Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

Automatic certificate enrollment for local system failed (0x800706ba) The RPC server is unavailable

$
0
0

I'm getting the auto-enrollment error above not because of a configuration error but for the reason that the Root CA machine was taken out of service and disposed of! So the unable to contact is a true error. The machine no longer exists!

I have checked the expiration date of the certificate using certmgr in the AD servers (Three Windows 2008 server cluster) and I have found different expiring dates for the same certificate as described below. 

Trusted Root Certification Authorities > CONTOSO-CA (exp 17/05/2018)

Intermediate Certification Authorities > CONTOSO-CA (exp 17/05/2018)

Active directory User Object > CONTOSO-CA (exp 17/05/2014)

We currently have an AD cluster conformed by three Windows server 2008 and no currently Certificate Authority role installed on any of them. 

I also have seen using certmgr that all machines in the company have the certificate CONTOSO-CA in the following way:

Trusted Root Certification Authorities > CONTOSO-CA (exp 17/05/2018)

Intermediate Certification Authorities > CONTOSO-CA (exp 17/05/2018)

Active directory User Object > Not present

My question is, can I safely decommission the certificate? What will be the impact of this certificate (Active directory user object) expiring?

Thanks in advance


Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>