Welcome to ServerForumz.com!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Root certificate authority no longer added to client machi..

 
   Windows Server (Home) -> Windows Server Security RSS
Next:  Problems with Enterprise CA  
Author Message
NothingtoSay?

External


Since: Jul 14, 2006
Posts: 1



(Msg. 1) Posted: Fri Jul 14, 2006 1:05 pm
Post subject: Root certificate authority no longer added to client machines
Archived from groups: microsoft>public>windows>server>security (more info?)

Hi all,

Our PKI is based on 2003 and using an offline root and issuing CAs.
All worked fine but about a month a go it developed a slight issue.

Whilst i can see the offline root cert is in AD under the correct node
(looking through adsiedit) and it is still valid (10yr validity)
when i add a new computer to the domain it does not get the root cert
added to the client pcs trusted store.

my two thoughts are to
1. republish the same certificate using certutil -dspublish
2. to use the thority gpo setting on the domain policy

Any comments ?
or better suggestions
Jonathan

 >> Stay informed about: Root certificate authority no longer added to client machi.. 
Back to top
Login to vote
"S. Pidgorny

External


Since: Oct 09, 2003
Posts: 160



(Msg. 2) Posted: Sun Jul 16, 2006 9:45 pm
Post subject: Re: Root certificate authority no longer added to client machines [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

I'd try both 1 and 2 - one will work for sure.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

"NothingtoSay?" wrote in message

> Hi all,
>
> Our PKI is based on 2003 and using an offline root and issuing CAs.
> All worked fine but about a month a go it developed a slight issue.
>
> Whilst i can see the offline root cert is in AD under the correct node
> (looking through adsiedit) and it is still valid (10yr validity)
> when i add a new computer to the domain it does not get the root cert
> added to the client pcs trusted store.
>
> my two thoughts are to
> 1. republish the same certificate using certutil -dspublish
> 2. to use the thority gpo setting on the domain policy
>
> Any comments ?
> or better suggestions
> Jonathan
>

 >> Stay informed about: Root certificate authority no longer added to client machi.. 
Back to top
Login to vote
StuartH

External


Since: Dec 14, 2006
Posts: 2



(Msg. 3) Posted: Thu Dec 14, 2006 3:20 am
Post subject: Re: Root certificate authority no longer added to client machines [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Did either of these work Jonathan?

The reason I ask is, funny enough, we have the same issue. I have read as
many articles/KB that I can and would like some clarification if anyone can,
PLEASE!!.

We have a standalone RootCA, with Enterprise issuing CAs. We have ran
DSpublish for the RootCA into the AD, but clients do not get entries added to
their trusted store. From what I understand, and read many times is things
like "When you install an enterprise root CA or a stand-alone root CA, the
certificate of the CA is added automatically to the Trusted Root
Certification Authorities Group Policy for the domain.". Well, if this is a
standalone Root, how the heck does it put it into a GPO ? Another article
states, that if the client is a domain member, then they will automatically
receive the CAs in the trusted store....but negates to say how.

So...in a complete Microsoft world (RootCA, SubEntCAs and clients)...how
does the trusted store get populated on a client ? Do you need a GPO or not ?
Thanks

Stuart

"S. Pidgorny <MVP>" wrote:

> I'd try both 1 and 2 - one will work for sure.
>
> --
> Svyatoslav Pidgorny, MS MVP - Security, MCSE
> -= F1 is the key =-
>
> "NothingtoSay?" wrote in message
>
> > Hi all,
> >
> > Our PKI is based on 2003 and using an offline root and issuing CAs.
> > All worked fine but about a month a go it developed a slight issue.
> >
> > Whilst i can see the offline root cert is in AD under the correct node
> > (looking through adsiedit) and it is still valid (10yr validity)
> > when i add a new computer to the domain it does not get the root cert
> > added to the client pcs trusted store.
> >
> > my two thoughts are to
> > 1. republish the same certificate using certutil -dspublish
> > 2. to use the thority gpo setting on the domain policy
> >
> > Any comments ?
> > or better suggestions
> > Jonathan
> >
>
>
>
 >> Stay informed about: Root certificate authority no longer added to client machi.. 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
How to install a new Enterprise Root Certificate Authority.. - Hello all, We have an Enterprise Root Certificate Authority on an old W2k domain controller that will be decommissioned and replaced with a new Windows Server 2003 DC with a different name. From what I've read on Google and on Microsoft there is no...

Finding out which account added a workstation to the AD... - See subject. Any way to determine this? Regards, Brian Steele

Certificates MMC does request the newly added/modified tem.. - Hello, I have added a certificate template to the CA (by duplicating IPSec (offline request)). The template has now modified security for Authenticated Users=Entroll, Administrators=Entroll, DomainComputers=Enroll. Request handling CSP is set up to..

URGENT -- NT AUTHORITY ids !!!!! - I have an overzealous admin that thought that the NT AUTHORITY\INTERACTIVE and NT AUTHORITY\Authenticated Users were left over from NT4 days so he removed them from the USERS group on my 2003/2000 servers... Now some are broke... How can we add them..

Move certificate authority - Hi, I wish to move a windows 2003 enterprise based CA from one server to another, and i just want to verify the process with some of you knowledgable type people. Certificate usage - Provides certificates to web servers that are accesable to the..
   Windows Server (Home) -> Windows Server Security All times are: Pacific Time (US & Canada)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]