Problem with an Enterprise Certificate Server-It got added by acci

  • Thread starter Thread starter Coyote
  • Start date Start date
C

Coyote

So, I had a domain that was Windows 200 based. I went through all the
process of upgrading to Windows 2003 and have both forest and domain raised
to 2003. Things were working great for a couple of months. Then we needed
to add a new Windows 2003 server. When it was built, the installer installed
leterally every package available from the R2 disk. One of those features
was Certificate Server. Now I am getting weird KDC errors and errors in
event log that say the certificate server is unavailable. The service was
disabled on the new server after install and joining to the domain. What
should I do? When I go to Certificates on my domain controllers I see teh
original cert for the box and I see a new one that the certificate server
deployed. How do I clean this up? Should I remove the certificates form all
my machines? I just want my domain back to how it was before this
certificate server was added.

Any help truly appreciated!

Thanks,
Wiley
 
Hello coyote,

Please post the complete error message from the event viewer.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
 
EventID 20
KDC
The currently selected KDC certificate was once valid, but now is invalid
and no suitable replacement was found. Smartcard logon may not function
correctly if this problem is not remedied. Have the system administrator
check on the state of the domain's public key infrastructure. The chain
status is in the error data.

DCOM Errors
DCOM got error "General access denied error " from the computer
firewall.office.work.com when attempting to activate the server:
{D99E6E74-FC88-11D0-B498-00A0C90312F3}
 
Excellent!

Thank you!

The CA has not been removed from AD yet though.
I just stopped and disabled teh service on the offending machine.

Do all the same fixes still apply?
Do I need to remove teh CA from AD?

Thanks!
Wiley
 
Back
Top