The information in this article applies to:
SYMPTOMSYou may not be able to issue certificates using an enterprise Certificate Authority (CA) to users in child domains. When you try to do so, the following entry may appear in the event log:
CAUSEWhen you install a child domain in an existing domain tree with an enterprise CA already configured, the default permissions on the child domain do not allow the enterprise CA to publish certificates from the child domain. RESOLUTION
To resolve this issue, convert the environment to Native mode and change the Cert Publishers group to a universal group instead of a global group.
STATUSMicrosoft has confirmed this to be a problem in the Microsoft products listed at the beginning of this article. MORE INFORMATION
Certificate servers publish certificates to user objects in the Directory service (DS). They are allowed to do this because they are in the Cert Publishers group, which has write access to the 'userCertificate' attribute on the user object. Additional query words:
Keywords : ntsecurity |
Last Reviewed: December 29, 1999 © 2000 Microsoft Corporation. All rights reserved. Terms of Use. |