certificate Services will not startup on specified port

certificate Services will not startup on specified port

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
certificate Services will not startup on specified port Billy 05-08-2008
Posted by Billy on May 8, 2008, 5:02 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello All,
I hope you can help:

I keep seeing errors when I setup a Enterprise CA. The Certsvc
request
is configured in component services to utilize port 2000 (lets say),
and rpc ports are restricted to a range of ports. (usually 100
ports are allocated). However, The CA process is usually found on a
port in the rpc range
instead of being on the port specifically allocated to it (2000).


This causes Autoenrollment of certificates to not occur unless i
reset
the configuration in component services to default.


Upon further investigation, i found that the DHCP server service
loves
to
grab the 2000 port, and this then forces forces the CA service to
take a port within the rpc range. The
question becomes: Can I force the CA to always grab port 2000 before
anything else takes it?


thanks in advance.



Posted by Brian Komar \(MVP\) on May 8, 2008, 5:26 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
why are you changing the default configuration?
What risk are you trying to mitigate.
You mention that the configuration works when running in the default
configuration.
Why change something that works?
Brian

> Hello All,
> I hope you can help:
>
> I keep seeing errors when I setup a Enterprise CA. The Certsvc
> request
> is configured in component services to utilize port 2000 (lets say),
> and rpc ports are restricted to a range of ports. (usually 100
> ports are allocated). However, The CA process is usually found on a
> port in the rpc range
> instead of being on the port specifically allocated to it (2000).
>
>
> This causes Autoenrollment of certificates to not occur unless i
> reset
> the configuration in component services to default.
>
>
> Upon further investigation, i found that the DHCP server service
> loves
> to
> grab the 2000 port, and this then forces forces the CA service to
> take a port within the rpc range. The
> question becomes: Can I force the CA to always grab port 2000 before
> anything else takes it?
>
>
> thanks in advance.
>
>


Similar ThreadsPosted
Certificate Services Port and Protocol Requirements April 2, 2007, 4:34 am
Generic Host process for win32 services listening to port: tcp: 135 November 6, 2006, 6:03 am
Certificate Services August 3, 2005, 12:22 pm
Certificate Services? August 31, 2005, 8:42 pm
Certificate Services September 5, 2005, 7:01 am
Remove Certificate services June 24, 2005, 7:43 pm
Certificate Services Performance --- August 1, 2005, 10:24 am
Certificate Services: Key Archival November 22, 2005, 4:39 am
Moving Certificate Services May 3, 2007, 8:29 am
Difference in Certificate Services June 11, 2007, 5:21 am

The site map in XML format XML site map

Contact Us | Privacy Policy