Certificate (auto)enrollment works for all servers and clients except for domain controllers
-
Thursday, July 05, 2012 6:42 AM
I have been in the process of setting up a PKI with root and issuing CA's. The (auto)enrollment works perfectly, except for the DC's in the environment. The error in the application log is: The RPC server is unavailable. 0x800706ba (WIN32: 1722).
Why can't the DC's connect the CA server, while the other servers and clients can? What am I overlooking?
Regards,
StephanYou know you're an engineer when you have no life and can prove it mathematically
All Replies
-
Thursday, July 05, 2012 7:08 AM
When giving "Domain Controllers" explicite permissions in the local security settings (via GPO) "DCOM: Machine Access Restrictions in Security Descriptor Definition Language" and "DCOM: Machine Launch Restrictions in Security Descriptor Definition Language", the RPC error disappears. Now the event changes to: Access is denied. 0x80070005 (WIN32: 5)
After making the "domain controllers"group member of the "Certificate Service DCOM Access" group and rebooting the CA servers, it works!
- Edited by Stephan van der Plas Thursday, July 05, 2012 7:35 AM
- Marked As Answer by Stephan van der Plas Thursday, July 05, 2012 7:35 AM
-
Friday, July 06, 2012 4:34 AMModerator
Hi Stephan,
I'm glad to hear that you have the problem solved. Your shared experience and solution are appreciated. They can be helpful to other community members who face similar problems.
Have a nice day.
Best Regards
KevinIf you are TechNet Subscription user and have any feedback on our support quality, please send your feedback here.
-
Friday, July 06, 2012 6:41 AM
Kevin,
the thing I actually never realized is that "domain controllers" is not a member of "domain computers". At least in my environment. Is that normal in an Windows 2008 R2 native AD DS domain?
You know you're an engineer when you have no life and can prove it mathematically
-
Friday, July 06, 2012 7:44 AMModerator
Hi Stephan,
It is by design.
The Domain Computers group contains all member servers and workstations in a domain.
The Domain Controllers group contains all domain controllers in a domain.
Regards
Kevin
If you are TechNet Subscription user and have any feedback on our support quality, please send your feedback here.
- Edited by K_evin ZhuMicrosoft Contingent Staff, Moderator Friday, July 06, 2012 7:44 AM
- Marked As Answer by K_evin ZhuMicrosoft Contingent Staff, Moderator Monday, July 09, 2012 4:41 AM

