Moved CA generating errors

T

Tim Ryter

Greetings:

I recently went through the process of moving a Certificate Authority
from one physical server to another. The basic process (since it was
running on a Domain Controller) was to backup the registry and CA on
server1(the old server). Demote and remove from service server1. I
then renamed a domain controller server2 to server1 and performed a
restore of the CA and imported the registry keys.

The major problem I encountered (which was not covered in the articles)
was on the original server1 the system_root was c:\winnt as it was an
upgrade machine. Server2 (which was renamed to server1) was an original
2003 install and thus its system_root was c:\windows. This caused many
problems but I was able to overcome it by installing the CA to C:\winnt
when I ran through the custom install.

The CA is up and running and issuing certificates to the enterprise,
however, I get the following Event ID 10 times:

Source: CertSvc
Category: None
Event ID: 66
Description:
Certificate Services could not publish a Delta CRL for key 0 to the
following location: c:\WINNT\system32\CertSrv\CertEnroll
\blahCAname+.crl. The directory name is invalid. 0x8007010b
(WIN32/HTTP:267).

After 10 of these I get this event:

Source: CertSvc
Category: None
Event ID: 67
Description:
Certificate Services made 10 attempts to publish a CRL and will stop
publishing attempts until the next CRL is generated.

I have followed the process of moving the CA back into the windows
directory by modifying the registry key HKLM\SYSTEM\CurrentControlSet
\Services\CertSvc\Configuration and changing all paths to C:\Windows,
however I cannot find where to change the CRL publish path from C:
\WINNT. This has to be something from the import of the old CA from the
original server1.

Any help would be much appreciated and TIA.

Tim

Articles used during my migration: 555012 and 298138
 
T

Tim Ryter

Greetings:

Actually, I fixed this (after writing out the question I had an idea) by
copying c:\windows\system32\CertSrv\CertEnroll\* to c:\WINNT\system32
\CertSrv\CertEnroll\ and restarting certificate services. Forcing the
Delta CRL to publish updated the files in this new directory with no errors
in the event log. I'd still like to know where that setting is (the path
for the CRL) so I can change it and put it back under c:\windows with
everything else.

TIA
 
G

Guest

On the Extensions tab of the Properties page of your CA server. There you can
set all the CRL paths.

Dave.
 
G

Guest

I know you expected this to be dead and done, but I had the same issues you
were having the same issues that you were having. Did you get a resolution?
If not I can possibly help. I think I have fixed my issue.
This was the CA errors since you moved from win2000 to win2003... etc.

-Mike
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top