Unanswered CA template issue

  • 2012年4月26日 10:06
     
     

    Hi

    I am running an enterprise CA on windows 2000.I want to issue a new certificate to one of my web server.

    When I try to select the web server certificate template from the certification authority, the following error pops up:

    "The template information on the CA cannot be modified at this time. This is most likely because the CA service is not running or there are replication delays.One or more certificate templates to be enabled on this certification authority could not be found 0x80094813 (-2146875373)

    The changes can be saved to Active Directory and retrieved by the CA next time it is started.Do you want to save the changes to Active Directory?"

    Microsoft support pages says the authenticated users have to be a member in the security group of the CA and have read access to the CA. But it is already enabled in my scenario. 

    Does anyone have a different thought or a solution. Appreciate it

    Thanks

すべての返信

  • 2012年4月26日 12:20
     
     

    I would use the Certificate Template Manager or ADSIedit to verify the integrity of the certificate template information that is stored in Active Directory.

    Also check that you haven't deleted a Certificate Template that the CA expects to be using...

    Cheers

    JJ


    Jason Jones | Forefront MVP | Silversands Ltd | My Blogs: http://blog.msedge.org.uk and http://blog.msfirewall.org.uk

  • 2012年4月27日 2:33
     
     

    The certificate template is available in the AD. 

    I can issue all templates except the web server template.

    FYI, my AD is server 2008 and CA is server 2000.

    Regards

  • 2012年4月27日 5:48
     
     

    How are you attempting to request the certificate?

    How is the subject configured for the certificate template?

    Brian

  • 2012年5月2日 2:34
     
     

    Log into certification authority, under certificate templates, click on new template to issue.

    When I try to issue template for web server it comes up with the above error.

     All other templates can be successfully issued.

  • 2012年5月7日 11:22
    モデレータ
     
     

    Hi,

    Please also verify Active Directory Replication:

    Verify Active Directory Replication

    http://technet.microsoft.com/en-us/library/cc816863(v=ws.10).aspx

    Then, restart certificate service and test the problem again.