P
Paul Landry
Hi All,
I've got a 2003 SP1 server with all of the latest updates ( as of today )
running as a Stand-Alone Certificate Authority.
When I attempt to request certificates for IIS servers, using the Web
Enrollment, I keep getting the following messages.
Your certificate request was denied.
You Request id is xx. The disposition is "Denied by Policy Module"
On the CA machine, in he mmc, I see the rejected certificate requests. They
all say the same thing.
"The permissions on this certification authority do not allow the current
user to enroll for certificates. 0x80094011 (-2146877423)"
The requester name is LAB\IUSR_SPS which is the Anonymous Access user on the
Certificate authority machine.
I've googled the error and checked out several KB's , but nothing I've tried
has solved the problem.
I'm assuming I'm missing the spot where I can give the IUSR account
permissions, but I'll be darned if I can find that spot.
Does anyone have a clue how I can fix this problem?
On last piece of Info, the CA is running on the AD controller, in case that
matters.
TIA,
Paul Landry
IT Manager - Centric Software, Inc.
I've got a 2003 SP1 server with all of the latest updates ( as of today )
running as a Stand-Alone Certificate Authority.
When I attempt to request certificates for IIS servers, using the Web
Enrollment, I keep getting the following messages.
Your certificate request was denied.
You Request id is xx. The disposition is "Denied by Policy Module"
On the CA machine, in he mmc, I see the rejected certificate requests. They
all say the same thing.
"The permissions on this certification authority do not allow the current
user to enroll for certificates. 0x80094011 (-2146877423)"
The requester name is LAB\IUSR_SPS which is the Anonymous Access user on the
Certificate authority machine.
I've googled the error and checked out several KB's , but nothing I've tried
has solved the problem.
I'm assuming I'm missing the spot where I can give the IUSR account
permissions, but I'll be darned if I can find that spot.
Does anyone have a clue how I can fix this problem?
On last piece of Info, the CA is running on the AD controller, in case that
matters.
TIA,
Paul Landry
IT Manager - Centric Software, Inc.