Hi,
Hoping someone can assist.
Environment: Windows Active Directory 2003 R2
Subordinate Enterprise Certificate Authority running on Windows Server 2008 R2 - Enterprise Edition
I have a custom V2 template, created by duplicating the Code Signing Template.
When I set the Issuance Requirements to nothing, the user can request a certificate and it is issued automatically with no issues.
When I set the Issuance Requirements to CA Certificate Manager Approval, the user can request a certificate, and it appears in Pending Approval BUT
when a Cert Admin Issues the certificate it fails and generates a Application Log Entry
"Active Directory Certificate Services denied request xx because Configuration information could not be read from the domain controller, either because the machine is unavailable, or access has been denied. 0x80070547 (WIN32: 1351). The request was for DOMAIN\User. Additional information: Denied by Policy Module Resubmitted by DOMAIN\CertAdministrator
"
I have tried all the altering the "Certificate Service DCOM Access" group members.
James