Domain certificate error

Hello,

I have installed a entreprise CA on my new domain. I see that all my
DC recieved a Domain Controler certificate except one.

If I check the log I can see two event :

First : Eventid 6 :

 Automatic certificate enrollment for local system failed (0x800706ba)
The RPC server is unavailable.

Second : EventID 13 : 

Certificate enrollment for Local system failed to enroll for a
DomainController certificate with request ID N/A from
DCSHDCT02.mydomaint.local\mydomain-DCSHDCT02-CA (The RPC server is
unavailable. 0x800706ba (WIN32: 1722)).

The message seems to be clear, but if i try to do a telnet one
DCSHDCT02 I can see a connection! Then, I can say the RPC server is on
and working well.

Can anybody help me?


--- news://freenews.netfront.net/ - complaints: news@netfront.net ---
0
jithurbide
1/29/2010 1:21:40 PM
windows.server.active_director 902 articles. 0 followers. Follow

37 Replies
9416 Views

Similar Articles

[PageSpeed] 5

<jithurbide@gmail.com> wrote in message 
news:rln5m5p9hg7qq6agbjrnqag382s1ho5k3j@4ax.com...
> Hello,
>
> I have installed a entreprise CA on my new domain. I see that all my
> DC recieved a Domain Controler certificate except one.
>
> If I check the log I can see two event :
>
> First : Eventid 6 :
>
> Automatic certificate enrollment for local system failed (0x800706ba)
> The RPC server is unavailable.
>
> Second : EventID 13 :
>
> Certificate enrollment for Local system failed to enroll for a
> DomainController certificate with request ID N/A from
> DCSHDCT02.mydomaint.local\mydomain-DCSHDCT02-CA (The RPC server is
> unavailable. 0x800706ba (WIN32: 1722)).
>
> The message seems to be clear, but if i try to do a telnet one
> DCSHDCT02 I can see a connection! Then, I can say the RPC server is on
> and working well.
>
> Can anybody help me?


It's more than just telnet. The RPC server is unavailable message simply 
means it either cannot fully communicate with the necessary ports to the 
server, DNS cannot resolve all necessary records (SRV and "A" records), or 
the server is completely down. Since you can telnet, then it's indicating 
the server is up but there are possibly some firewall ports blocked. Within 
a private infrastructure, it is assumed that all ports are allowed and 
opened between all servers and workstations.

I remember you said you 'changed your firewall strategy' in another thread 
regarding your Sites issues. What exactly is your new strategy?

-- 
Ace

This posting is provided "AS-IS" with no warranties or guarantees and 
confers no rights.

Please reply back to the newsgroup or forum for collaboration benefit among 
responding engineers, and to help others benefit from your resolution.

Ace Fekay, MVP, MCT, MCITP EA, MCTS Windows 2008 & Exchange 2007, MCSE & 
MCSA 2003/2000, MCSA Messaging 2003
Microsoft Certified Trainer
Microsoft MVP - Directory Services

If you feel this is an urgent issue and require immediate assistance, please 
contact Microsoft PSS directly. Please check http://support.microsoft.com 
for regional support phone numbers. 


0
Ace
1/29/2010 3:19:57 PM
Hi
To test do a SMB connection: "\\CAName.yourdomain.tld" from that DC. IF it 
asks for authentication credentials, you may have a FW issue, name 
resolution problems (from CA side or DC side). A workaround for this may be 
to cache the credentials on DC side (using the option save the credentials 
when you're doing the SMB connection).

-- 

I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MVP Directory Services

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.




<jithurbide@gmail.com> wrote in message 
news:rln5m5p9hg7qq6agbjrnqag382s1ho5k3j@4ax.com...
> Hello,
>
> I have installed a entreprise CA on my new domain. I see that all my
> DC recieved a Domain Controler certificate except one.
>
> If I check the log I can see two event :
>
> First : Eventid 6 :
>
> Automatic certificate enrollment for local system failed (0x800706ba)
> The RPC server is unavailable.
>
> Second : EventID 13 :
>
> Certificate enrollment for Local system failed to enroll for a
> DomainController certificate with request ID N/A from
> DCSHDCT02.mydomaint.local\mydomain-DCSHDCT02-CA (The RPC server is
> unavailable. 0x800706ba (WIN32: 1722)).
>
> The message seems to be clear, but if i try to do a telnet one
> DCSHDCT02 I can see a connection! Then, I can say the RPC server is on
> and working well.
>
> Can anybody help me?
>
>
> --- news://freenews.netfront.net/ - complaints: news@netfront.net ---  

0
Jorge
1/30/2010 11:43:01 PM
Hello,


> I remember you said you 'changed your firewall strategy' in another thread 
> regarding your Sites issues. What exactly is your new strategy?

Ok fist I have block all trafics execpt for AD port. But, I discover that 
with winsows 2008 r2 Ad need to have a range of port open. Then I open IP 
communication between all DC! Then, I can say that it's not a problem with 
my firewall!

Julien
 

0
Julien
2/1/2010 12:08:27 PM
Hello,

You say :

> To test do a SMB connection: "\\CAName.yourdomain.tld" from that DC.

What is the CAName ? My computer name ? like dcshdct02 ? or the name I can 
see on the Certification authority MMC?

I can browse the CA with the comupter name \\dcshdct02 but not the name I 
see on the CA MMC.

Julien
 

0
Julien
2/1/2010 12:12:25 PM
"Julien" <jithurbide@removegmail.com> wrote in message 
news:Od9jrizoKHA.5260@TK2MSFTNGP02.phx.gbl...
> Hello,
>
>
>> I remember you said you 'changed your firewall strategy' in another 
>> thread regarding your Sites issues. What exactly is your new strategy?
>
> Ok fist I have block all trafics execpt for AD port. But, I discover that 
> with winsows 2008 r2 Ad need to have a range of port open. Then I open IP 
> communication between all DC! Then, I can say that it's not a problem with 
> my firewall!
>
> Julien
>
>


There are numerous ports that AD needs, as you know. Usually we just open it 
up wide open and let it have everything, otherwise if you try to make port 
exceptions in a firewall, it turns it into Swiss cheese anyway.

Can you post exactly what ports you opened up? Also, if you followed an 
article on what ports to open, can you post the article you followed?

Ace


0
Ace
2/1/2010 4:21:56 PM
"Julien" <jithurbide@removegmail.com> wrote in message 
news:uOaW1izoKHA.5260@TK2MSFTNGP02.phx.gbl...
> Hello,
>
> You say :
>
>> To test do a SMB connection: "\\CAName.yourdomain.tld" from that DC.
>
> What is the CAName ? My computer name ? like dcshdct02 ? or the name I can 
> see on the Certification authority MMC?
>
> I can browse the CA with the comupter name \\dcshdct02 but not the name I 
> see on the CA MMC.
>
> Julien
>
>


The CAName is the computer name of your CA (Certificate Authority) server.

Is dcshdct02 the name of the CA? If so, what do you mean by can't browse by 
the name in the CA MMC console? what name is that?

Ace 


0
Ace
2/1/2010 4:23:28 PM
Hello,

First I have open the port TCP/UDP:

1025
1030
123
135
139
3268
389
445
49155
49159
88
53
750

But now, I have open all TCP/UDP trafic !!!!!



"Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in message 
news:eFvusq1oKHA.4836@TK2MSFTNGP05.phx.gbl...
> "Julien" <jithurbide@removegmail.com> wrote in message 
> news:Od9jrizoKHA.5260@TK2MSFTNGP02.phx.gbl...
>> Hello,
>>
>>
>>> I remember you said you 'changed your firewall strategy' in another 
>>> thread regarding your Sites issues. What exactly is your new strategy?
>>
>> Ok fist I have block all trafics execpt for AD port. But, I discover that 
>> with winsows 2008 r2 Ad need to have a range of port open. Then I open IP 
>> communication between all DC! Then, I can say that it's not a problem 
>> with my firewall!
>>
>> Julien
>>
>>
>
>
> There are numerous ports that AD needs, as you know. Usually we just open 
> it up wide open and let it have everything, otherwise if you try to make 
> port exceptions in a firewall, it turns it into Swiss cheese anyway.
>
> Can you post exactly what ports you opened up? Also, if you followed an 
> article on what ports to open, can you post the article you followed?
>
> Ace
>
> 
0
Julien
2/2/2010 8:59:29 AM
Hello,

In fact, the computer name is dcshdct02, but if I open the certification 
authority MMC, the name of the server is : mydomain-DCSHDCT02-CA.



"Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in message 
news:#Yp$jr1oKHA.4836@TK2MSFTNGP05.phx.gbl...
> "Julien" <jithurbide@removegmail.com> wrote in message 
> news:uOaW1izoKHA.5260@TK2MSFTNGP02.phx.gbl...
>> Hello,
>>
>> You say :
>>
>>> To test do a SMB connection: "\\CAName.yourdomain.tld" from that DC.
>>
>> What is the CAName ? My computer name ? like dcshdct02 ? or the name I 
>> can see on the Certification authority MMC?
>>
>> I can browse the CA with the comupter name \\dcshdct02 but not the name I 
>> see on the CA MMC.
>>
>> Julien
>>
>>
>
>
> The CAName is the computer name of your CA (Certificate Authority) server.
>
> Is dcshdct02 the name of the CA? If so, what do you mean by can't browse 
> by the name in the CA MMC console? what name is that?
>
> Ace
> 
0
Julien
2/2/2010 9:02:59 AM
"Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
news:%239DAJY%23oKHA.5328@TK2MSFTNGP04.phx.gbl...
> Hello,
>
> First I have open the port TCP/UDP:
>
> 1025
> 1030
> 123
> 135
> 139
> 3268
> 389
> 445
> 49155
> 49159
> 88
> 53
> 750
>
> But now, I have open all TCP/UDP trafic !!!!!

That's good you opened all traffic. There are more ports that are required 
than you posted. That was why you got the errors. You were missing the 
Service ports.

For more information on ports required, please read the following to 
understand better what ports AD requires. It's not as simple as the ports 
you mentioned. That was why I was saying it is easier just to allow ALL 
ports, for after all, if it is an internal private network, you are safe 
anyway.

Paul Bergson's Blog on AD Replication and Firewall Ports
http://www.pbbergs.com/windows/articles/FirewallReplication.html

Restricting Active Directory replication traffic and client RPC 
....Restricting Active Directory replication traffic and client RPC traffic 
to a ... unique port, and you restart the Netlogon service on the domain 
controller. ...
http://support.microsoft.com/kb/224196

How to restrict FRS replication traffic to a specific static port - How to 
restrict FRS replication traffic to a specific static port ... Windows 
2000-based domain controllers and servers use FRS to replicate system policy 
....
http://support.microsoft.com/kb/319553

Network Ports Used by Key Microsoft Server Products - You can also restrict 
the range of ports that RPC dynamically assigns to a small range, ..... 
Windows domain controllers use the SMTP service for intersite ...
http://www.microsoft.com/smallbusiness/support/articles/ref_net_ports_ms_prod.mspx

Ace



0
Ace
2/2/2010 5:05:35 PM
"Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
news:OoKFGa%23oKHA.1548@TK2MSFTNGP02.phx.gbl...
> Hello,
>
> In fact, the computer name is dcshdct02, but if I open the certification 
> authority MMC, the name of the server is : mydomain-DCSHDCT02-CA.
>

That appears to be the CA name you gave it, not the computer name.

Ace



0
Ace
2/2/2010 5:06:41 PM
Hi
Yes, test the connection using \\dcshdct02


-- 

I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MVP Directory Services

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.




"Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
news:OoKFGa#oKHA.1548@TK2MSFTNGP02.phx.gbl...
> Hello,
>
> In fact, the computer name is dcshdct02, but if I open the certification 
> authority MMC, the name of the server is : mydomain-DCSHDCT02-CA.
>
>
>
> "Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in 
> message news:#Yp$jr1oKHA.4836@TK2MSFTNGP05.phx.gbl...
>> "Julien" <jithurbide@removegmail.com> wrote in message 
>> news:uOaW1izoKHA.5260@TK2MSFTNGP02.phx.gbl...
>>> Hello,
>>>
>>> You say :
>>>
>>>> To test do a SMB connection: "\\CAName.yourdomain.tld" from that DC.
>>>
>>> What is the CAName ? My computer name ? like dcshdct02 ? or the name I 
>>> can see on the Certification authority MMC?
>>>
>>> I can browse the CA with the comupter name \\dcshdct02 but not the name 
>>> I see on the CA MMC.
>>>
>>> Julien
>>>
>>>
>>
>>
>> The CAName is the computer name of your CA (Certificate Authority) 
>> server.
>>
>> Is dcshdct02 the name of the CA? If so, what do you mean by can't browse 
>> by the name in the CA MMC console? what name is that?
>>
>> Ace
>> 
0
Jorge
2/2/2010 9:50:58 PM
Hello,


I have tested and it's working !



"Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
news:9A0DEBC9-0F64-4EA7-9A5C-5A21FE44642E@microsoft.com...
> Hi
> Yes, test the connection using \\dcshdct02
>
>
> -- 
>
> I hope that the information above helps you.
> Have a Nice day.
>
> Jorge Silva
> MVP Directory Services
>
> Please no e-mails, any questions should be posted in the NewsGroup
> This posting is provided "AS IS" with no warranties, and confers no 
> rights.
>
>
>
>
> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
> news:OoKFGa#oKHA.1548@TK2MSFTNGP02.phx.gbl...
>> Hello,
>>
>> In fact, the computer name is dcshdct02, but if I open the certification 
>> authority MMC, the name of the server is : mydomain-DCSHDCT02-CA.
>>
>>
>>
>> "Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in 
>> message news:#Yp$jr1oKHA.4836@TK2MSFTNGP05.phx.gbl...
>>> "Julien" <jithurbide@removegmail.com> wrote in message 
>>> news:uOaW1izoKHA.5260@TK2MSFTNGP02.phx.gbl...
>>>> Hello,
>>>>
>>>> You say :
>>>>
>>>>> To test do a SMB connection: "\\CAName.yourdomain.tld" from that DC.
>>>>
>>>> What is the CAName ? My computer name ? like dcshdct02 ? or the name I 
>>>> can see on the Certification authority MMC?
>>>>
>>>> I can browse the CA with the comupter name \\dcshdct02 but not the name 
>>>> I see on the CA MMC.
>>>>
>>>> Julien
>>>>
>>>>
>>>
>>>
>>> The CAName is the computer name of your CA (Certificate Authority) 
>>> server.
>>>
>>> Is dcshdct02 the name of the CA? If so, what do you mean by can't browse 
>>> by the name in the CA MMC console? what name is that?
>>>
>>> Ace
>>> 
0
Julien
2/4/2010 8:27:06 AM
Hello,

I can do a SMB connection but I don't have the certificate.

Can any body help me to resolve this issue?

Julien



"Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
news:9A0DEBC9-0F64-4EA7-9A5C-5A21FE44642E@microsoft.com...
> Hi
> Yes, test the connection using \\dcshdct02
>
>
> -- 
>
> I hope that the information above helps you.
> Have a Nice day.
>
> Jorge Silva
> MVP Directory Services
>
> Please no e-mails, any questions should be posted in the NewsGroup
> This posting is provided "AS IS" with no warranties, and confers no 
> rights.
>
>
>
>
> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
> news:OoKFGa#oKHA.1548@TK2MSFTNGP02.phx.gbl...
>> Hello,
>>
>> In fact, the computer name is dcshdct02, but if I open the certification 
>> authority MMC, the name of the server is : mydomain-DCSHDCT02-CA.
>>
>>
>>
>> "Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in 
>> message news:#Yp$jr1oKHA.4836@TK2MSFTNGP05.phx.gbl...
>>> "Julien" <jithurbide@removegmail.com> wrote in message 
>>> news:uOaW1izoKHA.5260@TK2MSFTNGP02.phx.gbl...
>>>> Hello,
>>>>
>>>> You say :
>>>>
>>>>> To test do a SMB connection: "\\CAName.yourdomain.tld" from that DC.
>>>>
>>>> What is the CAName ? My computer name ? like dcshdct02 ? or the name I 
>>>> can see on the Certification authority MMC?
>>>>
>>>> I can browse the CA with the comupter name \\dcshdct02 but not the name 
>>>> I see on the CA MMC.
>>>>
>>>> Julien
>>>>
>>>>
>>>
>>>
>>> The CAName is the computer name of your CA (Certificate Authority) 
>>> server.
>>>
>>> Is dcshdct02 the name of the CA? If so, what do you mean by can't browse 
>>> by the name in the CA MMC console? what name is that?
>>>
>>> Ace
>>> 
0
Julien
2/8/2010 10:33:19 AM
"Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
news:la2dnfevwcrtdfLWnZ2dnUVZ8nydnZ2d@giganews.com...
> Hello,
>
> I can do a SMB connection but I don't have the certificate.
>
> Can any body help me to resolve this issue?
>
> Julien

Can you connect to the CA using a browser? If you can, you can request a 
cert.

https://dcshdct02
or
http://dcshdct02

Also, you said that you've opened the firewall up wide open, correct? That 
should have alleviated the RPC errors. However, if it didn't resolve the 
errors, then something else is going on. It could be using the wrong DNS, 
multihomed DC (more than one NIC and/or RRAS is installed on a DC) which 
will cause these problems, too, due to incorrect DNS lookups, which will 
stop GPOs from applying, among other things.

Can you post an ipconfig /all from the DC, as well as any EventID# errors 
(App, System, FRS, Dir Service logs)?

Ace


0
Ace
2/8/2010 4:53:50 PM
Is the CA service started?
Did you test SMB from that DC?
IS that DC passing through ISA? IF yes, can you disable the RPC filter for 
that rule and test again? You may need to reboot the DC twice until that 
error goes away.

-- 

I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MVP Directory Services

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.




"Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
news:la2dnfevwcrtdfLWnZ2dnUVZ8nydnZ2d@giganews.com...
> Hello,
>
> I can do a SMB connection but I don't have the certificate.
>
> Can any body help me to resolve this issue?
>
> Julien
>
>
>
> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
> news:9A0DEBC9-0F64-4EA7-9A5C-5A21FE44642E@microsoft.com...
>> Hi
>> Yes, test the connection using \\dcshdct02
>>
>>
>> -- 
>>
>> I hope that the information above helps you.
>> Have a Nice day.
>>
>> Jorge Silva
>> MVP Directory Services
>>
>> Please no e-mails, any questions should be posted in the NewsGroup
>> This posting is provided "AS IS" with no warranties, and confers no 
>> rights.
>>
>>
>>
>>
>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>> news:OoKFGa#oKHA.1548@TK2MSFTNGP02.phx.gbl...
>>> Hello,
>>>
>>> In fact, the computer name is dcshdct02, but if I open the certification 
>>> authority MMC, the name of the server is : mydomain-DCSHDCT02-CA.
>>>
>>>
>>>
>>> "Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in 
>>> message news:#Yp$jr1oKHA.4836@TK2MSFTNGP05.phx.gbl...
>>>> "Julien" <jithurbide@removegmail.com> wrote in message 
>>>> news:uOaW1izoKHA.5260@TK2MSFTNGP02.phx.gbl...
>>>>> Hello,
>>>>>
>>>>> You say :
>>>>>
>>>>>> To test do a SMB connection: "\\CAName.yourdomain.tld" from that DC.
>>>>>
>>>>> What is the CAName ? My computer name ? like dcshdct02 ? or the name I 
>>>>> can see on the Certification authority MMC?
>>>>>
>>>>> I can browse the CA with the comupter name \\dcshdct02 but not the 
>>>>> name I see on the CA MMC.
>>>>>
>>>>> Julien
>>>>>
>>>>>
>>>>
>>>>
>>>> The CAName is the computer name of your CA (Certificate Authority) 
>>>> server.
>>>>
>>>> Is dcshdct02 the name of the CA? If so, what do you mean by can't 
>>>> browse by the name in the CA MMC console? what name is that?
>>>>
>>>> Ace
>>>> 
0
Jorge
2/9/2010 9:02:18 PM
Hello,


This is my ipconfig :

----------------------------------------------------------------------------------------------

ipconfig /all

Windows IP Configuration

   Host Name . . . . . . . . . . . . : DCITDCT01
   Primary Dns Suffix  . . . . . . . : mydomain.local
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : mydomain.local

Ethernet adDCter Local Area Connection:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network 
Connection
   Physical Address. . . . . . . . . : 00-0C-29-72-A4-A4
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv4 Address. . . . . . . . . . . : 192.168.11.14(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.11.254
   DNS Servers . . . . . . . . . . . : 192.168.11.14
                                       192.168.30.2
                                       127.0.0.1
   NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adDCter isatDC.{6DE906DB-E4F6-45A1-A6D3-A5B10F2663BA}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATDC AdDCter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adDCter Local Area Connection* 11:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

-------------------------------------------------------------------------------------------------------------

Here are my application log error :

-------------------------------------------------------------------------------------------------------------

Log Name:      DCplication
Source:        Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Date:          10.02.2010 05:42:07
Event ID:      6
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      DCITDCT01.mydomain.local
Description:
Automatic certificate enrollment for local system failed (0x800706ba) The 
RPC server is unavailable.
..
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider 
Name="Microsoft-Windows-CertificateServicesClient-AutoEnrollment" 
Guid="{F0DB7EF8-B6F3-4005-9937-FEB77B9E1B43}" 
EventSourceName="AutoEnrollment" />
    <EventID Qualifiers="16384">6</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-10T04:42:07.000000000Z" />
    <EventRecordID>2334</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>DCplication</Channel>
    <Computer>DCITDCT01.mydomain.local</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="Context">local system</Data>
    <Data Name="ErrorCode">0x800706ba</Data>
    <Data Name="ErrorMsg">The RPC server is unavailable.
</Data>
  </EventData>
</Event>

Log Name:      DCplication
Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
Date:          10.02.2010 05:42:07
Event ID:      13
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      DCITDCT01.mydomain.local
Description:
Certificate enrollment for Local system failed to enroll for a 
DomainController certificate with request ID N/A from 
DCSHDCT02.mydomain.local\mydomain-DCSHDCT02-CA (The RPC server is 
unavailable. 0x800706ba (WIN32: 1722)).
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" EventSourceName="CertEnroll" 
/>
    <EventID Qualifiers="49754">13</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-10T04:42:07.000000000Z" />
    <EventRecordID>2333</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>DCplication</Channel>
    <Computer>DCITDCT01.mydomain.local</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="Context">Local system</Data>
    <Data Name="TemplateName">DomainController</Data>
    <Data 
Name="RequestId">DCSHDCT02.mydomain.local\mydomain-DCSHDCT02-CA</Data>
    <Data Name="CA">N/A</Data>
    <Data Name="ErrorCode">The RPC server is unavailable. 0x800706ba (WIN32: 
1722)</Data>
  </EventData>
</Event>

Log Name:      DCplication
Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
Date:          10.02.2010 05:41:26
Event ID:      64
Task Category: None
Level:         Information
Keywords:      Classic
User:          SYSTEM
Computer:      DCITDCT01.mydomain.local
Description:
Certificate enrollment for Local system successfully load policy from policy 
server
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" EventSourceName="CertEnroll" 
/>
    <EventID Qualifiers="33370">64</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-10T04:41:26.000000000Z" />
    <EventRecordID>2332</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>DCplication</Channel>
    <Computer>DCITDCT01.mydomain.local</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="Context">Local system</Data>
    <Data Name="ServerID">
    </Data>
  </EventData>
</Event>

Log Name:      DCplication
Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
Date:          10.02.2010 05:41:26
Event ID:      65
Task Category: None
Level:         Information
Keywords:      Classic
User:          SYSTEM
Computer:      DCITDCT01.mydomain.local
Description:
Certificate enrollment for Local system is successfully authenticated by 
policy server {A1DF368B-D850-4F4E-9ACF-80ADABD8C1D9}
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" EventSourceName="CertEnroll" 
/>
    <EventID Qualifiers="33370">65</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-10T04:41:26.000000000Z" />
    <EventRecordID>2331</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>DCplication</Channel>
    <Computer>DCITDCT01.mydomain.local</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="Context">Local system</Data>
    <Data Name="ServerURL">{A1DF368B-D850-4F4E-9ACF-80ADABD8C1D9}</Data>
  </EventData>
</Event>

Log Name:      DCplication
Source:        SceCli
Date:          10.02.2010 03:11:30
Event ID:      1704
Task Category: None
Level:         Information
Keywords:      Classic
User:          N/A
Computer:      DCITDCT01.mydomain.local
Description:
Security policy in the Group policy objects has been DCplied successfully.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="SceCli" />
    <EventID Qualifiers="16384">1704</EventID>
    <Level>4</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-10T02:11:30.000000000Z" />
    <EventRecordID>2330</EventRecordID>
    <Channel>DCplication</Channel>
    <Computer>DCITDCT01.mydomain.local</Computer>
    <Security />
  </System>
  <EventData>
    <Data>
    </Data>
  </EventData>
</Event>

---------------------------------------------------------------------------------------------------------------------------

Here are my system log error :

-----------------------------------------------------------------------------------------------------------------------------

Log Name:      System
Source:        Microsoft-Windows-Kerberos-Key-Distribution-Center
Date:          10.02.2010 01:39:03
Event ID:      29
Task Category: None
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      DCITDCT01.mydomain.local
Description:
The Key Distribution Center (KDC) cannot find a suitable certificate to use 
for smart card logons, or the KDC certificate could not be verified. Smart 
card logon may not function correctly if this problem is not resolved. To 
correct this problem, either verify the existing KDC certificate using 
certutil.exe or enroll for a new KDC certificate.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Kerberos-Key-Distribution-Center" 
Guid="{3FD9DA1A-5A54-46C5-9A26-9BD7C0685056}" EventSourceName="KDC" />
    <EventID Qualifiers="32768">29</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-10T00:39:03.000000000Z" />
    <EventRecordID>3205</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>System</Channel>
    <Computer>DCITDCT01.mydomain.local</Computer>
    <Security />
  </System>
  <EventData>
  </EventData>
</Event>

----------------------------------------------------------------------------------------------------------------------------------------------------------

I don't have any other error except DFS Replication that I maid for remote 
backup.

Did you need more details or log?



"Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in message 
news:uTweL9NqKHA.4280@TK2MSFTNGP06.phx.gbl...
>
> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
> news:la2dnfevwcrtdfLWnZ2dnUVZ8nydnZ2d@giganews.com...
>> Hello,
>>
>> I can do a SMB connection but I don't have the certificate.
>>
>> Can any body help me to resolve this issue?
>>
>> Julien
>
> Can you connect to the CA using a browser? If you can, you can request a 
> cert.
>
> https://dcshdct02
> or
> http://dcshdct02
>
> Also, you said that you've opened the firewall up wide open, correct? That 
> should have alleviated the RPC errors. However, if it didn't resolve the 
> errors, then something else is going on. It could be using the wrong DNS, 
> multihomed DC (more than one NIC and/or RRAS is installed on a DC) which 
> will cause these problems, too, due to incorrect DNS lookups, which will 
> stop GPOs from applying, among other things.
>
> Can you post an ipconfig /all from the DC, as well as any EventID# errors 
> (App, System, FRS, Dir Service logs)?
>
> Ace
>
> 
0
Julien
2/10/2010 7:51:32 AM
Hello,

> Did you test SMB from that DC?

Yes, I did. I test smb connection form and to my dc.

> IS that DC passing through ISA?

No, we don't use ISA!

>You may need to reboot the DC twice

I'll try this, this night, but if I remember well I already reboot it more 
thant twice.


Julien




"Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
news:76D3BF28-7F66-4CB0-A72A-94928CFFE8AC@microsoft.com...
> Is the CA service started?
> Did you test SMB from that DC?
> IS that DC passing through ISA? IF yes, can you disable the RPC filter for 
> that rule and test again? You may need to reboot the DC twice until that 
> error goes away.
>
> -- 
>
> I hope that the information above helps you.
> Have a Nice day.
>
> Jorge Silva
> MVP Directory Services
>
> Please no e-mails, any questions should be posted in the NewsGroup
> This posting is provided "AS IS" with no warranties, and confers no 
> rights.
>
>
>
>
> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
> news:la2dnfevwcrtdfLWnZ2dnUVZ8nydnZ2d@giganews.com...
>> Hello,
>>
>> I can do a SMB connection but I don't have the certificate.
>>
>> Can any body help me to resolve this issue?
>>
>> Julien
>>
>>
>>
>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>> news:9A0DEBC9-0F64-4EA7-9A5C-5A21FE44642E@microsoft.com...
>>> Hi
>>> Yes, test the connection using \\dcshdct02
>>>
>>>
>>> -- 
>>>
>>> I hope that the information above helps you.
>>> Have a Nice day.
>>>
>>> Jorge Silva
>>> MVP Directory Services
>>>
>>> Please no e-mails, any questions should be posted in the NewsGroup
>>> This posting is provided "AS IS" with no warranties, and confers no 
>>> rights.
>>>
>>>
>>>
>>>
>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>> news:OoKFGa#oKHA.1548@TK2MSFTNGP02.phx.gbl...
>>>> Hello,
>>>>
>>>> In fact, the computer name is dcshdct02, but if I open the 
>>>> certification authority MMC, the name of the server is : 
>>>> mydomain-DCSHDCT02-CA.
>>>>
>>>>
>>>>
>>>> "Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in 
>>>> message news:#Yp$jr1oKHA.4836@TK2MSFTNGP05.phx.gbl...
>>>>> "Julien" <jithurbide@removegmail.com> wrote in message 
>>>>> news:uOaW1izoKHA.5260@TK2MSFTNGP02.phx.gbl...
>>>>>> Hello,
>>>>>>
>>>>>> You say :
>>>>>>
>>>>>>> To test do a SMB connection: "\\CAName.yourdomain.tld" from that DC.
>>>>>>
>>>>>> What is the CAName ? My computer name ? like dcshdct02 ? or the name 
>>>>>> I can see on the Certification authority MMC?
>>>>>>
>>>>>> I can browse the CA with the comupter name \\dcshdct02 but not the 
>>>>>> name I see on the CA MMC.
>>>>>>
>>>>>> Julien
>>>>>>
>>>>>>
>>>>>
>>>>>
>>>>> The CAName is the computer name of your CA (Certificate Authority) 
>>>>> server.
>>>>>
>>>>> Is dcshdct02 the name of the CA? If so, what do you mean by can't 
>>>>> browse by the name in the CA MMC console? what name is that?
>>>>>
>>>>> Ace
>>>>> 
0
Julien
2/10/2010 7:58:44 AM
Ok, do that, can you also explain these 2 DNS entries:
                                       192.168.30.2
                                       127.0.0.1

-- 

I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MVP Directory Services

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.




"Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
news:df2dnTJWt_Wr-u_WnZ2dnUVZ8qGdnZ2d@giganews.com...
> Hello,
>
>> Did you test SMB from that DC?
>
> Yes, I did. I test smb connection form and to my dc.
>
>> IS that DC passing through ISA?
>
> No, we don't use ISA!
>
>>You may need to reboot the DC twice
>
> I'll try this, this night, but if I remember well I already reboot it more 
> thant twice.
>
>
> Julien
>
>
>
>
> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
> news:76D3BF28-7F66-4CB0-A72A-94928CFFE8AC@microsoft.com...
>> Is the CA service started?
>> Did you test SMB from that DC?
>> IS that DC passing through ISA? IF yes, can you disable the RPC filter 
>> for that rule and test again? You may need to reboot the DC twice until 
>> that error goes away.
>>
>> -- 
>>
>> I hope that the information above helps you.
>> Have a Nice day.
>>
>> Jorge Silva
>> MVP Directory Services
>>
>> Please no e-mails, any questions should be posted in the NewsGroup
>> This posting is provided "AS IS" with no warranties, and confers no 
>> rights.
>>
>>
>>
>>
>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>> news:la2dnfevwcrtdfLWnZ2dnUVZ8nydnZ2d@giganews.com...
>>> Hello,
>>>
>>> I can do a SMB connection but I don't have the certificate.
>>>
>>> Can any body help me to resolve this issue?
>>>
>>> Julien
>>>
>>>
>>>
>>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>>> news:9A0DEBC9-0F64-4EA7-9A5C-5A21FE44642E@microsoft.com...
>>>> Hi
>>>> Yes, test the connection using \\dcshdct02
>>>>
>>>>
>>>> -- 
>>>>
>>>> I hope that the information above helps you.
>>>> Have a Nice day.
>>>>
>>>> Jorge Silva
>>>> MVP Directory Services
>>>>
>>>> Please no e-mails, any questions should be posted in the NewsGroup
>>>> This posting is provided "AS IS" with no warranties, and confers no 
>>>> rights.
>>>>
>>>>
>>>>
>>>>
>>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>>> news:OoKFGa#oKHA.1548@TK2MSFTNGP02.phx.gbl...
>>>>> Hello,
>>>>>
>>>>> In fact, the computer name is dcshdct02, but if I open the 
>>>>> certification authority MMC, the name of the server is : 
>>>>> mydomain-DCSHDCT02-CA.
>>>>>
>>>>>
>>>>>
>>>>> "Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in 
>>>>> message news:#Yp$jr1oKHA.4836@TK2MSFTNGP05.phx.gbl...
>>>>>> "Julien" <jithurbide@removegmail.com> wrote in message 
>>>>>> news:uOaW1izoKHA.5260@TK2MSFTNGP02.phx.gbl...
>>>>>>> Hello,
>>>>>>>
>>>>>>> You say :
>>>>>>>
>>>>>>>> To test do a SMB connection: "\\CAName.yourdomain.tld" from that 
>>>>>>>> DC.
>>>>>>>
>>>>>>> What is the CAName ? My computer name ? like dcshdct02 ? or the name 
>>>>>>> I can see on the Certification authority MMC?
>>>>>>>
>>>>>>> I can browse the CA with the comupter name \\dcshdct02 but not the 
>>>>>>> name I see on the CA MMC.
>>>>>>>
>>>>>>> Julien
>>>>>>>
>>>>>>>
>>>>>>
>>>>>>
>>>>>> The CAName is the computer name of your CA (Certificate Authority) 
>>>>>> server.
>>>>>>
>>>>>> Is dcshdct02 the name of the CA? If so, what do you mean by can't 
>>>>>> browse by the name in the CA MMC console? what name is that?
>>>>>>
>>>>>> Ace
>>>>>> 
0
Jorge
2/10/2010 12:30:30 PM
ok simple 127.0.0.1 I have delete ... I don't know why is here.

192.168.30.2 is my central site and my fist DC on my domain.

I have a lot of site and this address is the ranch for my central offices.



"Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
news:D574EA20-F3DB-4511-880C-944F7D1BF4A9@microsoft.com...
> Ok, do that, can you also explain these 2 DNS entries:
>                                       192.168.30.2
>                                       127.0.0.1
>
> -- 
>
> I hope that the information above helps you.
> Have a Nice day.
>
> Jorge Silva
> MVP Directory Services
>
> Please no e-mails, any questions should be posted in the NewsGroup
> This posting is provided "AS IS" with no warranties, and confers no 
> rights.
>
>
>
>
> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
> news:df2dnTJWt_Wr-u_WnZ2dnUVZ8qGdnZ2d@giganews.com...
>> Hello,
>>
>>> Did you test SMB from that DC?
>>
>> Yes, I did. I test smb connection form and to my dc.
>>
>>> IS that DC passing through ISA?
>>
>> No, we don't use ISA!
>>
>>>You may need to reboot the DC twice
>>
>> I'll try this, this night, but if I remember well I already reboot it 
>> more thant twice.
>>
>>
>> Julien
>>
>>
>>
>>
>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>> news:76D3BF28-7F66-4CB0-A72A-94928CFFE8AC@microsoft.com...
>>> Is the CA service started?
>>> Did you test SMB from that DC?
>>> IS that DC passing through ISA? IF yes, can you disable the RPC filter 
>>> for that rule and test again? You may need to reboot the DC twice until 
>>> that error goes away.
>>>
>>> -- 
>>>
>>> I hope that the information above helps you.
>>> Have a Nice day.
>>>
>>> Jorge Silva
>>> MVP Directory Services
>>>
>>> Please no e-mails, any questions should be posted in the NewsGroup
>>> This posting is provided "AS IS" with no warranties, and confers no 
>>> rights.
>>>
>>>
>>>
>>>
>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>> news:la2dnfevwcrtdfLWnZ2dnUVZ8nydnZ2d@giganews.com...
>>>> Hello,
>>>>
>>>> I can do a SMB connection but I don't have the certificate.
>>>>
>>>> Can any body help me to resolve this issue?
>>>>
>>>> Julien
>>>>
>>>>
>>>>
>>>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>>>> news:9A0DEBC9-0F64-4EA7-9A5C-5A21FE44642E@microsoft.com...
>>>>> Hi
>>>>> Yes, test the connection using \\dcshdct02
>>>>>
>>>>>
>>>>> -- 
>>>>>
>>>>> I hope that the information above helps you.
>>>>> Have a Nice day.
>>>>>
>>>>> Jorge Silva
>>>>> MVP Directory Services
>>>>>
>>>>> Please no e-mails, any questions should be posted in the NewsGroup
>>>>> This posting is provided "AS IS" with no warranties, and confers no 
>>>>> rights.
>>>>>
>>>>>
>>>>>
>>>>>
>>>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>>>> news:OoKFGa#oKHA.1548@TK2MSFTNGP02.phx.gbl...
>>>>>> Hello,
>>>>>>
>>>>>> In fact, the computer name is dcshdct02, but if I open the 
>>>>>> certification authority MMC, the name of the server is : 
>>>>>> mydomain-DCSHDCT02-CA.
>>>>>>
>>>>>>
>>>>>>
>>>>>> "Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in 
>>>>>> message news:#Yp$jr1oKHA.4836@TK2MSFTNGP05.phx.gbl...
>>>>>>> "Julien" <jithurbide@removegmail.com> wrote in message 
>>>>>>> news:uOaW1izoKHA.5260@TK2MSFTNGP02.phx.gbl...
>>>>>>>> Hello,
>>>>>>>>
>>>>>>>> You say :
>>>>>>>>
>>>>>>>>> To test do a SMB connection: "\\CAName.yourdomain.tld" from that 
>>>>>>>>> DC.
>>>>>>>>
>>>>>>>> What is the CAName ? My computer name ? like dcshdct02 ? or the 
>>>>>>>> name I can see on the Certification authority MMC?
>>>>>>>>
>>>>>>>> I can browse the CA with the comupter name \\dcshdct02 but not the 
>>>>>>>> name I see on the CA MMC.
>>>>>>>>
>>>>>>>> Julien
>>>>>>>>
>>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>> The CAName is the computer name of your CA (Certificate Authority) 
>>>>>>> server.
>>>>>>>
>>>>>>> Is dcshdct02 the name of the CA? If so, what do you mean by can't 
>>>>>>> browse by the name in the CA MMC console? what name is that?
>>>>>>>
>>>>>>> Ace
>>>>>>> 
0
Julien
2/10/2010 1:12:48 PM
Ok,
- Did you also test SMB from the CA to the DC?
- Can you ping from both sides (DC and CA) to each other?
- Did you already reboot the DC 2?

-- 

I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MVP Directory Services

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.




"Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
news:05mdnTtB8_9hLe_WnZ2dnUVZ8qSdnZ2d@giganews.com...
> ok simple 127.0.0.1 I have delete ... I don't know why is here.
>
> 192.168.30.2 is my central site and my fist DC on my domain.
>
> I have a lot of site and this address is the ranch for my central offices.
>
>
>
> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
> news:D574EA20-F3DB-4511-880C-944F7D1BF4A9@microsoft.com...
>> Ok, do that, can you also explain these 2 DNS entries:
>>                                       192.168.30.2
>>                                       127.0.0.1
>>
>> -- 
>>
>> I hope that the information above helps you.
>> Have a Nice day.
>>
>> Jorge Silva
>> MVP Directory Services
>>
>> Please no e-mails, any questions should be posted in the NewsGroup
>> This posting is provided "AS IS" with no warranties, and confers no 
>> rights.
>>
>>
>>
>>
>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>> news:df2dnTJWt_Wr-u_WnZ2dnUVZ8qGdnZ2d@giganews.com...
>>> Hello,
>>>
>>>> Did you test SMB from that DC?
>>>
>>> Yes, I did. I test smb connection form and to my dc.
>>>
>>>> IS that DC passing through ISA?
>>>
>>> No, we don't use ISA!
>>>
>>>>You may need to reboot the DC twice
>>>
>>> I'll try this, this night, but if I remember well I already reboot it 
>>> more thant twice.
>>>
>>>
>>> Julien
>>>
>>>
>>>
>>>
>>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>>> news:76D3BF28-7F66-4CB0-A72A-94928CFFE8AC@microsoft.com...
>>>> Is the CA service started?
>>>> Did you test SMB from that DC?
>>>> IS that DC passing through ISA? IF yes, can you disable the RPC filter 
>>>> for that rule and test again? You may need to reboot the DC twice until 
>>>> that error goes away.
>>>>
>>>> -- 
>>>>
>>>> I hope that the information above helps you.
>>>> Have a Nice day.
>>>>
>>>> Jorge Silva
>>>> MVP Directory Services
>>>>
>>>> Please no e-mails, any questions should be posted in the NewsGroup
>>>> This posting is provided "AS IS" with no warranties, and confers no 
>>>> rights.
>>>>
>>>>
>>>>
>>>>
>>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>>> news:la2dnfevwcrtdfLWnZ2dnUVZ8nydnZ2d@giganews.com...
>>>>> Hello,
>>>>>
>>>>> I can do a SMB connection but I don't have the certificate.
>>>>>
>>>>> Can any body help me to resolve this issue?
>>>>>
>>>>> Julien
>>>>>
>>>>>
>>>>>
>>>>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>>>>> news:9A0DEBC9-0F64-4EA7-9A5C-5A21FE44642E@microsoft.com...
>>>>>> Hi
>>>>>> Yes, test the connection using \\dcshdct02
>>>>>>
>>>>>>
>>>>>> -- 
>>>>>>
>>>>>> I hope that the information above helps you.
>>>>>> Have a Nice day.
>>>>>>
>>>>>> Jorge Silva
>>>>>> MVP Directory Services
>>>>>>
>>>>>> Please no e-mails, any questions should be posted in the NewsGroup
>>>>>> This posting is provided "AS IS" with no warranties, and confers no 
>>>>>> rights.
>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>>>>> news:OoKFGa#oKHA.1548@TK2MSFTNGP02.phx.gbl...
>>>>>>> Hello,
>>>>>>>
>>>>>>> In fact, the computer name is dcshdct02, but if I open the 
>>>>>>> certification authority MMC, the name of the server is : 
>>>>>>> mydomain-DCSHDCT02-CA.
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>> "Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in 
>>>>>>> message news:#Yp$jr1oKHA.4836@TK2MSFTNGP05.phx.gbl...
>>>>>>>> "Julien" <jithurbide@removegmail.com> wrote in message 
>>>>>>>> news:uOaW1izoKHA.5260@TK2MSFTNGP02.phx.gbl...
>>>>>>>>> Hello,
>>>>>>>>>
>>>>>>>>> You say :
>>>>>>>>>
>>>>>>>>>> To test do a SMB connection: "\\CAName.yourdomain.tld" from that 
>>>>>>>>>> DC.
>>>>>>>>>
>>>>>>>>> What is the CAName ? My computer name ? like dcshdct02 ? or the 
>>>>>>>>> name I can see on the Certification authority MMC?
>>>>>>>>>
>>>>>>>>> I can browse the CA with the comupter name \\dcshdct02 but not the 
>>>>>>>>> name I see on the CA MMC.
>>>>>>>>>
>>>>>>>>> Julien
>>>>>>>>>
>>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>> The CAName is the computer name of your CA (Certificate Authority) 
>>>>>>>> server.
>>>>>>>>
>>>>>>>> Is dcshdct02 the name of the CA? If so, what do you mean by can't 
>>>>>>>> browse by the name in the CA MMC console? what name is that?
>>>>>>>>
>>>>>>>> Ace
>>>>>>>> 
0
Jorge
2/11/2010 1:39:13 AM
> - Did you also test SMB from the CA to the DC?

Yes, I do

> - Can you ping from both sides (DC and CA) to each other?

Yes, I can

> - Did you already reboot the DC 2?

I have palnned to reboot my dc and the ca this night.



"Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
news:7B115C84-012E-4397-8F34-ECAC27074558@microsoft.com...
> Ok,
> - Did you also test SMB from the CA to the DC?
> - Can you ping from both sides (DC and CA) to each other?
> - Did you already reboot the DC 2?
>
> -- 
>
> I hope that the information above helps you.
> Have a Nice day.
>
> Jorge Silva
> MVP Directory Services
>
> Please no e-mails, any questions should be posted in the NewsGroup
> This posting is provided "AS IS" with no warranties, and confers no 
> rights.
>
>
>
>
> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
> news:05mdnTtB8_9hLe_WnZ2dnUVZ8qSdnZ2d@giganews.com...
>> ok simple 127.0.0.1 I have delete ... I don't know why is here.
>>
>> 192.168.30.2 is my central site and my fist DC on my domain.
>>
>> I have a lot of site and this address is the ranch for my central 
>> offices.
>>
>>
>>
>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>> news:D574EA20-F3DB-4511-880C-944F7D1BF4A9@microsoft.com...
>>> Ok, do that, can you also explain these 2 DNS entries:
>>>                                       192.168.30.2
>>>                                       127.0.0.1
>>>
>>> -- 
>>>
>>> I hope that the information above helps you.
>>> Have a Nice day.
>>>
>>> Jorge Silva
>>> MVP Directory Services
>>>
>>> Please no e-mails, any questions should be posted in the NewsGroup
>>> This posting is provided "AS IS" with no warranties, and confers no 
>>> rights.
>>>
>>>
>>>
>>>
>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>> news:df2dnTJWt_Wr-u_WnZ2dnUVZ8qGdnZ2d@giganews.com...
>>>> Hello,
>>>>
>>>>> Did you test SMB from that DC?
>>>>
>>>> Yes, I did. I test smb connection form and to my dc.
>>>>
>>>>> IS that DC passing through ISA?
>>>>
>>>> No, we don't use ISA!
>>>>
>>>>>You may need to reboot the DC twice
>>>>
>>>> I'll try this, this night, but if I remember well I already reboot it 
>>>> more thant twice.
>>>>
>>>>
>>>> Julien
>>>>
>>>>
>>>>
>>>>
>>>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>>>> news:76D3BF28-7F66-4CB0-A72A-94928CFFE8AC@microsoft.com...
>>>>> Is the CA service started?
>>>>> Did you test SMB from that DC?
>>>>> IS that DC passing through ISA? IF yes, can you disable the RPC filter 
>>>>> for that rule and test again? You may need to reboot the DC twice 
>>>>> until that error goes away.
>>>>>
>>>>> -- 
>>>>>
>>>>> I hope that the information above helps you.
>>>>> Have a Nice day.
>>>>>
>>>>> Jorge Silva
>>>>> MVP Directory Services
>>>>>
>>>>> Please no e-mails, any questions should be posted in the NewsGroup
>>>>> This posting is provided "AS IS" with no warranties, and confers no 
>>>>> rights.
>>>>>
>>>>>
>>>>>
>>>>>
>>>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>>>> news:la2dnfevwcrtdfLWnZ2dnUVZ8nydnZ2d@giganews.com...
>>>>>> Hello,
>>>>>>
>>>>>> I can do a SMB connection but I don't have the certificate.
>>>>>>
>>>>>> Can any body help me to resolve this issue?
>>>>>>
>>>>>> Julien
>>>>>>
>>>>>>
>>>>>>
>>>>>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>>>>>> news:9A0DEBC9-0F64-4EA7-9A5C-5A21FE44642E@microsoft.com...
>>>>>>> Hi
>>>>>>> Yes, test the connection using \\dcshdct02
>>>>>>>
>>>>>>>
>>>>>>> -- 
>>>>>>>
>>>>>>> I hope that the information above helps you.
>>>>>>> Have a Nice day.
>>>>>>>
>>>>>>> Jorge Silva
>>>>>>> MVP Directory Services
>>>>>>>
>>>>>>> Please no e-mails, any questions should be posted in the NewsGroup
>>>>>>> This posting is provided "AS IS" with no warranties, and confers no 
>>>>>>> rights.
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>>>>>> news:OoKFGa#oKHA.1548@TK2MSFTNGP02.phx.gbl...
>>>>>>>> Hello,
>>>>>>>>
>>>>>>>> In fact, the computer name is dcshdct02, but if I open the 
>>>>>>>> certification authority MMC, the name of the server is : 
>>>>>>>> mydomain-DCSHDCT02-CA.
>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>> "Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in 
>>>>>>>> message news:#Yp$jr1oKHA.4836@TK2MSFTNGP05.phx.gbl...
>>>>>>>>> "Julien" <jithurbide@removegmail.com> wrote in message 
>>>>>>>>> news:uOaW1izoKHA.5260@TK2MSFTNGP02.phx.gbl...
>>>>>>>>>> Hello,
>>>>>>>>>>
>>>>>>>>>> You say :
>>>>>>>>>>
>>>>>>>>>>> To test do a SMB connection: "\\CAName.yourdomain.tld" from that 
>>>>>>>>>>> DC.
>>>>>>>>>>
>>>>>>>>>> What is the CAName ? My computer name ? like dcshdct02 ? or the 
>>>>>>>>>> name I can see on the Certification authority MMC?
>>>>>>>>>>
>>>>>>>>>> I can browse the CA with the comupter name \\dcshdct02 but not 
>>>>>>>>>> the name I see on the CA MMC.
>>>>>>>>>>
>>>>>>>>>> Julien
>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>
>>>>>>>>>
>>>>>>>>> The CAName is the computer name of your CA (Certificate Authority) 
>>>>>>>>> server.
>>>>>>>>>
>>>>>>>>> Is dcshdct02 the name of the CA? If so, what do you mean by can't 
>>>>>>>>> browse by the name in the CA MMC console? what name is that?
>>>>>>>>>
>>>>>>>>> Ace
>>>>>>>>> 
0
Julien
2/11/2010 10:39:40 AM
Hold on...
If you're going to reboot the CA...
1St the CA, after the CA is up, do 2 reboots with a logon between them on 
the DC.

-- 

I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MVP Directory Services

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.




"Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
news:T5idndaKfvbpQ-7WnZ2dnUVZ8vOdnZ2d@giganews.com...
>> - Did you also test SMB from the CA to the DC?
>
> Yes, I do
>
>> - Can you ping from both sides (DC and CA) to each other?
>
> Yes, I can
>
>> - Did you already reboot the DC 2?
>
> I have palnned to reboot my dc and the ca this night.
>
>
>
> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
> news:7B115C84-012E-4397-8F34-ECAC27074558@microsoft.com...
>> Ok,
>> - Did you also test SMB from the CA to the DC?
>> - Can you ping from both sides (DC and CA) to each other?
>> - Did you already reboot the DC 2?
>>
>> -- 
>>
>> I hope that the information above helps you.
>> Have a Nice day.
>>
>> Jorge Silva
>> MVP Directory Services
>>
>> Please no e-mails, any questions should be posted in the NewsGroup
>> This posting is provided "AS IS" with no warranties, and confers no 
>> rights.
>>
>>
>>
>>
>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>> news:05mdnTtB8_9hLe_WnZ2dnUVZ8qSdnZ2d@giganews.com...
>>> ok simple 127.0.0.1 I have delete ... I don't know why is here.
>>>
>>> 192.168.30.2 is my central site and my fist DC on my domain.
>>>
>>> I have a lot of site and this address is the ranch for my central 
>>> offices.
>>>
>>>
>>>
>>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>>> news:D574EA20-F3DB-4511-880C-944F7D1BF4A9@microsoft.com...
>>>> Ok, do that, can you also explain these 2 DNS entries:
>>>>                                       192.168.30.2
>>>>                                       127.0.0.1
>>>>
>>>> -- 
>>>>
>>>> I hope that the information above helps you.
>>>> Have a Nice day.
>>>>
>>>> Jorge Silva
>>>> MVP Directory Services
>>>>
>>>> Please no e-mails, any questions should be posted in the NewsGroup
>>>> This posting is provided "AS IS" with no warranties, and confers no 
>>>> rights.
>>>>
>>>>
>>>>
>>>>
>>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>>> news:df2dnTJWt_Wr-u_WnZ2dnUVZ8qGdnZ2d@giganews.com...
>>>>> Hello,
>>>>>
>>>>>> Did you test SMB from that DC?
>>>>>
>>>>> Yes, I did. I test smb connection form and to my dc.
>>>>>
>>>>>> IS that DC passing through ISA?
>>>>>
>>>>> No, we don't use ISA!
>>>>>
>>>>>>You may need to reboot the DC twice
>>>>>
>>>>> I'll try this, this night, but if I remember well I already reboot it 
>>>>> more thant twice.
>>>>>
>>>>>
>>>>> Julien
>>>>>
>>>>>
>>>>>
>>>>>
>>>>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>>>>> news:76D3BF28-7F66-4CB0-A72A-94928CFFE8AC@microsoft.com...
>>>>>> Is the CA service started?
>>>>>> Did you test SMB from that DC?
>>>>>> IS that DC passing through ISA? IF yes, can you disable the RPC 
>>>>>> filter for that rule and test again? You may need to reboot the DC 
>>>>>> twice until that error goes away.
>>>>>>
>>>>>> -- 
>>>>>>
>>>>>> I hope that the information above helps you.
>>>>>> Have a Nice day.
>>>>>>
>>>>>> Jorge Silva
>>>>>> MVP Directory Services
>>>>>>
>>>>>> Please no e-mails, any questions should be posted in the NewsGroup
>>>>>> This posting is provided "AS IS" with no warranties, and confers no 
>>>>>> rights.
>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>>>>> news:la2dnfevwcrtdfLWnZ2dnUVZ8nydnZ2d@giganews.com...
>>>>>>> Hello,
>>>>>>>
>>>>>>> I can do a SMB connection but I don't have the certificate.
>>>>>>>
>>>>>>> Can any body help me to resolve this issue?
>>>>>>>
>>>>>>> Julien
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>>>>>>> news:9A0DEBC9-0F64-4EA7-9A5C-5A21FE44642E@microsoft.com...
>>>>>>>> Hi
>>>>>>>> Yes, test the connection using \\dcshdct02
>>>>>>>>
>>>>>>>>
>>>>>>>> -- 
>>>>>>>>
>>>>>>>> I hope that the information above helps you.
>>>>>>>> Have a Nice day.
>>>>>>>>
>>>>>>>> Jorge Silva
>>>>>>>> MVP Directory Services
>>>>>>>>
>>>>>>>> Please no e-mails, any questions should be posted in the NewsGroup
>>>>>>>> This posting is provided "AS IS" with no warranties, and confers no 
>>>>>>>> rights.
>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>>>>>>> news:OoKFGa#oKHA.1548@TK2MSFTNGP02.phx.gbl...
>>>>>>>>> Hello,
>>>>>>>>>
>>>>>>>>> In fact, the computer name is dcshdct02, but if I open the 
>>>>>>>>> certification authority MMC, the name of the server is : 
>>>>>>>>> mydomain-DCSHDCT02-CA.
>>>>>>>>>
>>>>>>>>>
>>>>>>>>>
>>>>>>>>> "Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote 
>>>>>>>>> in message news:#Yp$jr1oKHA.4836@TK2MSFTNGP05.phx.gbl...
>>>>>>>>>> "Julien" <jithurbide@removegmail.com> wrote in message 
>>>>>>>>>> news:uOaW1izoKHA.5260@TK2MSFTNGP02.phx.gbl...
>>>>>>>>>>> Hello,
>>>>>>>>>>>
>>>>>>>>>>> You say :
>>>>>>>>>>>
>>>>>>>>>>>> To test do a SMB connection: "\\CAName.yourdomain.tld" from 
>>>>>>>>>>>> that DC.
>>>>>>>>>>>
>>>>>>>>>>> What is the CAName ? My computer name ? like dcshdct02 ? or the 
>>>>>>>>>>> name I can see on the Certification authority MMC?
>>>>>>>>>>>
>>>>>>>>>>> I can browse the CA with the comupter name \\dcshdct02 but not 
>>>>>>>>>>> the name I see on the CA MMC.
>>>>>>>>>>>
>>>>>>>>>>> Julien
>>>>>>>>>>>
>>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>> The CAName is the computer name of your CA (Certificate 
>>>>>>>>>> Authority) server.
>>>>>>>>>>
>>>>>>>>>> Is dcshdct02 the name of the CA? If so, what do you mean by can't 
>>>>>>>>>> browse by the name in the CA MMC console? what name is that?
>>>>>>>>>>
>>>>>>>>>> Ace
>>>>>>>>>> 
0
Jorge
2/11/2010 5:53:17 PM
Another thing, please check if you have any thyrd party FW installed on the 
DC and CA. For instance, some antivirus have additional products that 
provides FW capabilities.

-- 

I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MVP Directory Services

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.




"Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
news:T5idndaKfvbpQ-7WnZ2dnUVZ8vOdnZ2d@giganews.com...
>> - Did you also test SMB from the CA to the DC?
>
> Yes, I do
>
>> - Can you ping from both sides (DC and CA) to each other?
>
> Yes, I can
>
>> - Did you already reboot the DC 2?
>
> I have palnned to reboot my dc and the ca this night.
>
>
>
> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
> news:7B115C84-012E-4397-8F34-ECAC27074558@microsoft.com...
>> Ok,
>> - Did you also test SMB from the CA to the DC?
>> - Can you ping from both sides (DC and CA) to each other?
>> - Did you already reboot the DC 2?
>>
>> -- 
>>
>> I hope that the information above helps you.
>> Have a Nice day.
>>
>> Jorge Silva
>> MVP Directory Services
>>
>> Please no e-mails, any questions should be posted in the NewsGroup
>> This posting is provided "AS IS" with no warranties, and confers no 
>> rights.
>>
>>
>>
>>
>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>> news:05mdnTtB8_9hLe_WnZ2dnUVZ8qSdnZ2d@giganews.com...
>>> ok simple 127.0.0.1 I have delete ... I don't know why is here.
>>>
>>> 192.168.30.2 is my central site and my fist DC on my domain.
>>>
>>> I have a lot of site and this address is the ranch for my central 
>>> offices.
>>>
>>>
>>>
>>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>>> news:D574EA20-F3DB-4511-880C-944F7D1BF4A9@microsoft.com...
>>>> Ok, do that, can you also explain these 2 DNS entries:
>>>>                                       192.168.30.2
>>>>                                       127.0.0.1
>>>>
>>>> -- 
>>>>
>>>> I hope that the information above helps you.
>>>> Have a Nice day.
>>>>
>>>> Jorge Silva
>>>> MVP Directory Services
>>>>
>>>> Please no e-mails, any questions should be posted in the NewsGroup
>>>> This posting is provided "AS IS" with no warranties, and confers no 
>>>> rights.
>>>>
>>>>
>>>>
>>>>
>>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>>> news:df2dnTJWt_Wr-u_WnZ2dnUVZ8qGdnZ2d@giganews.com...
>>>>> Hello,
>>>>>
>>>>>> Did you test SMB from that DC?
>>>>>
>>>>> Yes, I did. I test smb connection form and to my dc.
>>>>>
>>>>>> IS that DC passing through ISA?
>>>>>
>>>>> No, we don't use ISA!
>>>>>
>>>>>>You may need to reboot the DC twice
>>>>>
>>>>> I'll try this, this night, but if I remember well I already reboot it 
>>>>> more thant twice.
>>>>>
>>>>>
>>>>> Julien
>>>>>
>>>>>
>>>>>
>>>>>
>>>>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>>>>> news:76D3BF28-7F66-4CB0-A72A-94928CFFE8AC@microsoft.com...
>>>>>> Is the CA service started?
>>>>>> Did you test SMB from that DC?
>>>>>> IS that DC passing through ISA? IF yes, can you disable the RPC 
>>>>>> filter for that rule and test again? You may need to reboot the DC 
>>>>>> twice until that error goes away.
>>>>>>
>>>>>> -- 
>>>>>>
>>>>>> I hope that the information above helps you.
>>>>>> Have a Nice day.
>>>>>>
>>>>>> Jorge Silva
>>>>>> MVP Directory Services
>>>>>>
>>>>>> Please no e-mails, any questions should be posted in the NewsGroup
>>>>>> This posting is provided "AS IS" with no warranties, and confers no 
>>>>>> rights.
>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>>>>> news:la2dnfevwcrtdfLWnZ2dnUVZ8nydnZ2d@giganews.com...
>>>>>>> Hello,
>>>>>>>
>>>>>>> I can do a SMB connection but I don't have the certificate.
>>>>>>>
>>>>>>> Can any body help me to resolve this issue?
>>>>>>>
>>>>>>> Julien
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>>>>>>> news:9A0DEBC9-0F64-4EA7-9A5C-5A21FE44642E@microsoft.com...
>>>>>>>> Hi
>>>>>>>> Yes, test the connection using \\dcshdct02
>>>>>>>>
>>>>>>>>
>>>>>>>> -- 
>>>>>>>>
>>>>>>>> I hope that the information above helps you.
>>>>>>>> Have a Nice day.
>>>>>>>>
>>>>>>>> Jorge Silva
>>>>>>>> MVP Directory Services
>>>>>>>>
>>>>>>>> Please no e-mails, any questions should be posted in the NewsGroup
>>>>>>>> This posting is provided "AS IS" with no warranties, and confers no 
>>>>>>>> rights.
>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>>>>>>> news:OoKFGa#oKHA.1548@TK2MSFTNGP02.phx.gbl...
>>>>>>>>> Hello,
>>>>>>>>>
>>>>>>>>> In fact, the computer name is dcshdct02, but if I open the 
>>>>>>>>> certification authority MMC, the name of the server is : 
>>>>>>>>> mydomain-DCSHDCT02-CA.
>>>>>>>>>
>>>>>>>>>
>>>>>>>>>
>>>>>>>>> "Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote 
>>>>>>>>> in message news:#Yp$jr1oKHA.4836@TK2MSFTNGP05.phx.gbl...
>>>>>>>>>> "Julien" <jithurbide@removegmail.com> wrote in message 
>>>>>>>>>> news:uOaW1izoKHA.5260@TK2MSFTNGP02.phx.gbl...
>>>>>>>>>>> Hello,
>>>>>>>>>>>
>>>>>>>>>>> You say :
>>>>>>>>>>>
>>>>>>>>>>>> To test do a SMB connection: "\\CAName.yourdomain.tld" from 
>>>>>>>>>>>> that DC.
>>>>>>>>>>>
>>>>>>>>>>> What is the CAName ? My computer name ? like dcshdct02 ? or the 
>>>>>>>>>>> name I can see on the Certification authority MMC?
>>>>>>>>>>>
>>>>>>>>>>> I can browse the CA with the comupter name \\dcshdct02 but not 
>>>>>>>>>>> the name I see on the CA MMC.
>>>>>>>>>>>
>>>>>>>>>>> Julien
>>>>>>>>>>>
>>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>> The CAName is the computer name of your CA (Certificate 
>>>>>>>>>> Authority) server.
>>>>>>>>>>
>>>>>>>>>> Is dcshdct02 the name of the CA? If so, what do you mean by can't 
>>>>>>>>>> browse by the name in the CA MMC console? what name is that?
>>>>>>>>>>
>>>>>>>>>> Ace
>>>>>>>>>> 
0
Jorge
2/11/2010 5:55:20 PM
"Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
news:05mdnTtB8_9hLe_WnZ2dnUVZ8qSdnZ2d@giganews.com...
> ok simple 127.0.0.1 I have delete ... I don't know why is here.
>
> 192.168.30.2 is my central site and my fist DC on my domain.
>
> I have a lot of site and this address is the ranch for my central offices.
>

In a multi-site scenario, I suggest, as well as the consensus, to use itself 
as the first DNS entry, and the other one as the second entry, otherwise all 
intial queries will be hitting the first entry across the WAN link.

Good you removed the loopback. That was put in by dcpromo.

Ace



0
Ace
2/12/2010 5:04:34 AM
"Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
news:PtudnVYir6kY-O_WnZ2dnUVZ8vednZ2d@giganews.com...
> Hello,
>
>
> This is my ipconfig :
>
> ----------------------------------------------------------------------------------------------
>
> ipconfig /all
>
> Windows IP Configuration
>
>   Host Name . . . . . . . . . . . . : DCITDCT01
>   Primary Dns Suffix  . . . . . . . : mydomain.local
>   Node Type . . . . . . . . . . . . : Hybrid
>   IP Routing Enabled. . . . . . . . : No
>   WINS Proxy Enabled. . . . . . . . : No
>   DNS Suffix Search List. . . . . . : mydomain.local
>
> Ethernet adDCter Local Area Connection:
>
>   Connection-specific DNS Suffix  . :
>   Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network 
> Connection
>   Physical Address. . . . . . . . . : 00-0C-29-72-A4-A4
>   DHCP Enabled. . . . . . . . . . . : No
>   Autoconfiguration Enabled . . . . : Yes
>   IPv4 Address. . . . . . . . . . . : 192.168.11.14(Preferred)
>   Subnet Mask . . . . . . . . . . . : 255.255.255.0
>   Default Gateway . . . . . . . . . : 192.168.11.254
>   DNS Servers . . . . . . . . . . . : 192.168.11.14
>                                       192.168.30.2
>                                       127.0.0.1
>   NetBIOS over Tcpip. . . . . . . . : Enabled
>
> Tunnel adDCter isatDC.{6DE906DB-E4F6-45A1-A6D3-A5B10F2663BA}:
>
>   Media State . . . . . . . . . . . : Media disconnected
>   Connection-specific DNS Suffix  . :
>   Description . . . . . . . . . . . : Microsoft ISATDC AdDCter
>   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
>   DHCP Enabled. . . . . . . . . . . : No
>   Autoconfiguration Enabled . . . . : Yes
>
> Tunnel adDCter Local Area Connection* 11:
>
>   Media State . . . . . . . . . . . : Media disconnected
>   Connection-specific DNS Suffix  . :
>   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
>   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
>   DHCP Enabled. . . . . . . . . . . : No
>   Autoconfiguration Enabled . . . . : Yes
>
> -------------------------------------------------------------------------------------------------------------
>
> Here are my application log error :
>
> -------------------------------------------------------------------------------------------------------------
>
> Log Name:      DCplication
> Source:        Microsoft-Windows-CertificateServicesClient-AutoEnrollment
> Date:          10.02.2010 05:42:07
> Event ID:      6
> Task Category: None
> Level:         Error
> Keywords:      Classic
> User:          N/A
> Computer:      DCITDCT01.mydomain.local
> Description:
> Automatic certificate enrollment for local system failed (0x800706ba) The 
> RPC server is unavailable.
> .
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>  <System>
>    <Provider 
> Name="Microsoft-Windows-CertificateServicesClient-AutoEnrollment" 
> Guid="{F0DB7EF8-B6F3-4005-9937-FEB77B9E1B43}" 
> EventSourceName="AutoEnrollment" />
>    <EventID Qualifiers="16384">6</EventID>
>    <Version>0</Version>
>    <Level>2</Level>
>    <Task>0</Task>
>    <Opcode>0</Opcode>
>    <Keywords>0x80000000000000</Keywords>
>    <TimeCreated SystemTime="2010-02-10T04:42:07.000000000Z" />
>    <EventRecordID>2334</EventRecordID>
>    <Correlation />
>    <Execution ProcessID="0" ThreadID="0" />
>    <Channel>DCplication</Channel>
>    <Computer>DCITDCT01.mydomain.local</Computer>
>    <Security />
>  </System>
>  <EventData>
>    <Data Name="Context">local system</Data>
>    <Data Name="ErrorCode">0x800706ba</Data>
>    <Data Name="ErrorMsg">The RPC server is unavailable.
> </Data>
>  </EventData>
> </Event>
>
> Log Name:      DCplication
> Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
> Date:          10.02.2010 05:42:07
> Event ID:      13
> Task Category: None
> Level:         Error
> Keywords:      Classic
> User:          SYSTEM
> Computer:      DCITDCT01.mydomain.local
> Description:
> Certificate enrollment for Local system failed to enroll for a 
> DomainController certificate with request ID N/A from 
> DCSHDCT02.mydomain.local\mydomain-DCSHDCT02-CA (The RPC server is 
> unavailable. 0x800706ba (WIN32: 1722)).
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>  <System>
>    <Provider Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
> Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" EventSourceName="CertEnroll" 
> />
>    <EventID Qualifiers="49754">13</EventID>
>    <Version>0</Version>
>    <Level>2</Level>
>    <Task>0</Task>
>    <Opcode>0</Opcode>
>    <Keywords>0x80000000000000</Keywords>
>    <TimeCreated SystemTime="2010-02-10T04:42:07.000000000Z" />
>    <EventRecordID>2333</EventRecordID>
>    <Correlation />
>    <Execution ProcessID="0" ThreadID="0" />
>    <Channel>DCplication</Channel>
>    <Computer>DCITDCT01.mydomain.local</Computer>
>    <Security UserID="S-1-5-18" />
>  </System>
>  <EventData>
>    <Data Name="Context">Local system</Data>
>    <Data Name="TemplateName">DomainController</Data>
>    <Data 
> Name="RequestId">DCSHDCT02.mydomain.local\mydomain-DCSHDCT02-CA</Data>
>    <Data Name="CA">N/A</Data>
>    <Data Name="ErrorCode">The RPC server is unavailable. 0x800706ba 
> (WIN32: 1722)</Data>
>  </EventData>
> </Event>
>
> Log Name:      DCplication
> Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
> Date:          10.02.2010 05:41:26
> Event ID:      64
> Task Category: None
> Level:         Information
> Keywords:      Classic
> User:          SYSTEM
> Computer:      DCITDCT01.mydomain.local
> Description:
> Certificate enrollment for Local system successfully load policy from 
> policy server
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>  <System>
>    <Provider Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
> Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" EventSourceName="CertEnroll" 
> />
>    <EventID Qualifiers="33370">64</EventID>
>    <Version>0</Version>
>    <Level>0</Level>
>    <Task>0</Task>
>    <Opcode>0</Opcode>
>    <Keywords>0x80000000000000</Keywords>
>    <TimeCreated SystemTime="2010-02-10T04:41:26.000000000Z" />
>    <EventRecordID>2332</EventRecordID>
>    <Correlation />
>    <Execution ProcessID="0" ThreadID="0" />
>    <Channel>DCplication</Channel>
>    <Computer>DCITDCT01.mydomain.local</Computer>
>    <Security UserID="S-1-5-18" />
>  </System>
>  <EventData>
>    <Data Name="Context">Local system</Data>
>    <Data Name="ServerID">
>    </Data>
>  </EventData>
> </Event>
>
> Log Name:      DCplication
> Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
> Date:          10.02.2010 05:41:26
> Event ID:      65
> Task Category: None
> Level:         Information
> Keywords:      Classic
> User:          SYSTEM
> Computer:      DCITDCT01.mydomain.local
> Description:
> Certificate enrollment for Local system is successfully authenticated by 
> policy server {A1DF368B-D850-4F4E-9ACF-80ADABD8C1D9}
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>  <System>
>    <Provider Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
> Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" EventSourceName="CertEnroll" 
> />
>    <EventID Qualifiers="33370">65</EventID>
>    <Version>0</Version>
>    <Level>0</Level>
>    <Task>0</Task>
>    <Opcode>0</Opcode>
>    <Keywords>0x80000000000000</Keywords>
>    <TimeCreated SystemTime="2010-02-10T04:41:26.000000000Z" />
>    <EventRecordID>2331</EventRecordID>
>    <Correlation />
>    <Execution ProcessID="0" ThreadID="0" />
>    <Channel>DCplication</Channel>
>    <Computer>DCITDCT01.mydomain.local</Computer>
>    <Security UserID="S-1-5-18" />
>  </System>
>  <EventData>
>    <Data Name="Context">Local system</Data>
>    <Data Name="ServerURL">{A1DF368B-D850-4F4E-9ACF-80ADABD8C1D9}</Data>
>  </EventData>
> </Event>
>
> Log Name:      DCplication
> Source:        SceCli
> Date:          10.02.2010 03:11:30
> Event ID:      1704
> Task Category: None
> Level:         Information
> Keywords:      Classic
> User:          N/A
> Computer:      DCITDCT01.mydomain.local
> Description:
> Security policy in the Group policy objects has been DCplied successfully.
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>  <System>
>    <Provider Name="SceCli" />
>    <EventID Qualifiers="16384">1704</EventID>
>    <Level>4</Level>
>    <Task>0</Task>
>    <Keywords>0x80000000000000</Keywords>
>    <TimeCreated SystemTime="2010-02-10T02:11:30.000000000Z" />
>    <EventRecordID>2330</EventRecordID>
>    <Channel>DCplication</Channel>
>    <Computer>DCITDCT01.mydomain.local</Computer>
>    <Security />
>  </System>
>  <EventData>
>    <Data>
>    </Data>
>  </EventData>
> </Event>
>
> ---------------------------------------------------------------------------------------------------------------------------
>
> Here are my system log error :
>
> -----------------------------------------------------------------------------------------------------------------------------
>
> Log Name:      System
> Source:        Microsoft-Windows-Kerberos-Key-Distribution-Center
> Date:          10.02.2010 01:39:03
> Event ID:      29
> Task Category: None
> Level:         Warning
> Keywords:      Classic
> User:          N/A
> Computer:      DCITDCT01.mydomain.local
> Description:
> The Key Distribution Center (KDC) cannot find a suitable certificate to 
> use for smart card logons, or the KDC certificate could not be verified. 
> Smart card logon may not function correctly if this problem is not 
> resolved. To correct this problem, either verify the existing KDC 
> certificate using certutil.exe or enroll for a new KDC certificate.
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>  <System>
>    <Provider Name="Microsoft-Windows-Kerberos-Key-Distribution-Center" 
> Guid="{3FD9DA1A-5A54-46C5-9A26-9BD7C0685056}" EventSourceName="KDC" />
>    <EventID Qualifiers="32768">29</EventID>
>    <Version>0</Version>
>    <Level>3</Level>
>    <Task>0</Task>
>    <Opcode>0</Opcode>
>    <Keywords>0x80000000000000</Keywords>
>    <TimeCreated SystemTime="2010-02-10T00:39:03.000000000Z" />
>    <EventRecordID>3205</EventRecordID>
>    <Correlation />
>    <Execution ProcessID="0" ThreadID="0" />
>    <Channel>System</Channel>
>    <Computer>DCITDCT01.mydomain.local</Computer>
>    <Security />
>  </System>
>  <EventData>
>  </EventData>
> </Event>
>
> ----------------------------------------------------------------------------------------------------------------------------------------------------------
>
> I don't have any other error except DFS Replication that I maid for remote 
> backup.
>
> Did you need more details or log?



Thank you for posting this info. All the errors indicate the CA is not 
resolvable or responding. Follow Jorge's suggestions.

Also, I was curious of this part, but I didn't see it in your response:

Can you connect to the CA using a browser? If you can, you can request a
cert.

https://dcshdct02
or
http://dcshdct02

Ace 


0
Ace
2/12/2010 5:07:39 AM
Ops, I also miss that important part about http; https access...

-- 

I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MVP Directory Services

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.




"Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in message 
news:uq#UOF6qKHA.4604@TK2MSFTNGP05.phx.gbl...
> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
> news:PtudnVYir6kY-O_WnZ2dnUVZ8vednZ2d@giganews.com...
>> Hello,
>>
>>
>> This is my ipconfig :
>>
>> ----------------------------------------------------------------------------------------------
>>
>> ipconfig /all
>>
>> Windows IP Configuration
>>
>>   Host Name . . . . . . . . . . . . : DCITDCT01
>>   Primary Dns Suffix  . . . . . . . : mydomain.local
>>   Node Type . . . . . . . . . . . . : Hybrid
>>   IP Routing Enabled. . . . . . . . : No
>>   WINS Proxy Enabled. . . . . . . . : No
>>   DNS Suffix Search List. . . . . . : mydomain.local
>>
>> Ethernet adDCter Local Area Connection:
>>
>>   Connection-specific DNS Suffix  . :
>>   Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network 
>> Connection
>>   Physical Address. . . . . . . . . : 00-0C-29-72-A4-A4
>>   DHCP Enabled. . . . . . . . . . . : No
>>   Autoconfiguration Enabled . . . . : Yes
>>   IPv4 Address. . . . . . . . . . . : 192.168.11.14(Preferred)
>>   Subnet Mask . . . . . . . . . . . : 255.255.255.0
>>   Default Gateway . . . . . . . . . : 192.168.11.254
>>   DNS Servers . . . . . . . . . . . : 192.168.11.14
>>                                       192.168.30.2
>>                                       127.0.0.1
>>   NetBIOS over Tcpip. . . . . . . . : Enabled
>>
>> Tunnel adDCter isatDC.{6DE906DB-E4F6-45A1-A6D3-A5B10F2663BA}:
>>
>>   Media State . . . . . . . . . . . : Media disconnected
>>   Connection-specific DNS Suffix  . :
>>   Description . . . . . . . . . . . : Microsoft ISATDC AdDCter
>>   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
>>   DHCP Enabled. . . . . . . . . . . : No
>>   Autoconfiguration Enabled . . . . : Yes
>>
>> Tunnel adDCter Local Area Connection* 11:
>>
>>   Media State . . . . . . . . . . . : Media disconnected
>>   Connection-specific DNS Suffix  . :
>>   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
>>   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
>>   DHCP Enabled. . . . . . . . . . . : No
>>   Autoconfiguration Enabled . . . . : Yes
>>
>> -------------------------------------------------------------------------------------------------------------
>>
>> Here are my application log error :
>>
>> -------------------------------------------------------------------------------------------------------------
>>
>> Log Name:      DCplication
>> Source:        Microsoft-Windows-CertificateServicesClient-AutoEnrollment
>> Date:          10.02.2010 05:42:07
>> Event ID:      6
>> Task Category: None
>> Level:         Error
>> Keywords:      Classic
>> User:          N/A
>> Computer:      DCITDCT01.mydomain.local
>> Description:
>> Automatic certificate enrollment for local system failed (0x800706ba) The 
>> RPC server is unavailable.
>> .
>> Event Xml:
>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>  <System>
>>    <Provider 
>> Name="Microsoft-Windows-CertificateServicesClient-AutoEnrollment" 
>> Guid="{F0DB7EF8-B6F3-4005-9937-FEB77B9E1B43}" 
>> EventSourceName="AutoEnrollment" />
>>    <EventID Qualifiers="16384">6</EventID>
>>    <Version>0</Version>
>>    <Level>2</Level>
>>    <Task>0</Task>
>>    <Opcode>0</Opcode>
>>    <Keywords>0x80000000000000</Keywords>
>>    <TimeCreated SystemTime="2010-02-10T04:42:07.000000000Z" />
>>    <EventRecordID>2334</EventRecordID>
>>    <Correlation />
>>    <Execution ProcessID="0" ThreadID="0" />
>>    <Channel>DCplication</Channel>
>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>    <Security />
>>  </System>
>>  <EventData>
>>    <Data Name="Context">local system</Data>
>>    <Data Name="ErrorCode">0x800706ba</Data>
>>    <Data Name="ErrorMsg">The RPC server is unavailable.
>> </Data>
>>  </EventData>
>> </Event>
>>
>> Log Name:      DCplication
>> Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
>> Date:          10.02.2010 05:42:07
>> Event ID:      13
>> Task Category: None
>> Level:         Error
>> Keywords:      Classic
>> User:          SYSTEM
>> Computer:      DCITDCT01.mydomain.local
>> Description:
>> Certificate enrollment for Local system failed to enroll for a 
>> DomainController certificate with request ID N/A from 
>> DCSHDCT02.mydomain.local\mydomain-DCSHDCT02-CA (The RPC server is 
>> unavailable. 0x800706ba (WIN32: 1722)).
>> Event Xml:
>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>  <System>
>>    <Provider 
>> Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
>> Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" 
>> EventSourceName="CertEnroll" />
>>    <EventID Qualifiers="49754">13</EventID>
>>    <Version>0</Version>
>>    <Level>2</Level>
>>    <Task>0</Task>
>>    <Opcode>0</Opcode>
>>    <Keywords>0x80000000000000</Keywords>
>>    <TimeCreated SystemTime="2010-02-10T04:42:07.000000000Z" />
>>    <EventRecordID>2333</EventRecordID>
>>    <Correlation />
>>    <Execution ProcessID="0" ThreadID="0" />
>>    <Channel>DCplication</Channel>
>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>    <Security UserID="S-1-5-18" />
>>  </System>
>>  <EventData>
>>    <Data Name="Context">Local system</Data>
>>    <Data Name="TemplateName">DomainController</Data>
>>    <Data 
>> Name="RequestId">DCSHDCT02.mydomain.local\mydomain-DCSHDCT02-CA</Data>
>>    <Data Name="CA">N/A</Data>
>>    <Data Name="ErrorCode">The RPC server is unavailable. 0x800706ba 
>> (WIN32: 1722)</Data>
>>  </EventData>
>> </Event>
>>
>> Log Name:      DCplication
>> Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
>> Date:          10.02.2010 05:41:26
>> Event ID:      64
>> Task Category: None
>> Level:         Information
>> Keywords:      Classic
>> User:          SYSTEM
>> Computer:      DCITDCT01.mydomain.local
>> Description:
>> Certificate enrollment for Local system successfully load policy from 
>> policy server
>> Event Xml:
>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>  <System>
>>    <Provider 
>> Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
>> Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" 
>> EventSourceName="CertEnroll" />
>>    <EventID Qualifiers="33370">64</EventID>
>>    <Version>0</Version>
>>    <Level>0</Level>
>>    <Task>0</Task>
>>    <Opcode>0</Opcode>
>>    <Keywords>0x80000000000000</Keywords>
>>    <TimeCreated SystemTime="2010-02-10T04:41:26.000000000Z" />
>>    <EventRecordID>2332</EventRecordID>
>>    <Correlation />
>>    <Execution ProcessID="0" ThreadID="0" />
>>    <Channel>DCplication</Channel>
>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>    <Security UserID="S-1-5-18" />
>>  </System>
>>  <EventData>
>>    <Data Name="Context">Local system</Data>
>>    <Data Name="ServerID">
>>    </Data>
>>  </EventData>
>> </Event>
>>
>> Log Name:      DCplication
>> Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
>> Date:          10.02.2010 05:41:26
>> Event ID:      65
>> Task Category: None
>> Level:         Information
>> Keywords:      Classic
>> User:          SYSTEM
>> Computer:      DCITDCT01.mydomain.local
>> Description:
>> Certificate enrollment for Local system is successfully authenticated by 
>> policy server {A1DF368B-D850-4F4E-9ACF-80ADABD8C1D9}
>> Event Xml:
>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>  <System>
>>    <Provider 
>> Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
>> Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" 
>> EventSourceName="CertEnroll" />
>>    <EventID Qualifiers="33370">65</EventID>
>>    <Version>0</Version>
>>    <Level>0</Level>
>>    <Task>0</Task>
>>    <Opcode>0</Opcode>
>>    <Keywords>0x80000000000000</Keywords>
>>    <TimeCreated SystemTime="2010-02-10T04:41:26.000000000Z" />
>>    <EventRecordID>2331</EventRecordID>
>>    <Correlation />
>>    <Execution ProcessID="0" ThreadID="0" />
>>    <Channel>DCplication</Channel>
>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>    <Security UserID="S-1-5-18" />
>>  </System>
>>  <EventData>
>>    <Data Name="Context">Local system</Data>
>>    <Data Name="ServerURL">{A1DF368B-D850-4F4E-9ACF-80ADABD8C1D9}</Data>
>>  </EventData>
>> </Event>
>>
>> Log Name:      DCplication
>> Source:        SceCli
>> Date:          10.02.2010 03:11:30
>> Event ID:      1704
>> Task Category: None
>> Level:         Information
>> Keywords:      Classic
>> User:          N/A
>> Computer:      DCITDCT01.mydomain.local
>> Description:
>> Security policy in the Group policy objects has been DCplied 
>> successfully.
>> Event Xml:
>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>  <System>
>>    <Provider Name="SceCli" />
>>    <EventID Qualifiers="16384">1704</EventID>
>>    <Level>4</Level>
>>    <Task>0</Task>
>>    <Keywords>0x80000000000000</Keywords>
>>    <TimeCreated SystemTime="2010-02-10T02:11:30.000000000Z" />
>>    <EventRecordID>2330</EventRecordID>
>>    <Channel>DCplication</Channel>
>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>    <Security />
>>  </System>
>>  <EventData>
>>    <Data>
>>    </Data>
>>  </EventData>
>> </Event>
>>
>> ---------------------------------------------------------------------------------------------------------------------------
>>
>> Here are my system log error :
>>
>> -----------------------------------------------------------------------------------------------------------------------------
>>
>> Log Name:      System
>> Source:        Microsoft-Windows-Kerberos-Key-Distribution-Center
>> Date:          10.02.2010 01:39:03
>> Event ID:      29
>> Task Category: None
>> Level:         Warning
>> Keywords:      Classic
>> User:          N/A
>> Computer:      DCITDCT01.mydomain.local
>> Description:
>> The Key Distribution Center (KDC) cannot find a suitable certificate to 
>> use for smart card logons, or the KDC certificate could not be verified. 
>> Smart card logon may not function correctly if this problem is not 
>> resolved. To correct this problem, either verify the existing KDC 
>> certificate using certutil.exe or enroll for a new KDC certificate.
>> Event Xml:
>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>  <System>
>>    <Provider Name="Microsoft-Windows-Kerberos-Key-Distribution-Center" 
>> Guid="{3FD9DA1A-5A54-46C5-9A26-9BD7C0685056}" EventSourceName="KDC" />
>>    <EventID Qualifiers="32768">29</EventID>
>>    <Version>0</Version>
>>    <Level>3</Level>
>>    <Task>0</Task>
>>    <Opcode>0</Opcode>
>>    <Keywords>0x80000000000000</Keywords>
>>    <TimeCreated SystemTime="2010-02-10T00:39:03.000000000Z" />
>>    <EventRecordID>3205</EventRecordID>
>>    <Correlation />
>>    <Execution ProcessID="0" ThreadID="0" />
>>    <Channel>System</Channel>
>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>    <Security />
>>  </System>
>>  <EventData>
>>  </EventData>
>> </Event>
>>
>> ----------------------------------------------------------------------------------------------------------------------------------------------------------
>>
>> I don't have any other error except DFS Replication that I maid for 
>> remote backup.
>>
>> Did you need more details or log?
>
>
>
> Thank you for posting this info. All the errors indicate the CA is not 
> resolvable or responding. Follow Jorge's suggestions.
>
> Also, I was curious of this part, but I didn't see it in your response:
>
> Can you connect to the CA using a browser? If you can, you can request a
> cert.
>
> https://dcshdct02
> or
> http://dcshdct02
>
> Ace
> 
0
Jorge
2/13/2010 11:36:28 PM
"Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
news:15204AD8-4F67-4E61-A811-FF63B304EFF3@microsoft.com...

I figured that would be the easiest way to tell if it's working. :-)

Ace


> Ops, I also miss that important part about http; https access...
>
> -- 
>
> I hope that the information above helps you.
> Have a Nice day.
>
> Jorge Silva
> MVP Directory Services
>
> Please no e-mails, any questions should be posted in the NewsGroup
> This posting is provided "AS IS" with no warranties, and confers no 
> rights.
>
>
>
>
> "Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in 
> message news:uq#UOF6qKHA.4604@TK2MSFTNGP05.phx.gbl...
>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>> news:PtudnVYir6kY-O_WnZ2dnUVZ8vednZ2d@giganews.com...
>>> Hello,
>>>
>>>
>>> This is my ipconfig :
>>>
>>> ----------------------------------------------------------------------------------------------
>>>
>>> ipconfig /all
>>>
>>> Windows IP Configuration
>>>
>>>   Host Name . . . . . . . . . . . . : DCITDCT01
>>>   Primary Dns Suffix  . . . . . . . : mydomain.local
>>>   Node Type . . . . . . . . . . . . : Hybrid
>>>   IP Routing Enabled. . . . . . . . : No
>>>   WINS Proxy Enabled. . . . . . . . : No
>>>   DNS Suffix Search List. . . . . . : mydomain.local
>>>
>>> Ethernet adDCter Local Area Connection:
>>>
>>>   Connection-specific DNS Suffix  . :
>>>   Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network 
>>> Connection
>>>   Physical Address. . . . . . . . . : 00-0C-29-72-A4-A4
>>>   DHCP Enabled. . . . . . . . . . . : No
>>>   Autoconfiguration Enabled . . . . : Yes
>>>   IPv4 Address. . . . . . . . . . . : 192.168.11.14(Preferred)
>>>   Subnet Mask . . . . . . . . . . . : 255.255.255.0
>>>   Default Gateway . . . . . . . . . : 192.168.11.254
>>>   DNS Servers . . . . . . . . . . . : 192.168.11.14
>>>                                       192.168.30.2
>>>                                       127.0.0.1
>>>   NetBIOS over Tcpip. . . . . . . . : Enabled
>>>
>>> Tunnel adDCter isatDC.{6DE906DB-E4F6-45A1-A6D3-A5B10F2663BA}:
>>>
>>>   Media State . . . . . . . . . . . : Media disconnected
>>>   Connection-specific DNS Suffix  . :
>>>   Description . . . . . . . . . . . : Microsoft ISATDC AdDCter
>>>   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
>>>   DHCP Enabled. . . . . . . . . . . : No
>>>   Autoconfiguration Enabled . . . . : Yes
>>>
>>> Tunnel adDCter Local Area Connection* 11:
>>>
>>>   Media State . . . . . . . . . . . : Media disconnected
>>>   Connection-specific DNS Suffix  . :
>>>   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
>>>   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
>>>   DHCP Enabled. . . . . . . . . . . : No
>>>   Autoconfiguration Enabled . . . . : Yes
>>>
>>> -------------------------------------------------------------------------------------------------------------
>>>
>>> Here are my application log error :
>>>
>>> -------------------------------------------------------------------------------------------------------------
>>>
>>> Log Name:      DCplication
>>> Source: 
>>> Microsoft-Windows-CertificateServicesClient-AutoEnrollment
>>> Date:          10.02.2010 05:42:07
>>> Event ID:      6
>>> Task Category: None
>>> Level:         Error
>>> Keywords:      Classic
>>> User:          N/A
>>> Computer:      DCITDCT01.mydomain.local
>>> Description:
>>> Automatic certificate enrollment for local system failed (0x800706ba) 
>>> The RPC server is unavailable.
>>> .
>>> Event Xml:
>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>  <System>
>>>    <Provider 
>>> Name="Microsoft-Windows-CertificateServicesClient-AutoEnrollment" 
>>> Guid="{F0DB7EF8-B6F3-4005-9937-FEB77B9E1B43}" 
>>> EventSourceName="AutoEnrollment" />
>>>    <EventID Qualifiers="16384">6</EventID>
>>>    <Version>0</Version>
>>>    <Level>2</Level>
>>>    <Task>0</Task>
>>>    <Opcode>0</Opcode>
>>>    <Keywords>0x80000000000000</Keywords>
>>>    <TimeCreated SystemTime="2010-02-10T04:42:07.000000000Z" />
>>>    <EventRecordID>2334</EventRecordID>
>>>    <Correlation />
>>>    <Execution ProcessID="0" ThreadID="0" />
>>>    <Channel>DCplication</Channel>
>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>    <Security />
>>>  </System>
>>>  <EventData>
>>>    <Data Name="Context">local system</Data>
>>>    <Data Name="ErrorCode">0x800706ba</Data>
>>>    <Data Name="ErrorMsg">The RPC server is unavailable.
>>> </Data>
>>>  </EventData>
>>> </Event>
>>>
>>> Log Name:      DCplication
>>> Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
>>> Date:          10.02.2010 05:42:07
>>> Event ID:      13
>>> Task Category: None
>>> Level:         Error
>>> Keywords:      Classic
>>> User:          SYSTEM
>>> Computer:      DCITDCT01.mydomain.local
>>> Description:
>>> Certificate enrollment for Local system failed to enroll for a 
>>> DomainController certificate with request ID N/A from 
>>> DCSHDCT02.mydomain.local\mydomain-DCSHDCT02-CA (The RPC server is 
>>> unavailable. 0x800706ba (WIN32: 1722)).
>>> Event Xml:
>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>  <System>
>>>    <Provider 
>>> Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
>>> Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" 
>>> EventSourceName="CertEnroll" />
>>>    <EventID Qualifiers="49754">13</EventID>
>>>    <Version>0</Version>
>>>    <Level>2</Level>
>>>    <Task>0</Task>
>>>    <Opcode>0</Opcode>
>>>    <Keywords>0x80000000000000</Keywords>
>>>    <TimeCreated SystemTime="2010-02-10T04:42:07.000000000Z" />
>>>    <EventRecordID>2333</EventRecordID>
>>>    <Correlation />
>>>    <Execution ProcessID="0" ThreadID="0" />
>>>    <Channel>DCplication</Channel>
>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>    <Security UserID="S-1-5-18" />
>>>  </System>
>>>  <EventData>
>>>    <Data Name="Context">Local system</Data>
>>>    <Data Name="TemplateName">DomainController</Data>
>>>    <Data 
>>> Name="RequestId">DCSHDCT02.mydomain.local\mydomain-DCSHDCT02-CA</Data>
>>>    <Data Name="CA">N/A</Data>
>>>    <Data Name="ErrorCode">The RPC server is unavailable. 0x800706ba 
>>> (WIN32: 1722)</Data>
>>>  </EventData>
>>> </Event>
>>>
>>> Log Name:      DCplication
>>> Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
>>> Date:          10.02.2010 05:41:26
>>> Event ID:      64
>>> Task Category: None
>>> Level:         Information
>>> Keywords:      Classic
>>> User:          SYSTEM
>>> Computer:      DCITDCT01.mydomain.local
>>> Description:
>>> Certificate enrollment for Local system successfully load policy from 
>>> policy server
>>> Event Xml:
>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>  <System>
>>>    <Provider 
>>> Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
>>> Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" 
>>> EventSourceName="CertEnroll" />
>>>    <EventID Qualifiers="33370">64</EventID>
>>>    <Version>0</Version>
>>>    <Level>0</Level>
>>>    <Task>0</Task>
>>>    <Opcode>0</Opcode>
>>>    <Keywords>0x80000000000000</Keywords>
>>>    <TimeCreated SystemTime="2010-02-10T04:41:26.000000000Z" />
>>>    <EventRecordID>2332</EventRecordID>
>>>    <Correlation />
>>>    <Execution ProcessID="0" ThreadID="0" />
>>>    <Channel>DCplication</Channel>
>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>    <Security UserID="S-1-5-18" />
>>>  </System>
>>>  <EventData>
>>>    <Data Name="Context">Local system</Data>
>>>    <Data Name="ServerID">
>>>    </Data>
>>>  </EventData>
>>> </Event>
>>>
>>> Log Name:      DCplication
>>> Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
>>> Date:          10.02.2010 05:41:26
>>> Event ID:      65
>>> Task Category: None
>>> Level:         Information
>>> Keywords:      Classic
>>> User:          SYSTEM
>>> Computer:      DCITDCT01.mydomain.local
>>> Description:
>>> Certificate enrollment for Local system is successfully authenticated by 
>>> policy server {A1DF368B-D850-4F4E-9ACF-80ADABD8C1D9}
>>> Event Xml:
>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>  <System>
>>>    <Provider 
>>> Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
>>> Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" 
>>> EventSourceName="CertEnroll" />
>>>    <EventID Qualifiers="33370">65</EventID>
>>>    <Version>0</Version>
>>>    <Level>0</Level>
>>>    <Task>0</Task>
>>>    <Opcode>0</Opcode>
>>>    <Keywords>0x80000000000000</Keywords>
>>>    <TimeCreated SystemTime="2010-02-10T04:41:26.000000000Z" />
>>>    <EventRecordID>2331</EventRecordID>
>>>    <Correlation />
>>>    <Execution ProcessID="0" ThreadID="0" />
>>>    <Channel>DCplication</Channel>
>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>    <Security UserID="S-1-5-18" />
>>>  </System>
>>>  <EventData>
>>>    <Data Name="Context">Local system</Data>
>>>    <Data Name="ServerURL">{A1DF368B-D850-4F4E-9ACF-80ADABD8C1D9}</Data>
>>>  </EventData>
>>> </Event>
>>>
>>> Log Name:      DCplication
>>> Source:        SceCli
>>> Date:          10.02.2010 03:11:30
>>> Event ID:      1704
>>> Task Category: None
>>> Level:         Information
>>> Keywords:      Classic
>>> User:          N/A
>>> Computer:      DCITDCT01.mydomain.local
>>> Description:
>>> Security policy in the Group policy objects has been DCplied 
>>> successfully.
>>> Event Xml:
>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>  <System>
>>>    <Provider Name="SceCli" />
>>>    <EventID Qualifiers="16384">1704</EventID>
>>>    <Level>4</Level>
>>>    <Task>0</Task>
>>>    <Keywords>0x80000000000000</Keywords>
>>>    <TimeCreated SystemTime="2010-02-10T02:11:30.000000000Z" />
>>>    <EventRecordID>2330</EventRecordID>
>>>    <Channel>DCplication</Channel>
>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>    <Security />
>>>  </System>
>>>  <EventData>
>>>    <Data>
>>>    </Data>
>>>  </EventData>
>>> </Event>
>>>
>>> ---------------------------------------------------------------------------------------------------------------------------
>>>
>>> Here are my system log error :
>>>
>>> -----------------------------------------------------------------------------------------------------------------------------
>>>
>>> Log Name:      System
>>> Source:        Microsoft-Windows-Kerberos-Key-Distribution-Center
>>> Date:          10.02.2010 01:39:03
>>> Event ID:      29
>>> Task Category: None
>>> Level:         Warning
>>> Keywords:      Classic
>>> User:          N/A
>>> Computer:      DCITDCT01.mydomain.local
>>> Description:
>>> The Key Distribution Center (KDC) cannot find a suitable certificate to 
>>> use for smart card logons, or the KDC certificate could not be verified. 
>>> Smart card logon may not function correctly if this problem is not 
>>> resolved. To correct this problem, either verify the existing KDC 
>>> certificate using certutil.exe or enroll for a new KDC certificate.
>>> Event Xml:
>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>  <System>
>>>    <Provider Name="Microsoft-Windows-Kerberos-Key-Distribution-Center" 
>>> Guid="{3FD9DA1A-5A54-46C5-9A26-9BD7C0685056}" EventSourceName="KDC" />
>>>    <EventID Qualifiers="32768">29</EventID>
>>>    <Version>0</Version>
>>>    <Level>3</Level>
>>>    <Task>0</Task>
>>>    <Opcode>0</Opcode>
>>>    <Keywords>0x80000000000000</Keywords>
>>>    <TimeCreated SystemTime="2010-02-10T00:39:03.000000000Z" />
>>>    <EventRecordID>3205</EventRecordID>
>>>    <Correlation />
>>>    <Execution ProcessID="0" ThreadID="0" />
>>>    <Channel>System</Channel>
>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>    <Security />
>>>  </System>
>>>  <EventData>
>>>  </EventData>
>>> </Event>
>>>
>>> ----------------------------------------------------------------------------------------------------------------------------------------------------------
>>>
>>> I don't have any other error except DFS Replication that I maid for 
>>> remote backup.
>>>
>>> Did you need more details or log?
>>
>>
>>
>> Thank you for posting this info. All the errors indicate the CA is not 
>> resolvable or responding. Follow Jorge's suggestions.
>>
>> Also, I was curious of this part, but I didn't see it in your response:
>>
>> Can you connect to the CA using a browser? If you can, you can request a
>> cert.
>>
>> https://dcshdct02
>> or
>> http://dcshdct02
>>
>> Ace
>>



0
Ace
2/14/2010 7:23:34 AM
Hello,

To answer your question, I can access to http://dcshdct02/certsrv but not 
the https://dcshdct02/certsrv

I already try to request a cert but I don't see any domain cert!

