Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

Certificate Services Event ID 90 & 130 & 102 - Can't issue certs from 2008 R2 CA

$
0
0

Certificate Service was running fine on my 2008 R2 server(also a DC) until a few days ago when I started logging these 2 System Errors:

EVENT ID 90
509.4018.3260678234: Active Directory Certificate Services detected an exception at address 0x00000000FF5633D6.  Flags = 0x00000000.  The exception is The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s. 0xc0000005 (-1073741819).


EVENT ID 130
Active Directory Certificate Services could not create a certificate revocation list. The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s. 0xc0000005 (-1073741819).  This may cause applications that need to check the revocation status of certificates issued by this CA to fail. You can recreate the certificate revocation list manually by running the following command: "certutil -CRL". If the problem persists, restart Certificate Services.


I've restarted the service and restarted the server itself based on the following information:

http://technet.microsoft.com/en-us/library/cc726385(v=ws.10).aspx

http://technet.microsoft.com/en-us/library/dd299845(WS.10).aspx

 I also found an EVENT ID 102 (Active Directory Certificate Services could not create cross certificate (3-2) to certify its own root certificates.  The Certificate Policies extension is inconsistent.  Requested by DOMAIN\DC02$.  The certification authority's certificate contains invalid data. 0x80094005 (-2146877435).

I found an article about checking the extension but it's not very clear. I don't want to make a change without a clear explanation. 

http://technet.microsoft.com/en-us/library/cc774561(v=ws.10).aspx


Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>