Windows XP cannot autoenroll to Server 2012R2 CA, RPC error


hi, have been working on day !! hope can point me in correct direction.

we have fewl legacy xp machines left not connect our new 2012r2 ca.

the ca working fine , other workstations autoenrolling without issues (vista , 7 , 8)

i've downgraded security on ca per microsoft article, certificate templates xp compatible too.

the error id 13, 0x800706ba (win32 : 1722)

when running certutil -ping -config xyxyy.com\xyyg-server-ca

i can ping ca server , dns resolves. i've check dcom settings, looks ok.

so stuck :( , great appricated.

kind regards

mark

another possibility ca certificate uses unsupported public key algorithm (ecc/ecdsa) or signature algorithm (rsassa-pss, example). can confirm ca cert algorithms?

vadims podāns, aka powershell cryptoguy
weblog: en-us.sysadmins.lv
powershell pki module: pspki.codeplex.com
powershell cmdlet editor pscmdlethelpeditor.codeplex.com
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.



Windows Server  >  Security



Comments

Popular posts from this blog

DCOM received error "2147746132" from...

DFSR RPC replication errors 5014 1726 with large files over VPN

ADFS 3.0 Event ID 4625 | An Error occurred During Logon | Status: 0xC000035B