Domain Controller and Certificate Authority

G

Guest

I recently created an image of my PDC and restored it onto a new server,
since then there have been some issues. 1. I have the event id 1010
Automatic enrollment against the certification authority failed and I have a
user trying to connect to the PDC through port 636 (ssl) I even installed a
new CA and it is trying to automatically enroll and failing. 2. Every 5
minutes I get the events 1202 Security policies are propagated with warning.
0xd and event 1000 The Group Policy client-side extension Security was passed
flags (17) and returned a failure status code of (13). I found an article on
this and did exactly that and Im still getting the errors. Here is the
article http://support.microsoft.com/kb/256000/en-us I really would
appreciate any help on this, I am certain these errors are from restoring
the image of the PDC onto a new machine with different hardware. Thank you.
 
P

Paul Bergson

You don't want to create an image of a DC, because the image contains the AD
database and depending on how long it took before it was restored (And
whether or not its mirror image is online) you can lose replication events,
since replication partners in the domain (And Forest) might not ever be
notified that this is an older version of its AD database. This is really
bad don't mirror a dc.

When a DC comes online after beng off it needs to let its fellow dc's off
its status (USN Rollback has occured), since you did an image restore it
doesn't think anything bad has happened and there is a gap when changes that
were made won't be updated.

For more detailed info see:
http://support.microsoft.com/?id=885875
 
G

Guest

Paul, thanks for the reply. I actually found that I needed to reinstall SP4
to make the 1202 and 1000 event ids go away. SP4 adds a security setting in
the domain controller policy and since it was missing it could not apply the
policy correctly. However I still have 2 issues. 1. event Id 1010 automatic
enrollment against my CA failed. 2. I do not have permissions to open the
domain controller policy acess denied domain does not exist. However with a
command line command I can get into the domain controller policy, its like
it is not looking at the right domain name. I appreciate any more replies.
Thanks.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top