Solved - Certificate enrollment for Local system failed to enroll for a KerberosAuthentication certificate
on newly-added 2008 r2 replica domain controller, certificate enrollment autoenrollment works, except kerberos authentication certificate. enrollment or autoenrollment request made certificate fails, generating events 6 , 13 in application log. failure reason given in event text "the rpc server unavailable"
the ca receives request; appears in failed request folder. request status code "the rpc server unavailable". request disposition message "denied policy module".
i created duplicate template based on kerberos authentication certificate template, settings same, except on subject name tab, supply in request selected instead of build active directory information. when request made, subject alternative name manually populated same information in standard kerberos authentication certificate (dns name=dcname.domainname.com, dns name=domainname.com, , dns name=netbiosdomainname). certficate request succeeds. makes me think information built active directory missing something.
on pdc role holder, has ca role, enrollment kerberos authentication certificate succeeds.
how correct this?
thanks.
@ arthur_li
thanks reply , detailed suggestions. problem on the dc not enroll kerberos authentication certificate. the file , printer sharing (smb-in) firewall rule was set to block edge traversal (the default). changed allow edge traversal. necessary because nat router between dc , ca.
Windows Server > Security
Comments
Post a Comment