I see a strange behavior. If I connect to the a dc with my administrator 
login then try to connect to the url : http://dcshdct02/certsrv I see 
directly the web page.

But if I try this on the dcitdct01, I need to enter my credential info! May 
be it's could be the problem!

Have you any idea


"Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in message 
news:Oy7EfaUrKHA.3344@TK2MSFTNGP06.phx.gbl...
> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
> news:15204AD8-4F67-4E61-A811-FF63B304EFF3@microsoft.com...
>
> I figured that would be the easiest way to tell if it's working. :-)
>
> Ace
>
>
>> Ops, I also miss that important part about http; https access...
>>
>> -- 
>>
>> I hope that the information above helps you.
>> Have a Nice day.
>>
>> Jorge Silva
>> MVP Directory Services
>>
>> Please no e-mails, any questions should be posted in the NewsGroup
>> This posting is provided "AS IS" with no warranties, and confers no 
>> rights.
>>
>>
>>
>>
>> "Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in 
>> message news:uq#UOF6qKHA.4604@TK2MSFTNGP05.phx.gbl...
>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>> news:PtudnVYir6kY-O_WnZ2dnUVZ8vednZ2d@giganews.com...
>>>> Hello,
>>>>
>>>>
>>>> This is my ipconfig :
>>>>
>>>> ----------------------------------------------------------------------------------------------
>>>>
>>>> ipconfig /all
>>>>
>>>> Windows IP Configuration
>>>>
>>>>   Host Name . . . . . . . . . . . . : DCITDCT01
>>>>   Primary Dns Suffix  . . . . . . . : mydomain.local
>>>>   Node Type . . . . . . . . . . . . : Hybrid
>>>>   IP Routing Enabled. . . . . . . . : No
>>>>   WINS Proxy Enabled. . . . . . . . : No
>>>>   DNS Suffix Search List. . . . . . : mydomain.local
>>>>
>>>> Ethernet adDCter Local Area Connection:
>>>>
>>>>   Connection-specific DNS Suffix  . :
>>>>   Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network 
>>>> Connection
>>>>   Physical Address. . . . . . . . . : 00-0C-29-72-A4-A4
>>>>   DHCP Enabled. . . . . . . . . . . : No
>>>>   Autoconfiguration Enabled . . . . : Yes
>>>>   IPv4 Address. . . . . . . . . . . : 192.168.11.14(Preferred)
>>>>   Subnet Mask . . . . . . . . . . . : 255.255.255.0
>>>>   Default Gateway . . . . . . . . . : 192.168.11.254
>>>>   DNS Servers . . . . . . . . . . . : 192.168.11.14
>>>>                                       192.168.30.2
>>>>                                       127.0.0.1
>>>>   NetBIOS over Tcpip. . . . . . . . : Enabled
>>>>
>>>> Tunnel adDCter isatDC.{6DE906DB-E4F6-45A1-A6D3-A5B10F2663BA}:
>>>>
>>>>   Media State . . . . . . . . . . . : Media disconnected
>>>>   Connection-specific DNS Suffix  . :
>>>>   Description . . . . . . . . . . . : Microsoft ISATDC AdDCter
>>>>   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
>>>>   DHCP Enabled. . . . . . . . . . . : No
>>>>   Autoconfiguration Enabled . . . . : Yes
>>>>
>>>> Tunnel adDCter Local Area Connection* 11:
>>>>
>>>>   Media State . . . . . . . . . . . : Media disconnected
>>>>   Connection-specific DNS Suffix  . :
>>>>   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
>>>>   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
>>>>   DHCP Enabled. . . . . . . . . . . : No
>>>>   Autoconfiguration Enabled . . . . : Yes
>>>>
>>>> -------------------------------------------------------------------------------------------------------------
>>>>
>>>> Here are my application log error :
>>>>
>>>> -------------------------------------------------------------------------------------------------------------
>>>>
>>>> Log Name:      DCplication
>>>> Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
>>>> Date:          10.02.2010 05:42:07
>>>> Event ID:      6
>>>> Task Category: None
>>>> Level:         Error
>>>> Keywords:      Classic
>>>> User:          N/A
>>>> Computer:      DCITDCT01.mydomain.local
>>>> Description:
>>>> Automatic certificate enrollment for local system failed (0x800706ba) 
>>>> The RPC server is unavailable.
>>>> .
>>>> Event Xml:
>>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>>  <System>
>>>>    <Provider 
>>>> Name="Microsoft-Windows-CertificateServicesClient-AutoEnrollment" 
>>>> Guid="{F0DB7EF8-B6F3-4005-9937-FEB77B9E1B43}" 
>>>> EventSourceName="AutoEnrollment" />
>>>>    <EventID Qualifiers="16384">6</EventID>
>>>>    <Version>0</Version>
>>>>    <Level>2</Level>
>>>>    <Task>0</Task>
>>>>    <Opcode>0</Opcode>
>>>>    <Keywords>0x80000000000000</Keywords>
>>>>    <TimeCreated SystemTime="2010-02-10T04:42:07.000000000Z" />
>>>>    <EventRecordID>2334</EventRecordID>
>>>>    <Correlation />
>>>>    <Execution ProcessID="0" ThreadID="0" />
>>>>    <Channel>DCplication</Channel>
>>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>>    <Security />
>>>>  </System>
>>>>  <EventData>
>>>>    <Data Name="Context">local system</Data>
>>>>    <Data Name="ErrorCode">0x800706ba</Data>
>>>>    <Data Name="ErrorMsg">The RPC server is unavailable.
>>>> </Data>
>>>>  </EventData>
>>>> </Event>
>>>>
>>>> Log Name:      DCplication
>>>> Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
>>>> Date:          10.02.2010 05:42:07
>>>> Event ID:      13
>>>> Task Category: None
>>>> Level:         Error
>>>> Keywords:      Classic
>>>> User:          SYSTEM
>>>> Computer:      DCITDCT01.mydomain.local
>>>> Description:
>>>> Certificate enrollment for Local system failed to enroll for a 
>>>> DomainController certificate with request ID N/A from 
>>>> DCSHDCT02.mydomain.local\mydomain-DCSHDCT02-CA (The RPC server is 
>>>> unavailable. 0x800706ba (WIN32: 1722)).
>>>> Event Xml:
>>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>>  <System>
>>>>    <Provider 
>>>> Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
>>>> Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" 
>>>> EventSourceName="CertEnroll" />
>>>>    <EventID Qualifiers="49754">13</EventID>
>>>>    <Version>0</Version>
>>>>    <Level>2</Level>
>>>>    <Task>0</Task>
>>>>    <Opcode>0</Opcode>
>>>>    <Keywords>0x80000000000000</Keywords>
>>>>    <TimeCreated SystemTime="2010-02-10T04:42:07.000000000Z" />
>>>>    <EventRecordID>2333</EventRecordID>
>>>>    <Correlation />
>>>>    <Execution ProcessID="0" ThreadID="0" />
>>>>    <Channel>DCplication</Channel>
>>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>>    <Security UserID="S-1-5-18" />
>>>>  </System>
>>>>  <EventData>
>>>>    <Data Name="Context">Local system</Data>
>>>>    <Data Name="TemplateName">DomainController</Data>
>>>>    <Data 
>>>> Name="RequestId">DCSHDCT02.mydomain.local\mydomain-DCSHDCT02-CA</Data>
>>>>    <Data Name="CA">N/A</Data>
>>>>    <Data Name="ErrorCode">The RPC server is unavailable. 0x800706ba 
>>>> (WIN32: 1722)</Data>
>>>>  </EventData>
>>>> </Event>
>>>>
>>>> Log Name:      DCplication
>>>> Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
>>>> Date:          10.02.2010 05:41:26
>>>> Event ID:      64
>>>> Task Category: None
>>>> Level:         Information
>>>> Keywords:      Classic
>>>> User:          SYSTEM
>>>> Computer:      DCITDCT01.mydomain.local
>>>> Description:
>>>> Certificate enrollment for Local system successfully load policy from 
>>>> policy server
>>>> Event Xml:
>>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>>  <System>
>>>>    <Provider 
>>>> Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
>>>> Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" 
>>>> EventSourceName="CertEnroll" />
>>>>    <EventID Qualifiers="33370">64</EventID>
>>>>    <Version>0</Version>
>>>>    <Level>0</Level>
>>>>    <Task>0</Task>
>>>>    <Opcode>0</Opcode>
>>>>    <Keywords>0x80000000000000</Keywords>
>>>>    <TimeCreated SystemTime="2010-02-10T04:41:26.000000000Z" />
>>>>    <EventRecordID>2332</EventRecordID>
>>>>    <Correlation />
>>>>    <Execution ProcessID="0" ThreadID="0" />
>>>>    <Channel>DCplication</Channel>
>>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>>    <Security UserID="S-1-5-18" />
>>>>  </System>
>>>>  <EventData>
>>>>    <Data Name="Context">Local system</Data>
>>>>    <Data Name="ServerID">
>>>>    </Data>
>>>>  </EventData>
>>>> </Event>
>>>>
>>>> Log Name:      DCplication
>>>> Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
>>>> Date:          10.02.2010 05:41:26
>>>> Event ID:      65
>>>> Task Category: None
>>>> Level:         Information
>>>> Keywords:      Classic
>>>> User:          SYSTEM
>>>> Computer:      DCITDCT01.mydomain.local
>>>> Description:
>>>> Certificate enrollment for Local system is successfully authenticated 
>>>> by policy server {A1DF368B-D850-4F4E-9ACF-80ADABD8C1D9}
>>>> Event Xml:
>>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>>  <System>
>>>>    <Provider 
>>>> Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
>>>> Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" 
>>>> EventSourceName="CertEnroll" />
>>>>    <EventID Qualifiers="33370">65</EventID>
>>>>    <Version>0</Version>
>>>>    <Level>0</Level>
>>>>    <Task>0</Task>
>>>>    <Opcode>0</Opcode>
>>>>    <Keywords>0x80000000000000</Keywords>
>>>>    <TimeCreated SystemTime="2010-02-10T04:41:26.000000000Z" />
>>>>    <EventRecordID>2331</EventRecordID>
>>>>    <Correlation />
>>>>    <Execution ProcessID="0" ThreadID="0" />
>>>>    <Channel>DCplication</Channel>
>>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>>    <Security UserID="S-1-5-18" />
>>>>  </System>
>>>>  <EventData>
>>>>    <Data Name="Context">Local system</Data>
>>>>    <Data Name="ServerURL">{A1DF368B-D850-4F4E-9ACF-80ADABD8C1D9}</Data>
>>>>  </EventData>
>>>> </Event>
>>>>
>>>> Log Name:      DCplication
>>>> Source:        SceCli
>>>> Date:          10.02.2010 03:11:30
>>>> Event ID:      1704
>>>> Task Category: None
>>>> Level:         Information
>>>> Keywords:      Classic
>>>> User:          N/A
>>>> Computer:      DCITDCT01.mydomain.local
>>>> Description:
>>>> Security policy in the Group policy objects has been DCplied 
>>>> successfully.
>>>> Event Xml:
>>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>>  <System>
>>>>    <Provider Name="SceCli" />
>>>>    <EventID Qualifiers="16384">1704</EventID>
>>>>    <Level>4</Level>
>>>>    <Task>0</Task>
>>>>    <Keywords>0x80000000000000</Keywords>
>>>>    <TimeCreated SystemTime="2010-02-10T02:11:30.000000000Z" />
>>>>    <EventRecordID>2330</EventRecordID>
>>>>    <Channel>DCplication</Channel>
>>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>>    <Security />
>>>>  </System>
>>>>  <EventData>
>>>>    <Data>
>>>>    </Data>
>>>>  </EventData>
>>>> </Event>
>>>>
>>>> ---------------------------------------------------------------------------------------------------------------------------
>>>>
>>>> Here are my system log error :
>>>>
>>>> -----------------------------------------------------------------------------------------------------------------------------
>>>>
>>>> Log Name:      System
>>>> Source:        Microsoft-Windows-Kerberos-Key-Distribution-Center
>>>> Date:          10.02.2010 01:39:03
>>>> Event ID:      29
>>>> Task Category: None
>>>> Level:         Warning
>>>> Keywords:      Classic
>>>> User:          N/A
>>>> Computer:      DCITDCT01.mydomain.local
>>>> Description:
>>>> The Key Distribution Center (KDC) cannot find a suitable certificate to 
>>>> use for smart card logons, or the KDC certificate could not be 
>>>> verified. Smart card logon may not function correctly if this problem 
>>>> is not resolved. To correct this problem, either verify the existing 
>>>> KDC certificate using certutil.exe or enroll for a new KDC certificate.
>>>> Event Xml:
>>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>>  <System>
>>>>    <Provider Name="Microsoft-Windows-Kerberos-Key-Distribution-Center" 
>>>> Guid="{3FD9DA1A-5A54-46C5-9A26-9BD7C0685056}" EventSourceName="KDC" />
>>>>    <EventID Qualifiers="32768">29</EventID>
>>>>    <Version>0</Version>
>>>>    <Level>3</Level>
>>>>    <Task>0</Task>
>>>>    <Opcode>0</Opcode>
>>>>    <Keywords>0x80000000000000</Keywords>
>>>>    <TimeCreated SystemTime="2010-02-10T00:39:03.000000000Z" />
>>>>    <EventRecordID>3205</EventRecordID>
>>>>    <Correlation />
>>>>    <Execution ProcessID="0" ThreadID="0" />
>>>>    <Channel>System</Channel>
>>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>>    <Security />
>>>>  </System>
>>>>  <EventData>
>>>>  </EventData>
>>>> </Event>
>>>>
>>>> ----------------------------------------------------------------------------------------------------------------------------------------------------------
>>>>
>>>> I don't have any other error except DFS Replication that I maid for 
>>>> remote backup.
>>>>
>>>> Did you need more details or log?
>>>
>>>
>>>
>>> Thank you for posting this info. All the errors indicate the CA is not 
>>> resolvable or responding. Follow Jorge's suggestions.
>>>
>>> Also, I was curious of this part, but I didn't see it in your response:
>>>
>>> Can you connect to the CA using a browser? If you can, you can request a
>>> cert.
>>>
>>> https://dcshdct02
>>> or
>>> http://dcshdct02
>>>
>>> Ace
>>>
>
>
> 
0
Julien
2/15/2010 8:10:31 AM
I do exacly what you say. But I have always the two errors :

First :

Certificate enrollment for Local system failed to enroll for a 
DomainController certificate with request ID N/A from 
APSHDCT02.audemarspiguet.local\audemarspiguet-APSHDCT02-CA (The RPC server 
is unavailable. 0x800706ba (WIN32: 1722)).

Second :

Automatic certificate enrollment for local system failed (0x800706ba) The 
RPC server is unavailable.



"Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
news:325A4C22-8662-431E-820A-E0BC2B8D9A90@microsoft.com...
> Hold on...
> If you're going to reboot the CA...
> 1St the CA, after the CA is up, do 2 reboots with a logon between them on 
> the DC.
>
> -- 
>
> I hope that the information above helps you.
> Have a Nice day.
>
> Jorge Silva
> MVP Directory Services
>
> Please no e-mails, any questions should be posted in the NewsGroup
> This posting is provided "AS IS" with no warranties, and confers no 
> rights.
>
>
>
>
> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
> news:T5idndaKfvbpQ-7WnZ2dnUVZ8vOdnZ2d@giganews.com...
>>> - Did you also test SMB from the CA to the DC?
>>
>> Yes, I do
>>
>>> - Can you ping from both sides (DC and CA) to each other?
>>
>> Yes, I can
>>
>>> - Did you already reboot the DC 2?
>>
>> I have palnned to reboot my dc and the ca this night.
>>
>>
>>
>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>> news:7B115C84-012E-4397-8F34-ECAC27074558@microsoft.com...
>>> Ok,
>>> - Did you also test SMB from the CA to the DC?
>>> - Can you ping from both sides (DC and CA) to each other?
>>> - Did you already reboot the DC 2?
>>>
>>> -- 
>>>
>>> I hope that the information above helps you.
>>> Have a Nice day.
>>>
>>> Jorge Silva
>>> MVP Directory Services
>>>
>>> Please no e-mails, any questions should be posted in the NewsGroup
>>> This posting is provided "AS IS" with no warranties, and confers no 
>>> rights.
>>>
>>>
>>>
>>>
>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>> news:05mdnTtB8_9hLe_WnZ2dnUVZ8qSdnZ2d@giganews.com...
>>>> ok simple 127.0.0.1 I have delete ... I don't know why is here.
>>>>
>>>> 192.168.30.2 is my central site and my fist DC on my domain.
>>>>
>>>> I have a lot of site and this address is the ranch for my central 
>>>> offices.
>>>>
>>>>
>>>>
>>>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>>>> news:D574EA20-F3DB-4511-880C-944F7D1BF4A9@microsoft.com...
>>>>> Ok, do that, can you also explain these 2 DNS entries:
>>>>>                                       192.168.30.2
>>>>>                                       127.0.0.1
>>>>>
>>>>> -- 
>>>>>
>>>>> I hope that the information above helps you.
>>>>> Have a Nice day.
>>>>>
>>>>> Jorge Silva
>>>>> MVP Directory Services
>>>>>
>>>>> Please no e-mails, any questions should be posted in the NewsGroup
>>>>> This posting is provided "AS IS" with no warranties, and confers no 
>>>>> rights.
>>>>>
>>>>>
>>>>>
>>>>>
>>>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>>>> news:df2dnTJWt_Wr-u_WnZ2dnUVZ8qGdnZ2d@giganews.com...
>>>>>> Hello,
>>>>>>
>>>>>>> Did you test SMB from that DC?
>>>>>>
>>>>>> Yes, I did. I test smb connection form and to my dc.
>>>>>>
>>>>>>> IS that DC passing through ISA?
>>>>>>
>>>>>> No, we don't use ISA!
>>>>>>
>>>>>>>You may need to reboot the DC twice
>>>>>>
>>>>>> I'll try this, this night, but if I remember well I already reboot it 
>>>>>> more thant twice.
>>>>>>
>>>>>>
>>>>>> Julien
>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>>>>>> news:76D3BF28-7F66-4CB0-A72A-94928CFFE8AC@microsoft.com...
>>>>>>> Is the CA service started?
>>>>>>> Did you test SMB from that DC?
>>>>>>> IS that DC passing through ISA? IF yes, can you disable the RPC 
>>>>>>> filter for that rule and test again? You may need to reboot the DC 
>>>>>>> twice until that error goes away.
>>>>>>>
>>>>>>> -- 
>>>>>>>
>>>>>>> I hope that the information above helps you.
>>>>>>> Have a Nice day.
>>>>>>>
>>>>>>> Jorge Silva
>>>>>>> MVP Directory Services
>>>>>>>
>>>>>>> Please no e-mails, any questions should be posted in the NewsGroup
>>>>>>> This posting is provided "AS IS" with no warranties, and confers no 
>>>>>>> rights.
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>>>>>> news:la2dnfevwcrtdfLWnZ2dnUVZ8nydnZ2d@giganews.com...
>>>>>>>> Hello,
>>>>>>>>
>>>>>>>> I can do a SMB connection but I don't have the certificate.
>>>>>>>>
>>>>>>>> Can any body help me to resolve this issue?
>>>>>>>>
>>>>>>>> Julien
>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>>>>>>>> news:9A0DEBC9-0F64-4EA7-9A5C-5A21FE44642E@microsoft.com...
>>>>>>>>> Hi
>>>>>>>>> Yes, test the connection using \\dcshdct02
>>>>>>>>>
>>>>>>>>>
>>>>>>>>> -- 
>>>>>>>>>
>>>>>>>>> I hope that the information above helps you.
>>>>>>>>> Have a Nice day.
>>>>>>>>>
>>>>>>>>> Jorge Silva
>>>>>>>>> MVP Directory Services
>>>>>>>>>
>>>>>>>>> Please no e-mails, any questions should be posted in the NewsGroup
>>>>>>>>> This posting is provided "AS IS" with no warranties, and confers 
>>>>>>>>> no rights.
>>>>>>>>>
>>>>>>>>>
>>>>>>>>>
>>>>>>>>>
>>>>>>>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>>>>>>>> news:OoKFGa#oKHA.1548@TK2MSFTNGP02.phx.gbl...
>>>>>>>>>> Hello,
>>>>>>>>>>
>>>>>>>>>> In fact, the computer name is dcshdct02, but if I open the 
>>>>>>>>>> certification authority MMC, the name of the server is : 
>>>>>>>>>> mydomain-DCSHDCT02-CA.
>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>> "Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote 
>>>>>>>>>> in message news:#Yp$jr1oKHA.4836@TK2MSFTNGP05.phx.gbl...
>>>>>>>>>>> "Julien" <jithurbide@removegmail.com> wrote in message 
>>>>>>>>>>> news:uOaW1izoKHA.5260@TK2MSFTNGP02.phx.gbl...
>>>>>>>>>>>> Hello,
>>>>>>>>>>>>
>>>>>>>>>>>> You say :
>>>>>>>>>>>>
>>>>>>>>>>>>> To test do a SMB connection: "\\CAName.yourdomain.tld" from 
>>>>>>>>>>>>> that DC.
>>>>>>>>>>>>
>>>>>>>>>>>> What is the CAName ? My computer name ? like dcshdct02 ? or the 
>>>>>>>>>>>> name I can see on the Certification authority MMC?
>>>>>>>>>>>>
>>>>>>>>>>>> I can browse the CA with the comupter name \\dcshdct02 but not 
>>>>>>>>>>>> the name I see on the CA MMC.
>>>>>>>>>>>>
>>>>>>>>>>>> Julien
>>>>>>>>>>>>
>>>>>>>>>>>>
>>>>>>>>>>>
>>>>>>>>>>>
>>>>>>>>>>> The CAName is the computer name of your CA (Certificate 
>>>>>>>>>>> Authority) server.
>>>>>>>>>>>
>>>>>>>>>>> Is dcshdct02 the name of the CA? If so, what do you mean by 
>>>>>>>>>>> can't browse by the name in the CA MMC console? what name is 
>>>>>>>>>>> that?
>>>>>>>>>>>
>>>>>>>>>>> Ace
>>>>>>>>>>> 
0
Julien
2/15/2010 8:21:30 AM
"Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
news:d9OdnY88GdDlnOTWnZ2dnUVZ8kmdnZ2d@giganews.com...
>
> Hello,
>
> To answer your question, I can access to http://dcshdct02/certsrv but not 
> the https://dcshdct02/certsrv
>
> I already try to request a cert but I don't see any domain cert!
>
> I see a strange behavior. If I connect to the a dc with my administrator 
> login then try to connect to the url : http://dcshdct02/certsrv I see 
> directly the web page.
>
> But if I try this on the dcitdct01, I need to enter my credential info! 
> May be it's could be the problem!
>
> Have you any idea
>
>

Using the URL with the NetBIOS name while logged on as Domain Admin, you 
should immediately get the page without logging on. This is the Windows 
Authentication portion doing it in IIS. Now if you are getting prompted from 
the other DC, then something else is going on. But if you don't see a domain 
cert, and I can't remember if that is normal or not since it should 
automatically be enrolled using your GPO policy, it may be indicative of a 
CA misonfiguration when you set it up.

What article or publication did you follow to set this all up?

Due to the many pieces of a CA, autoenrollment, etc, it would be quite a bit 
of effort to go through what steps you took to install the CA and configure 
the GPO, how you setup permissions on the template, and other specifics. 
Maybe I can offer the following links. I hope they help.

Certificate Autoenrollment in Windows Server 2003Supported Hardware 
(Certificate Autoenrollment in Windows Server 2003) ... Configuring Group 
Policy � User Autoenrollment � Certificate Renewal ...
http://technet.microsoft.com/en-us/library/cc778954(WS.10).aspx

Install Windows Server 2003 CAHow can I install the Certificate Authority 
(CA) service in Windows Server 2003? Windows Server 2003 can be used as a 
Certificate Authority (also known as.
http://www.petri.co.il/install_windows_server_2003_ca.htm

Installing and Configuring Windows Server 2003 Enterprise ...Installing and 
Configuring Windows Server 2003 Enterprise Certification Authority. Topic 
Last Modified: 2005-05-19. The first step in setting up your lab is ...
http://technet.microsoft.com/en-us/library/aa998956(EXCHG.65).aspx

How can I enable digital certificate autoenrollment in Windows ... (Brief 
overview)
Dec 5, 2005 ... A. Autoenrollment is available to Windows 2003 and Windows 
XP domain ... Next you need to enable the Group Policy for the 
autoenrollment. ... (You can also view Failed Requests in the Certificate 
Authority MMC snap-in. ...
http://windowsitpro.com/article/articleid/48665/how-can-i-enable-digital-certificate-autoenrollment-in-windows-server-2003.html

Alex Tcherniakhovski - Security : Certificate auto-enrollment ...Jul 3, 2007 
.... For the most part configuring certificate auto-enrollment is a fairly 
.... but require CA to be running on Windows 2003 Server Enterprise Edition. 
.... In the GPO where the hosts reside configure the following setting ...
http://blogs.msdn.com/alextch/archive/2007/07/03/certautoenroll.aspx

Ace 


0
Ace
2/15/2010 2:01:40 PM
"Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
news:d9OdnY88GdDlnOTWnZ2dnUVZ8kmdnZ2d@giganews.com...
>
> Hello,
>
> To answer your question, I can access to http://dcshdct02/certsrv but not 
> the https://dcshdct02/certsrv
>
> I already try to request a cert but I don't see any domain cert!
>
> I see a strange behavior. If I connect to the a dc with my administrator 
> login then try to connect to the url : http://dcshdct02/certsrv I see 
> directly the web page.
>
> But if I try this on the dcitdct01, I need to enter my credential info! 
> May be it's could be the problem!
>
> Have you any idea
>

I forgot to add, the RPC Unavailable error will be part of the issue. You 
said you disabled the firewall and allowed all ports, correct?

As for not being able to connect by https:// (with the 's'), that means you 
never created or added an SSL cert in IIS.

Ace



0
Ace
2/15/2010 2:03:45 PM
"Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
news:ZJ-dnXbXZ6-XmeTWnZ2dnUVZ8hudnZ2d@giganews.com...
>I do exacly what you say. But I have always the two errors :
>
> First :
>
> Certificate enrollment for Local system failed to enroll for a 
> DomainController certificate with request ID N/A from 
> APSHDCT02.audemarspiguet.local\audemarspiguet-APSHDCT02-CA (The RPC server 
> is unavailable. 0x800706ba (WIN32: 1722)).
>
> Second :
>
> Automatic certificate enrollment for local system failed (0x800706ba) The 
> RPC server is unavailable.
>
>
>

As I mentioned earlier, RPC errors such as this means there is a 
communication block or DNS lookup issue. I assume DNS has the DCs listed, so 
I think tehre is a block going on elsewhere.

Ace



0
Ace
2/15/2010 2:04:55 PM
Ok,
And if you add the " http://dcshdct02/certsrv" to the Local Intranet Web 
Sites trust on dcitdct01?


-- 

I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MVP Directory Services

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.




"Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
news:d9OdnY88GdDlnOTWnZ2dnUVZ8kmdnZ2d@giganews.com...
>
> Hello,
>
> To answer your question, I can access to http://dcshdct02/certsrv but not 
> the https://dcshdct02/certsrv
>
> I already try to request a cert but I don't see any domain cert!
>
> I see a strange behavior. If I connect to the a dc with my administrator 
> login then try to connect to the url : http://dcshdct02/certsrv I see 
> directly the web page.
>
> But if I try this on the dcitdct01, I need to enter my credential info! 
> May be it's could be the problem!
>
> Have you any idea
>
>
> "Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in 
> message news:Oy7EfaUrKHA.3344@TK2MSFTNGP06.phx.gbl...
>> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
>> news:15204AD8-4F67-4E61-A811-FF63B304EFF3@microsoft.com...
>>
>> I figured that would be the easiest way to tell if it's working. :-)
>>
>> Ace
>>
>>
>>> Ops, I also miss that important part about http; https access...
>>>
>>> -- 
>>>
>>> I hope that the information above helps you.
>>> Have a Nice day.
>>>
>>> Jorge Silva
>>> MVP Directory Services
>>>
>>> Please no e-mails, any questions should be posted in the NewsGroup
>>> This posting is provided "AS IS" with no warranties, and confers no 
>>> rights.
>>>
>>>
>>>
>>>
>>> "Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in 
>>> message news:uq#UOF6qKHA.4604@TK2MSFTNGP05.phx.gbl...
>>>> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
>>>> news:PtudnVYir6kY-O_WnZ2dnUVZ8vednZ2d@giganews.com...
>>>>> Hello,
>>>>>
>>>>>
>>>>> This is my ipconfig :
>>>>>
>>>>> ----------------------------------------------------------------------------------------------
>>>>>
>>>>> ipconfig /all
>>>>>
>>>>> Windows IP Configuration
>>>>>
>>>>>   Host Name . . . . . . . . . . . . : DCITDCT01
>>>>>   Primary Dns Suffix  . . . . . . . : mydomain.local
>>>>>   Node Type . . . . . . . . . . . . : Hybrid
>>>>>   IP Routing Enabled. . . . . . . . : No
>>>>>   WINS Proxy Enabled. . . . . . . . : No
>>>>>   DNS Suffix Search List. . . . . . : mydomain.local
>>>>>
>>>>> Ethernet adDCter Local Area Connection:
>>>>>
>>>>>   Connection-specific DNS Suffix  . :
>>>>>   Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network 
>>>>> Connection
>>>>>   Physical Address. . . . . . . . . : 00-0C-29-72-A4-A4
>>>>>   DHCP Enabled. . . . . . . . . . . : No
>>>>>   Autoconfiguration Enabled . . . . : Yes
>>>>>   IPv4 Address. . . . . . . . . . . : 192.168.11.14(Preferred)
>>>>>   Subnet Mask . . . . . . . . . . . : 255.255.255.0
>>>>>   Default Gateway . . . . . . . . . : 192.168.11.254
>>>>>   DNS Servers . . . . . . . . . . . : 192.168.11.14
>>>>>                                       192.168.30.2
>>>>>                                       127.0.0.1
>>>>>   NetBIOS over Tcpip. . . . . . . . : Enabled
>>>>>
>>>>> Tunnel adDCter isatDC.{6DE906DB-E4F6-45A1-A6D3-A5B10F2663BA}:
>>>>>
>>>>>   Media State . . . . . . . . . . . : Media disconnected
>>>>>   Connection-specific DNS Suffix  . :
>>>>>   Description . . . . . . . . . . . : Microsoft ISATDC AdDCter
>>>>>   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
>>>>>   DHCP Enabled. . . . . . . . . . . : No
>>>>>   Autoconfiguration Enabled . . . . : Yes
>>>>>
>>>>> Tunnel adDCter Local Area Connection* 11:
>>>>>
>>>>>   Media State . . . . . . . . . . . : Media disconnected
>>>>>   Connection-specific DNS Suffix  . :
>>>>>   Description . . . . . . . . . . . : Teredo Tunneling 
>>>>> Pseudo-Interface
>>>>>   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
>>>>>   DHCP Enabled. . . . . . . . . . . : No
>>>>>   Autoconfiguration Enabled . . . . : Yes
>>>>>
>>>>> -------------------------------------------------------------------------------------------------------------
>>>>>
>>>>> Here are my application log error :
>>>>>
>>>>> -------------------------------------------------------------------------------------------------------------
>>>>>
>>>>> Log Name:      DCplication
>>>>> Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
>>>>> Date:          10.02.2010 05:42:07
>>>>> Event ID:      6
>>>>> Task Category: None
>>>>> Level:         Error
>>>>> Keywords:      Classic
>>>>> User:          N/A
>>>>> Computer:      DCITDCT01.mydomain.local
>>>>> Description:
>>>>> Automatic certificate enrollment for local system failed (0x800706ba) 
>>>>> The RPC server is unavailable.
>>>>> .
>>>>> Event Xml:
>>>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>>>  <System>
>>>>>    <Provider 
>>>>> Name="Microsoft-Windows-CertificateServicesClient-AutoEnrollment" 
>>>>> Guid="{F0DB7EF8-B6F3-4005-9937-FEB77B9E1B43}" 
>>>>> EventSourceName="AutoEnrollment" />
>>>>>    <EventID Qualifiers="16384">6</EventID>
>>>>>    <Version>0</Version>
>>>>>    <Level>2</Level>
>>>>>    <Task>0</Task>
>>>>>    <Opcode>0</Opcode>
>>>>>    <Keywords>0x80000000000000</Keywords>
>>>>>    <TimeCreated SystemTime="2010-02-10T04:42:07.000000000Z" />
>>>>>    <EventRecordID>2334</EventRecordID>
>>>>>    <Correlation />
>>>>>    <Execution ProcessID="0" ThreadID="0" />
>>>>>    <Channel>DCplication</Channel>
>>>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>>>    <Security />
>>>>>  </System>
>>>>>  <EventData>
>>>>>    <Data Name="Context">local system</Data>
>>>>>    <Data Name="ErrorCode">0x800706ba</Data>
>>>>>    <Data Name="ErrorMsg">The RPC server is unavailable.
>>>>> </Data>
>>>>>  </EventData>
>>>>> </Event>
>>>>>
>>>>> Log Name:      DCplication
>>>>> Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
>>>>> Date:          10.02.2010 05:42:07
>>>>> Event ID:      13
>>>>> Task Category: None
>>>>> Level:         Error
>>>>> Keywords:      Classic
>>>>> User:          SYSTEM
>>>>> Computer:      DCITDCT01.mydomain.local
>>>>> Description:
>>>>> Certificate enrollment for Local system failed to enroll for a 
>>>>> DomainController certificate with request ID N/A from 
>>>>> DCSHDCT02.mydomain.local\mydomain-DCSHDCT02-CA (The RPC server is 
>>>>> unavailable. 0x800706ba (WIN32: 1722)).
>>>>> Event Xml:
>>>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>>>  <System>
>>>>>    <Provider 
>>>>> Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
>>>>> Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" 
>>>>> EventSourceName="CertEnroll" />
>>>>>    <EventID Qualifiers="49754">13</EventID>
>>>>>    <Version>0</Version>
>>>>>    <Level>2</Level>
>>>>>    <Task>0</Task>
>>>>>    <Opcode>0</Opcode>
>>>>>    <Keywords>0x80000000000000</Keywords>
>>>>>    <TimeCreated SystemTime="2010-02-10T04:42:07.000000000Z" />
>>>>>    <EventRecordID>2333</EventRecordID>
>>>>>    <Correlation />
>>>>>    <Execution ProcessID="0" ThreadID="0" />
>>>>>    <Channel>DCplication</Channel>
>>>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>>>    <Security UserID="S-1-5-18" />
>>>>>  </System>
>>>>>  <EventData>
>>>>>    <Data Name="Context">Local system</Data>
>>>>>    <Data Name="TemplateName">DomainController</Data>
>>>>>    <Data 
>>>>> Name="RequestId">DCSHDCT02.mydomain.local\mydomain-DCSHDCT02-CA</Data>
>>>>>    <Data Name="CA">N/A</Data>
>>>>>    <Data Name="ErrorCode">The RPC server is unavailable. 0x800706ba 
>>>>> (WIN32: 1722)</Data>
>>>>>  </EventData>
>>>>> </Event>
>>>>>
>>>>> Log Name:      DCplication
>>>>> Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
>>>>> Date:          10.02.2010 05:41:26
>>>>> Event ID:      64
>>>>> Task Category: None
>>>>> Level:         Information
>>>>> Keywords:      Classic
>>>>> User:          SYSTEM
>>>>> Computer:      DCITDCT01.mydomain.local
>>>>> Description:
>>>>> Certificate enrollment for Local system successfully load policy from 
>>>>> policy server
>>>>> Event Xml:
>>>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>>>  <System>
>>>>>    <Provider 
>>>>> Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
>>>>> Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" 
>>>>> EventSourceName="CertEnroll" />
>>>>>    <EventID Qualifiers="33370">64</EventID>
>>>>>    <Version>0</Version>
>>>>>    <Level>0</Level>
>>>>>    <Task>0</Task>
>>>>>    <Opcode>0</Opcode>
>>>>>    <Keywords>0x80000000000000</Keywords>
>>>>>    <TimeCreated SystemTime="2010-02-10T04:41:26.000000000Z" />
>>>>>    <EventRecordID>2332</EventRecordID>
>>>>>    <Correlation />
>>>>>    <Execution ProcessID="0" ThreadID="0" />
>>>>>    <Channel>DCplication</Channel>
>>>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>>>    <Security UserID="S-1-5-18" />
>>>>>  </System>
>>>>>  <EventData>
>>>>>    <Data Name="Context">Local system</Data>
>>>>>    <Data Name="ServerID">
>>>>>    </Data>
>>>>>  </EventData>
>>>>> </Event>
>>>>>
>>>>> Log Name:      DCplication
>>>>> Source:        Microsoft-Windows-CertificateServicesClient-CertEnroll
>>>>> Date:          10.02.2010 05:41:26
>>>>> Event ID:      65
>>>>> Task Category: None
>>>>> Level:         Information
>>>>> Keywords:      Classic
>>>>> User:          SYSTEM
>>>>> Computer:      DCITDCT01.mydomain.local
>>>>> Description:
>>>>> Certificate enrollment for Local system is successfully authenticated 
>>>>> by policy server {A1DF368B-D850-4F4E-9ACF-80ADABD8C1D9}
>>>>> Event Xml:
>>>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>>>  <System>
>>>>>    <Provider 
>>>>> Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" 
>>>>> Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" 
>>>>> EventSourceName="CertEnroll" />
>>>>>    <EventID Qualifiers="33370">65</EventID>
>>>>>    <Version>0</Version>
>>>>>    <Level>0</Level>
>>>>>    <Task>0</Task>
>>>>>    <Opcode>0</Opcode>
>>>>>    <Keywords>0x80000000000000</Keywords>
>>>>>    <TimeCreated SystemTime="2010-02-10T04:41:26.000000000Z" />
>>>>>    <EventRecordID>2331</EventRecordID>
>>>>>    <Correlation />
>>>>>    <Execution ProcessID="0" ThreadID="0" />
>>>>>    <Channel>DCplication</Channel>
>>>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>>>    <Security UserID="S-1-5-18" />
>>>>>  </System>
>>>>>  <EventData>
>>>>>    <Data Name="Context">Local system</Data>
>>>>>    <Data 
>>>>> Name="ServerURL">{A1DF368B-D850-4F4E-9ACF-80ADABD8C1D9}</Data>
>>>>>  </EventData>
>>>>> </Event>
>>>>>
>>>>> Log Name:      DCplication
>>>>> Source:        SceCli
>>>>> Date:          10.02.2010 03:11:30
>>>>> Event ID:      1704
>>>>> Task Category: None
>>>>> Level:         Information
>>>>> Keywords:      Classic
>>>>> User:          N/A
>>>>> Computer:      DCITDCT01.mydomain.local
>>>>> Description:
>>>>> Security policy in the Group policy objects has been DCplied 
>>>>> successfully.
>>>>> Event Xml:
>>>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>>>  <System>
>>>>>    <Provider Name="SceCli" />
>>>>>    <EventID Qualifiers="16384">1704</EventID>
>>>>>    <Level>4</Level>
>>>>>    <Task>0</Task>
>>>>>    <Keywords>0x80000000000000</Keywords>
>>>>>    <TimeCreated SystemTime="2010-02-10T02:11:30.000000000Z" />
>>>>>    <EventRecordID>2330</EventRecordID>
>>>>>    <Channel>DCplication</Channel>
>>>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>>>    <Security />
>>>>>  </System>
>>>>>  <EventData>
>>>>>    <Data>
>>>>>    </Data>
>>>>>  </EventData>
>>>>> </Event>
>>>>>
>>>>> ---------------------------------------------------------------------------------------------------------------------------
>>>>>
>>>>> Here are my system log error :
>>>>>
>>>>> -----------------------------------------------------------------------------------------------------------------------------
>>>>>
>>>>> Log Name:      System
>>>>> Source:        Microsoft-Windows-Kerberos-Key-Distribution-Center
>>>>> Date:          10.02.2010 01:39:03
>>>>> Event ID:      29
>>>>> Task Category: None
>>>>> Level:         Warning
>>>>> Keywords:      Classic
>>>>> User:          N/A
>>>>> Computer:      DCITDCT01.mydomain.local
>>>>> Description:
>>>>> The Key Distribution Center (KDC) cannot find a suitable certificate 
>>>>> to use for smart card logons, or the KDC certificate could not be 
>>>>> verified. Smart card logon may not function correctly if this problem 
>>>>> is not resolved. To correct this problem, either verify the existing 
>>>>> KDC certificate using certutil.exe or enroll for a new KDC 
>>>>> certificate.
>>>>> Event Xml:
>>>>> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
>>>>>  <System>
>>>>>    <Provider Name="Microsoft-Windows-Kerberos-Key-Distribution-Center" 
>>>>> Guid="{3FD9DA1A-5A54-46C5-9A26-9BD7C0685056}" EventSourceName="KDC" />
>>>>>    <EventID Qualifiers="32768">29</EventID>
>>>>>    <Version>0</Version>
>>>>>    <Level>3</Level>
>>>>>    <Task>0</Task>
>>>>>    <Opcode>0</Opcode>
>>>>>    <Keywords>0x80000000000000</Keywords>
>>>>>    <TimeCreated SystemTime="2010-02-10T00:39:03.000000000Z" />
>>>>>    <EventRecordID>3205</EventRecordID>
>>>>>    <Correlation />
>>>>>    <Execution ProcessID="0" ThreadID="0" />
>>>>>    <Channel>System</Channel>
>>>>>    <Computer>DCITDCT01.mydomain.local</Computer>
>>>>>    <Security />
>>>>>  </System>
>>>>>  <EventData>
>>>>>  </EventData>
>>>>> </Event>
>>>>>
>>>>> ----------------------------------------------------------------------------------------------------------------------------------------------------------
>>>>>
>>>>> I don't have any other error except DFS Replication that I maid for 
>>>>> remote backup.
>>>>>
>>>>> Did you need more details or log?
>>>>
>>>>
>>>>
>>>> Thank you for posting this info. All the errors indicate the CA is not 
>>>> resolvable or responding. Follow Jorge's suggestions.
>>>>
>>>> Also, I was curious of this part, but I didn't see it in your response:
>>>>
>>>> Can you connect to the CA using a browser? If you can, you can request 
>>>> a
>>>> cert.
>>>>
>>>> https://dcshdct02
>>>> or
>>>> http://dcshdct02
>>>>
>>>> Ace
>>>>
>>
>>
>> 
0
Jorge
2/15/2010 8:32:24 PM
I already saw this error, but the problem was related with cached 
credentials on the requester... Can you check that please?

