Date: 22/09/2005
> Time: 10:09:49 PM
> User: N/A
> Computer: EPT-201
> Description:
> Automatic certificate enrollment for local system failed to enroll for one
> LFN Computer certificate (0x80070005). Access is denied.
>
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
> Where have I gone wrong? These are XP SP2 clients, I previously tried
> enabling detailed Enrollment Logging but the additional events provided no
> extra information.
>
> Thank-you in advance for all corresspondence,
>
> William Teller



Similar ThreadsPosted
Trojan? Computer security issues October 30, 2006, 12:40 am
User management issues July 20, 2006, 10:50 am
VPN with User Certificates on TPM August 8, 2007, 4:56 pm
Duplicate User Certificates July 20, 2007, 10:22 am
User Permissions Differ from Computer to Computer October 24, 2005, 7:16 pm
Credential Roaming + EFS - how to cleanup user certificates ? May 5, 2008, 2:49 pm
Track user/computer/ip by Caller Logon ID April 28, 2008, 1:20 am
0x80070569: Logon failure: the user has not been granted the requested logon type at this computer. December 22, 2005, 9:06 am
User permission to open Open files in Computer Management May 16, 2008, 4:56 am
Computer cert/User cert 802.x Authentication query August 7, 2007, 5:20 am

The site map in XML format XML site map

Contact Us | Privacy Policy