locked
Autoenrollment of Computer Certificates failed RRS feed

  • Question

  • Hi,

    I have a Server 2012 R2 DC and a Server 2012 Enterprise CA.

    When I set up an autoenrollment policy (Certificate Services Client - Auto-Enrollment), publish the computer certificate template and grant "Domain Computers" "read" and "autoenroll" rights - everything is working fine!

    When I grant these rights to a custom Computer Group  that contains certain Computer accounts - these Clients do not receive the certificates.

    Any help appreciated!

    Sunday, July 5, 2015 9:22 AM

Answers

  • Hi,

    Pleae make sure that the auto enrollment policy has been applied to the computer properly.

    To check the policy applied on the computer, please run the command below:

    • gpresult /h C:\report.html

    Note: This procedure needs the privilege of domain administrator.

    Best Regards.


    Steven Lee Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact tnmff@microsoft.com.

    Wednesday, July 29, 2015 9:14 AM

All replies

  • Hi,
     
    Am 05.07.2015 11:22, schrieb STEF_XX:
    > When I grant these rights to a custom Computer Group  that contains
    > certain Computer accounts - these Clients do not receive the certificates.
     
    du hast die Computer neugestartet, damit sie auch in der Gruppe sind?
     
    Tschö
    Mark
    --
    Mark Heitbrink - MVP Windows Server - Group Policy
     
    GPO Tool: http://www.reg2xml.com - Registry Export File Converter
     
    Monday, July 6, 2015 8:37 AM
  • Hi,

    Pleae make sure that the auto enrollment policy has been applied to the computer properly.

    To check the policy applied on the computer, please run the command below:

    • gpresult /h C:\report.html

    Note: This procedure needs the privilege of domain administrator.

    Best Regards.


    Steven Lee Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact tnmff@microsoft.com.

    Wednesday, July 29, 2015 9:14 AM