Home All Groups Group Topic Archive Search About

certificate of type DomainController has failed

Author
27 Jan 2006 1:52 PM
Mr. Backup
Recently I have started to receive the following error.



Automatic enrollment against the certification authority exchange for a
certificate of type DomainController has failed.  (0x800706ba) The RPC
server is unavailable.

..   Another certification authority will be tried.



Does anyone happen to know what this pertains to and measures to take to
fix?

Author
27 Jan 2006 2:00 PM
Paul Bergson
The one time I have seen this a domain controller was behind a firewall and
couldn't get to the root Certificate Authority.  Not sure what your topology
looks like.

--

Paul Bergson  MCT, MCSE, MCSA, CNE, CNA, CCA

This posting is provided "AS IS" with no warranties, and confers no rights.

Show quoteHide quote
"Mr. Backup" <bac***@yahoo.com> wrote in message
news:eBLTmh0IGHA.1424@TK2MSFTNGP12.phx.gbl...
> Recently I have started to receive the following error.
>
>
>
> Automatic enrollment against the certification authority exchange for a
> certificate of type DomainController has failed.  (0x800706ba) The RPC
> server is unavailable.
>
> .   Another certification authority will be tried.
>
>
>
> Does anyone happen to know what this pertains to and measures to take to
> fix?
>
>
>
Author
28 Jan 2006 4:36 AM
Ace Fekay [MVP]
In news:%23YG$Fo0IGHA.2460@TK2MSFTNGP10.phx.gbl,
Paul Bergson <pbergson@allete_nospam.com> stated, which I commented on
below:
> The one time I have seen this a domain controller was behind a
> firewall and couldn't get to the root Certificate Authority.  Not
> sure what your topology looks like.

Or just to add, I've seen it where the online root (Root CA or subordinate)
hasn't yet replicated the config context to all DCs in an infrastructure, or
in an offline/subordinate scenario, the CDP or AIA hasn't been published to
AD yet.

As you said, difficult to tell not knowing the scenario.

Ace
Author
28 Jan 2006 4:39 AM
Ace Fekay [MVP]
In news:eBLTmh0IGHA.1424@TK2MSFTNGP12.phx.gbl,
Mr. Backup <bac***@yahoo.com> stated, which I commented on below:
> Recently I have started to receive the following error.
>
> Automatic enrollment against the certification authority exchange for
> a certificate of type DomainController has failed.  (0x800706ba) The
> RPC server is unavailable.
>
> .   Another certification authority will be tried.
>
> Does anyone happen to know what this pertains to and measures to take
> to fix?

I would suggest to post this question to the
microsoft.public.security.crypto newsgroup for better specific assistance.

Ace
Author
30 Jan 2006 1:36 PM
Paul Bergson
That is why I couldn't find the newsgroup.  I was looking for PKI not
crypto.

--

Paul Bergson  MCT, MCSE, MCSA, CNE, CNA, CCA

This posting is provided "AS IS" with no warranties, and confers no rights.

"Ace Fekay [MVP]"
<PleaseSubstituteMyActualFirstName&LastNameH***@hotmail.com> wrote in
Show quoteHide quote
message news:eOaxdT8IGHA.648@TK2MSFTNGP14.phx.gbl...
> In news:eBLTmh0IGHA.1424@TK2MSFTNGP12.phx.gbl,
> Mr. Backup <bac***@yahoo.com> stated, which I commented on below:
>> Recently I have started to receive the following error.
>>
>> Automatic enrollment against the certification authority exchange for
>> a certificate of type DomainController has failed.  (0x800706ba) The
>> RPC server is unavailable.
>>
>> .   Another certification authority will be tried.
>>
>> Does anyone happen to know what this pertains to and measures to take
>> to fix?
>
> I would suggest to post this question to the
> microsoft.public.security.crypto newsgroup for better specific assistance.
>
> Ace
>
>
>
>
Author
31 Jan 2006 12:19 AM
Ace Fekay [MVP]
In news:OvZFxIaJGHA.140@TK2MSFTNGP12.phx.gbl,
Paul Bergson <pbergson@allete_nospam.com> stated, which I commented on
below:
> That is why I couldn't find the newsgroup.  I was looking for PKI not
> crypto.

I had that prob too! I searched for 'security' in the newsgroup list and
found the crypto!

:-)

Ace