Networking Forums

Networking Forums > Computer Networking > Windows Networking > Autoenrollment/Renewing Certificates across a VPN

Reply
Thread Tools Display Modes

Autoenrollment/Renewing Certificates across a VPN

 
 
Edward Ray
Guest
Posts: n/a

 
      07-06-2005, 03:37 AM
This is a Windows 2003 SP1/Windows XP SP2 native Active directory domain
with two sites.

I have a two tier PKI infrastructure, a standalone root CA servicing a
enterprise subordinate CA. I recently had to renew my sub CA certificate.
This occurred without incident, as did the autoenrollment feature on the
other computers in my LAN. However autoenrollment is failing on the
computers in the other site. The other site has a single domain controller
and XP machines connected via VPN tunnel (Netscreen devices).

I looked at the packet dumps and it is failing on port 135 connections.
The standard SYN, SYN/ACK, ACK works fine and a connection is established on
port 135 between the computer in the other site (for this case the domain
controller) and the enterprise subCA. Then a BIND request is initiated,
followed by a bunch of TCP retransmissions. The request eventually times
out with a "Certificate Request Failed, you do not have permissions to
request certificates from the available CAs"

I would like to solve the above problem, but I have a more immediate need of
manual certificate renewal, since these certificates expire on July 7th.

What would be the command to request certificates manually on the subCA
itself? I need the "IPSec" "Domain Controller" and "Domain Controller
Authentication" certificates for computer "xxx.domainname.local"

Thanks in advance!

Edward Ray


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Renewing Ip adress Jon GIll Wireless Networks 1 10-15-2006 08:40 PM
PLEASE HELP: Autoenrollment Failure (0x80070005) for Additional Domain Controller W2K3 Neil Hobbs Windows Networking 1 11-21-2005 05:16 PM
Ip Address Not Renewing Seth Thompson Wireless Networks 2 06-23-2005 09:27 PM
IP Not Renewing Poppa Earl Wireless Networks 0 05-12-2005 02:42 PM
Not renewing IP address David Wireless Networks 0 07-18-2004 02:38 PM



1 2 3 4 5 6 7 8 9 10 11