Certificates and Kerberos
I'm a newbie to server admin in general so this is probably an easy fix, I'm just not sure how to ask the question, but here goes...I'm running 2 servers, both running 2008 standard, but one of them is a Core RODC. I was getting errors in my AD event logs telling me to basically install the AD Certificate Services, which I did and all seems well with the world, but don't I have to install the CA Certificate on the Core RODC? If so how do I do this and verify it is working ok?I issued the: "certutil -dcinfo -urlfetch" on the core server and it verified that the PDC had a valid certificate, but the core came up with the following message:No certs in Ent Root store!Enterprise Root store: Cannot find object or property. 0x80092004 (-2146885628)Any help would be great.
August 18th, 2008 7:10pm

Hi, You need to install the CA certificate on the Core RODC. The message No certs in Ent Root store! indicates that the CA certificate has not been import to the Enterprise Root Store. Please run the following command to manually import the certificate on the Core RODC: certutil -enterprise -addstore NTAuth CA_CertFilename.cer certutil -enterprise -addstore Root CA_CertFilename.cerAdditionally, please ensure that Auto-Enrollment is not disabled in the domain and run "gpupdate /force" on the RODC.
Free Windows Admin Tool Kit Click here and download it now
August 20th, 2008 12:37pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics