We just upgraded our first domain controller and run into a hitch. Before the upgrade the serve
was running IAS and supporting clients using certificates from a stand-alone Microsoft CA server
After the upgrade all EAP-TLS clients are rejected with the reason
A certification chain processed correctly, but one of the CA certificates is not trusted by the policy provider
The machine cert and root cert look valid and worked before the upgrade. Other Windows 2000 server
are working using the same root CA and their own machine cert. We built a new 2003 server to se
if the issue was related to a problem with the upgrade, and it fails with the same reason
Is anyone using IAS on 2003 with certificates from a stand-alone Microsoft CA server? Any hints o
which policy provider is not trusting the CA certs? The knowledge based has nothing on this error
outside of the MSDN code samples, and tech support can find similar cases, but no fixes.
|