Enterprise CA May Not Publish Certificates from Child Domain or Trusted Domain

ID: Q219059


The information in this article applies to:
  • Microsoft Windows 2000 Advanced Server
  • Microsoft Windows 2000 Server
  • Microsoft Windows 2000 Datacenter Server


SYMPTOMS

You may not be able to issue certificates using an enterprise Certificate Authority (CA) to users in child domains. When you try to do so, the following entry may appear in the event log:

Event ID: 11
Source: Cert Server Enterprise Policy
Application: Warning CA was unable to publish the certificate for the Domain\server. Server is not part of the Cert Publishers group. Privilege violation.


CAUSE

When you install a child domain in an existing domain tree with an enterprise CA already configured, the default permissions on the child domain do not allow the enterprise CA to publish certificates from the child domain.


RESOLUTION

To resolve this issue, convert the environment to Native mode and change the Cert Publishers group to a universal group instead of a global group.

To work around this issue, use any of the following methods:

  • Manually add the CA computer to the Cert Publishers group on the child domain. This process cannot be performed during Setup because the child domain may not yet exist when the CA is configured.


  • Use the Delegation Wizard to manually add the root domain's Cert Publisher group to every user object in the child domain.



STATUS

Microsoft has confirmed this to be a problem in the Microsoft products listed at the beginning of this article.


MORE INFORMATION

Certificate servers publish certificates to user objects in the Directory service (DS). They are allowed to do this because they are in the Cert Publishers group, which has write access to the 'userCertificate' attribute on the user object.

The problem occurs when a certificate server in one domain tries to issue a certificate to a user in another domain.

Additional query words:

Keywords : ntsecurity
Version : WINDOWS:2000
Platform : WINDOWS
Issue type : kbprb


Last Reviewed: December 29, 1999
© 2000 Microsoft Corporation. All rights reserved. Terms of Use.