-- 

I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MVP Directory Services

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.




"Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in message 
news:uF8JbfkrKHA.728@TK2MSFTNGP04.phx.gbl...
> "Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
> news:ZJ-dnXbXZ6-XmeTWnZ2dnUVZ8hudnZ2d@giganews.com...
>>I do exacly what you say. But I have always the two errors :
>>
>> First :
>>
>> Certificate enrollment for Local system failed to enroll for a 
>> DomainController certificate with request ID N/A from 
>> APSHDCT02.audemarspiguet.local\audemarspiguet-APSHDCT02-CA (The RPC 
>> server is unavailable. 0x800706ba (WIN32: 1722)).
>>
>> Second :
>>
>> Automatic certificate enrollment for local system failed (0x800706ba) The 
>> RPC server is unavailable.
>>
>>
>>
>
> As I mentioned earlier, RPC errors such as this means there is a 
> communication block or DNS lookup issue. I assume DNS has the DCs listed, 
> so I think tehre is a block going on elsewhere.
>
> Ace
>
>
> 
0
Jorge
2/15/2010 8:34:06 PM
"Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
news:329CF86E-A5BE-4D40-9EF8-37687A2D1343@microsoft.com...
>I already saw this error, but the problem was related with cached 
>credentials on the requester... Can you check that please?
>


Good point. I forgot. :-)

Possibly run in a cmd prompt to check what credentials are stored:
Control keymgr.dll

However, I don't think it's in there. Maybe clear and restart IE?

Ace 


0
Ace
2/16/2010 12:42:48 AM
> However, I don't think it's in there. Maybe clear and restart IE?

In fact, I saw my user in the Credential manager! I remove it and restart 
IE.... without success! I always need to enter my credential!

To be honest, I think that when I do a dcpromo like another server something 
go wrong!

I'll try to depromate my dc, remove my dns server reboot it and do again a 
dcpromo.




"Ace Fekay [MVP-DS, MCT]" <aceman@mvps.RemoveThisPart.org> wrote in message 
news:ewho3DqrKHA.3944@TK2MSFTNGP06.phx.gbl...
> "Jorge Silva" <jorgesilva_pt@hotmail.com> wrote in message 
> news:329CF86E-A5BE-4D40-9EF8-37687A2D1343@microsoft.com...
>>I already saw this error, but the problem was related with cached 
>>credentials on the requester... Can you check that please?
>>
>
>
> Good point. I forgot. :-)
>
> Possibly run in a cmd prompt to check what credentials are stored:
> Control keymgr.dll
>
> However, I don't think it's in there. Maybe clear and restart IE?
>
> Ace
> 
0
Julien
2/17/2010 9:16:13 AM
"Julien Ithurbide" <jithurbide@removegmail.com> wrote in message 
news:e7ednU9Pyox9LubWnZ2dnUVZ7sudnZ2d@giganews.com...
>> However, I don't think it's in there. Maybe clear and restart IE?
>
> In fact, I saw my user in the Credential manager! I remove it and restart 
> IE.... without success! I always need to enter my credential!
>
> To be honest, I think that when I do a dcpromo like another server 
> something go wrong!
>
> I'll try to depromate my dc, remove my dns server reboot it and do again a 
> dcpromo.
>

You've been wrestling with this for over two weeks now. Have you possibly 
considered calling Microsoft PSS for assistance to get this resolved? A 
single call and they can resolve everything associated with this issue in 
one ticket. Just make sure you state everything in the ticket so they all 
get resolved.

Ace 


0
Ace
2/18/2010 6:43:13 PM
Reply:

Similar Artilces:

forged sender domain
Can anyone tell me if sending an email with a forged sender domain (for example the sender domain=the destination domain) actually violates any RFCs for internet mail? We are working with a service that sends legitimate mail to us but it appears "from" us. A recent policy addition by our ISP to block internet mail from our local domain has started blocking this real mail and we are left to solve the problem. Thanks I don't know about the RFCs but it will be flagged as suspect (possibly forged) if anyone is doing a reverse DNS lookup. Nue "William Gilles" <Wil...

outlook error #6
Every time i start outlook i get the following error: run- time error'-2147467259(80004005)':Automation error, unspecified error. I have run Repair outlook, which comes back with 'repair complete'. but when i restart it the error comes back. Can anyone help? ...

Error Msg: Mail not downloading
All of a sudden... a new problem has popped up! In one of my email accounts that goes into Outlook, I can see the sender and subject line -- but when I click on it to read it, I get an error message instructing me to "Mark for Download" -- ON EVERY EMAIL. This is a pain, as I have to mark every single email and the click on Send/Recieve. Any way to change my settings or something that stops this frustrating thing from happening??? "AMHEINS" <AMHEINS@discussions.microsoft.com> wrote in message news:AAB7775B-89E3-450A-905F-C97D4DC6BD3F@microsoft.com...

Cannot see child domain users in parent domain
Our domain has exchange servers in the parent domain and no exchange server in the child domain, when i create a mailbox for a user in the child domain the user can connect through OWA. The preview of the GAL on the server contains the user but on an outlook client i cannot find that user. the user cannot configure outlook because its name doesn't appear in the address list. help wanted please See if this helps re Outlook: http://support.microsoft.com/kb/297801/en-us Nue "Hidma" <Hidma@discussions.microsoft.com> wrote in message news:B0BF06DC-C9EC-483E-B219-FC3AB...

New Mail Error
In outlook, when I click on a new mail message, I the following error: "There is no disk in the drive.Please insert disk inot drive \Device\Harddisk2\DR4" This system used to be a dual boot machine. I ran Windows 2000 from the second hard drive. Since than I reinstalled Office on the "C:\" Any ideas? ...

Exch. Server in Child Domain
I've added both exchange servers in the replication tab of all the objects that I want to replicate... Should the folder just appear in the child domain users' public folder stack? Exchange Server 2003 on Windows Server 2003 Dan Klinge wrote: > But.....how do I get the Parent Domain's calendars to show up in the Child > Domain's users' outlook??? > > > > "Dan Klinge" <Dan.Klinge@NOSPAMJERKArborMed.com> wrote in message > news:%23pblelKOGHA.3728@tk2msftngp13.phx.gbl... >> Yes. I just setup replication of the two main public c...

multiple Domains under one domain or multiple forests under one forest
I have to research on below scenario. Asia regional countries are in separate forests/single domains Europe has forest and child domains. Europe is separate systems only connected via WAN only. Our proposal was make one forest under Europe as =91APAC=92, and then we will migrate regional counties under to APAC forest to appropriate Trees. Europe proposed that instead of creating APAC migrate all the Asia regional forest to one of Europe Domain. As example, migrate all Asia user accounts to Germany domain under Europe forest. for me putting every domain to one domain sounds messy f...

runtime error #2
Hi all, I have an mfc project a tray icon program but i can not run it from command prompt or at start up ,while it runs in usual ways, it gives a run time error which is below how can i solve this problem i need to run my program at startup : Runtime Error! Program c:\\.....alyb.exe This application has requested the Runtime to terminate it in an unusual way. Please contact the application's support team for more information. Thanks in advance Ismail Gunes There may be some Pointer Mistake! this type of error usually result from the BAD PTR OR DDX transfer for control which not e...

error opening outlook
I get the following error (below) whiles opening outlook. Use the repair tool but it did not help. HELP! Advise. Thanks. Outlook 2000 unable to display folder. the file C:\windows\local setings\application data\microsoft\outlook\mailbox.pst could not be accessed. access denied Were you ever able to open the mailbox? What happened just before you could no longer open it? --� Milly Staples [MVP - Outlook] Post all replies to the group to keep the discussion intact. Due to the Swen virus, all e-mails sent to my actual account will be deleted w/out reading. After searching google.gr...

script error in email
I receive an email periodically from a well known evangelist. If my cursor happens to hit on it in anyway, I get a "script error". I click yes or sometimes no, and my computer freezes up. I have to restart computer and without clicking on that email delete it by deleting emails before it. How can I put this email in my junk folder? Or, put it on my do not accept sender's website? And what might that script error that shows up say as per verbatim ? -- Peter Please Reply to Newsgroup for the benefit of others Requests for assistance by email can not and wil...

how to get a domain name
I sampled Outlook and obtained a license for it but how do I download it, open it or create it? Am I allowed a domain name? What are you talking about? Outlook is a PIM - nothing to do with = domains.=20 If you purchased Outlook, put in the CD, put in your PID when prompted, = then configure a mail account and start using Outlook. --=81 Milly Staples [MVP - Outlook] Post all replies to the group to keep the discussion intact. All unsolicited mail sent to my personal account will be deleted without reading. =20 After furious head scratching, AJ asked: | I sampled Outlook and obtained...

"Block auto-forward outside local domain" question
I know that Exchange can be configured to block auto-forward/redirection outside of it's own domain, and that this can be enabled for certain specified domains. But is there the possibility to add a "user exit" that can also enable this feature, based on some programtic criteria? For example, if Exchange user X has an external e-mail address my-x@somewhere.else.net, could a user exit allow X to auto-forward to their external account? If "yes", where is some information about this feature, and where would be a good place to configure the external e-mail address to mak...

Word error messages
List members: I work on an Intel Mac running OS 10.3.6 Regrettably I recently let a third-party software tech support person talk me into removing and then reinstalling MS Office 2008. I now regularly get two error messages with manual document saves and with Autorecover saves: 1) "Word cannot save or create this file. The disk may be full or write-protected. Try one of the following: Free more memory. Make sure that the disk you want to save the file on is not full, write- protected, or damaged." 2) "Word is unable to save the Autorecover file in th...

Intersite domain connection issues
I have been battling a strange problem that has been difficult to troubleshoot and difficult to explain or categorize. I'm hoping that someone may have encountered similar issues and have some ideas. Problem: About every 3 days or so, the exchange server in the branch office will experience some or all of the following problems: 1. Mail flow between the main office and this branch office will stop including outgoing and incoming Internet mail and mail. 2. From this server, I cannot connect to the administrative share (c$ or d$) of one or both of the domain controllers in the ...

upgrading to latest service pack of 9.0, file not found error
Good morning! I'm working with a customer who is upgrading to the latest service pack of GP 9.0 (they're not ready to move to 10). We installed 9.0, then installed the latest service pack of 9.0 and receive an error when launching GP Utilities: "File not found: D:\program files\microsoft Dynamics\GP\SQL\0\Upgrade.dll.UPGRADE_9__259.DRIVER_INI" I thought the fix was to create a file in that path, but doesn't seem to be working. Any other thoughts on how to fix this? -- --Peter peter, what version of gp 9 you installed, language and what version of service pack ...

rpchosts error
Hi, I am getting thie message when I try and send out mail. 553 sorry, that domain isn't in my list of allowed rcpthosts (#5.7.1) Can anyone advise me on how to sort it out? Thanks John Whose SMTP server are you using to send outbound mail through? Check with your ISP to make sure you're using the right server, and that if you need to use SMTP authentication to send mail, that you've configured it correctly. John Collins wrote: > Hi, > I am getting thie message when I try and send out mail. > > 553 sorry, that domain isn't in my list of allowed > rcpthosts...

domain to domain TLS
Hello, In Exchange 2003 is there an easy way to enforce TLS between my domain and one or two specific external domains? I know there are some overriding, more global settings but in the case of just a few domains is what I'm more curious about. If possible, what would I need to do on my end and what would the recipient domain require to be done? Thanks for any help! Scroll down to: Enable Transport Layer Security Encryption for a Specific Remote Domain in an Exchange Organization in the following KBA: http://support.microsoft.com/kb/829721 The remote domain would also need to co...

Changing Domain Name
We have mix W2k & W2k3 DCs and one E2k2 in a W2k3 member server. We now xxx.yyy.zzz.ca.us as our domain name. Now we have approval to change it to xxx.yyyyyyyy.gov format. What is the most efficient way to do it? We need to retain the old domain name with new domain name for a period of time to give our users enough time top inform their friends, other senders,etc. Thank you. -- JoeCL LACO-CAO In news:B8BD42A2-428A-4156-BE94-4CCAE8FF1E8E@microsoft.com, JoeCL <JoeCL@discussions.microsoft.com> typed: > We have mix W2k & W2k3 DCs and one E2k2 in a W2k3 member server. ...

Integration Manager error #15
I am getting an error message "ODBC Microsoft Access Driver" No current record. I have uninstalled then reinstalled IM to no avail. I have also downloaded SP4 for version 9.0 Any suggestions appreciated. Thanks, Russ Have you applied the latest Integration Manager 9.0 service pack? You can retrieve the latest IM service pack at: https://mbs.microsoft.com/customersource/support/downloads/servicepacks/integration+manager+9.0+downloads.htm?printpage=false Best regards, -- MG.- Mariano Gomez, MIS, MCP, PMP Maximum Global Business, LLC http://www.maximumglobalbusiness.com The Dyn...

error! Not a valid embedded object
this message appears when i try to open the equation editor ...

Joing old domain and new domain.
Hi, I have a Windows 2003 domain, seperate Exchange 2003 server which is quite flaky and I am in the process of designing and building a new Windows 2008 domain, Exchange 2010. The two will act in the begining as seperate domains but will have to interact for data transfer and more importantly moving Exchange mailboxes. What is the best way to achieve this with the idea of dissolving the 2003 domain eventually and running only on the 2008 one. Will I have to do an adprep? is a trust relationship the best way of doing it? These are the type of things I need to know. Any ...

ie 7 certificate error
Users who use owa to access their exchange 2k3 email account are getting a certificate error when using an ie7 browser. Is there something that can be done to correct this problem. they are able to get to it if they basically ignore the error. On Tue, 20 Feb 2007 15:42:34 -0500, "Mark" <rmwatrich@hotmail.com> wrote: >Users who use owa to access their exchange 2k3 email account are getting a >certificate error when using an ie7 browser. Is there something that can be >done to correct this problem. they are able to get to it if they basically >ignore th...

error 1931
when I install Outlook it gives me error 1931. This is just a recent problem. I've never gotten that error before. My operating system is Windows 2000 and I am installing Outlook 2000. I would also like to know if this error is related to another problem I am having in the "Outlook Today" view. I want to limit my Task list to just the "To Do" category and eliminate the "Messages" field since I don't use Outlook for Email but, the "Customize Outlook Today ..." button doesn't work and I can't figure out why. So I am trying to f...

Outlook 2003 Sending Errors
Just recently installed Outlook 2003, and now am unable to send/reply to emails. I am receiving the following errors: "Task 'mail.anglofinancial.com (1) - Sending' reported error (0x800CCC0B) : 'Unknown Error 0x800CCC0B' Task 'mail.anglofinancial.com (1) - Sending' reported error (0x8004210B) : 'The operation timed out waiting for a response from the sending (SMTP) server. If you continue to receive this message, contact your server administrator or Internet service provider (ISP).' If anyone has a solution to either error, I would greatly apprec...

Setup multiple domains
My boss owns multiple companies and each has a registerd domain name. Can a single SBS2003 exchange sever host all of the domains and allow traffic to all the different domains via pop? Point me in the right direction please. Thanks On Fri, 11 Feb 2005 09:27:04 -0800, "Jamie" <Jamie@discussions.microsoft.com> wrote: >My boss owns multiple companies and each has a registerd domain name. Can a >single SBS2003 exchange sever host all of the domains and allow traffic to >all the different domains via pop? > >Point me in the right direction please. > &g...