Domain Controller Certificate Autoenrollment
The domain has two dc s and the first of them has been configured to be the.
Domain controller certificate autoenrollment. These include machine computer domain controller and user certificates. Autoenrollment automatically downloads and manages trusted root certificates cross certificates and ntauth certificates from active directory into the local machine registry for domain joined machines. Computers apply the gpo and download the certificate the next time group policy is refreshed.
On the general tab type a name for the new template then go to the security tab. This combination allows the windows client to enroll users when they log on to their domain or a machine when it boots and keeps them periodically updated between these events. Non domain controllers are getting certificates for winrm and are working as expected and the domain controllers did self generate a few certificates too.
Click ok to save your changes. I have this ad domain where a windows server 2003 sp2 enterprise root certification authority is operational and certificate autoenrollment is enabled both for users and computers. Client to domain controller kerberos port 88 udp tcp.
Double click certificate services client auto enrollment. Right click the certificate templates folder and choose manage. After installing a new microsoft certificate server the event logs on the server 2003 domain controllers displayed an autoenrollment error event id 13 access is denied while on the 2008 domain controllers an event id 13 error with the source certificateservicesclient request or something close.
All fine and good every domain joined computer automatically gets a computer certificate issued. In the properties dialog box change configuration model to enabled. Select both renew expired certificates update pending certificates and remove revoked certificates and update certificates that use certificate templates.
Log in to one of your domain controllers and open the certification authority console. If the domain controller certificate template is not. Hard coded in this case means it is in the code it is not configured in any local or domain based policy.