Web Certificate Enrollment security problem

Web Certificate Enrollment security problem

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Web Certificate Enrollment security problem Franz Schenk 03-15-2006
Posted by Franz Schenk on March 15, 2006, 2:57 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Have a problem that many others have, but haven't found any solution in KB
or another NG Post. There are hints that something has to be ajusted with
dcomcfg, but not any hint what has to be changed.

- Have an enterprise CA on a Windows 2003 SP1 enterprise edition member
server
- Have the Certificate Web Enrollment Website installed on another Windows
2003 SP1 member server
- Have enabled "trust this computer for delegation" on the computer with the
Certificate Enrollment Website according KB 239452
- Rebooted both member servers
- Have tried with either Windows and Basic authentication

When requesting a certificate, after the Website shortly displays
"processing request", the following error appears:

Error


Your request failed. An error occurred while the server was processing your
request.

Contact your administrator for further assistance.



Request Mode:
newreq - New Request
Disposition:
(never set)
Disposition message:
(none)
Result:
Access is denied. 0x80070005 (WIN32: 5)
COM Error Info:
CCertRequest::Submit Access is denied. 0x80070005 (WIN32: 5)
LastStatus:
The operation completed successfully. 0x0 (WIN32: 0)
Suggested Cause:
The Certification Authority Service has not been started.

Thank you all in advance for any suggestions.
Franz



Posted by S. Pidgorny on March 15, 2006, 3:34 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi Franz,

Searching KB for "0x80070005" gives whole heap of problems and solutions -
not exactly like yours but very similar.
I assume that certificate services are running. The problem is most likely
with delegation - check security logs on the IIS and CA to find out how the
account is impersonated, and if the CA client has permissions to the
certificate template. There must be info in the event log on the CA about
the rejected enroillment as well.

Found the best KB for your situation -
http://support.microsoft.com/kb/239452

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

> Have a problem that many others have, but haven't found any solution in KB
> or another NG Post. There are hints that something has to be ajusted with
> dcomcfg, but not any hint what has to be changed.
>
> - Have an enterprise CA on a Windows 2003 SP1 enterprise edition member
> server
> - Have the Certificate Web Enrollment Website installed on another Windows
> 2003 SP1 member server
> - Have enabled "trust this computer for delegation" on the computer with
> the
> Certificate Enrollment Website according KB 239452
> - Rebooted both member servers
> - Have tried with either Windows and Basic authentication
>
> When requesting a certificate, after the Website shortly displays
> "processing request", the following error appears:
>
> Error
>
>
> Your request failed. An error occurred while the server was processing
> your
> request.
>
> Contact your administrator for further assistance.
>
>
>
> Request Mode:
> newreq - New Request
> Disposition:
> (never set)
> Disposition message:
> (none)
> Result:
> Access is denied. 0x80070005 (WIN32: 5)
> COM Error Info:
> CCertRequest::Submit Access is denied. 0x80070005 (WIN32: 5)
> LastStatus:
> The operation completed successfully. 0x0 (WIN32: 0)
> Suggested Cause:
> The Certification Authority Service has not been started.
>
> Thank you all in advance for any suggestions.
> Franz
>



Similar ThreadsPosted
Problem with WLAN IAS certificate enrollment May 16, 2008, 11:51 am
"No Certificate Templates Could Be Found" Error Message When User Requests Certificate from CA Web Enrollment Pages September 21, 2006, 1:33 pm
Certificate Enrollment API: Request on behalf of another user February 13, 2008, 9:02 pm
Certificate Web Enrollment (Server 2003 and Vista) November 14, 2008, 12:16 pm
Publishing a Certificate Authority Enrollment site using SSL + ISA 2004 May 18, 2006, 5:04 pm
Certificate Enrollment on behalf of others on a W2003 Standard Server June 18, 2008, 8:02 am
Problem with certificate authority January 27, 2006, 9:03 am
pfx certificate chain problem March 21, 2006, 6:35 am
Problem in Certificate Authority February 23, 2007, 4:09 am
Certificate problem with Windows Server 2003 May 22, 2006, 12:25 pm

The site map in XML format XML site map

Contact Us | Privacy Policy