Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Computer autoenrollment failing

1,118 views
Skip to first unread message

Rich Raffenetti

unread,
Sep 4, 2007, 10:29:17 PM9/4/07
to
I started doing auto enrollment of computers in preparation for RDP/TLS.
I've been widening the coverage in our root domain which has 8000 user
accounts and probably 2000-3000 Windows computers, mostly XP.

Failures to issue certificates started accumulating in one area of our
network where there are ~200-300 computers. Not all of the computers in
that area fail to get certs but only some (~20). In another area of our
network with 1000 computers there are no failures. None of these are remote
and all are well connected. We have been scratching our heads for a long
while looking for inconsistencies between the computers getting certs and
those which are not. There is one newsgroup posting which seems the same
but the posted solution is not at all clearly explained.

We see the following event log message on the computer: "Automatic
certificate enrollment for local system failed to enroll for one Auto Enroll
Computer certificate (0x800725f2). DNS name does not exist." The message
on the Certificate Authority is the same.

We have pursued name inconsistencies and DNS differences as well as
reconnection to the domain. Does anyone know what is happening? Any ideas
would be appreciated?


Brian Komar

unread,
Sep 6, 2007, 12:41:33 AM9/6/07
to
This is simple. Your certificate template is populating the subject
alternate name with the DNS name of the computer (as stored in AD). This
name is not there, so the enrollment fails.
Update the computer accounts with a DNS name
Brian
"Rich Raffenetti" <rich@raffenetti_takethisout.com> wrote in message
news:usiViP27...@TK2MSFTNGP05.phx.gbl...

Rich Raffenetti

unread,
Sep 7, 2007, 11:13:28 PM9/7/07
to
Brian,
Thanks. I think you are telling me that the computer in AD does not
have a value for "host DNS name" and therefore does not pass it along to the
CA in the cert request. I believe we have been pursuing viewing the
attributes of the computer and have not noticed any absences.
However, we may have missed something. Is the "host DNS name" the right
attribute? I found the way to dump the failed Binary Request. It appears
to me that the DNS name is ok.
Sometimes our DNS contains a name different from the name the computer
has for its DNS name. I have found this to not be an issue because many of
the computers successfully acquiring certs have this disparity. I can
explain what I have been seeing more fully if need be.
Would it be useful to post the text dump of the binary request? I would
have to modify the names to obscure our organization name.
Rich Raffenetti

"Brian Komar" <brian...@nospam.identit.ca> wrote in message
news:OACxoCE8...@TK2MSFTNGP02.phx.gbl...

Brian Komar

unread,
Sep 8, 2007, 8:13:24 AM9/8/07
to
You can send it to me privately if you prefer
Brian

"Rich Raffenetti" <rich@raffenetti_takethisout.com> wrote in message

news:uBzJQWc8...@TK2MSFTNGP02.phx.gbl...

Rich Raffenetti

unread,
Sep 19, 2007, 10:03:21 PM9/19/07
to
Did you get my private email sent on 9/8?

"Brian Komar" <brian...@nospam.identit.ca> wrote in message

news:uZ2xIIh...@TK2MSFTNGP02.phx.gbl...

Brian Komar

unread,
Sep 20, 2007, 6:19:53 AM9/20/07
to
Sorry Rich, I have been on the road and have not had any cycles to look at
it. I will try and look at it during my flights this Friday

Brian
"Rich Raffenetti" <rich@raffenetti_takethisout.com> wrote in message
news:O4m2vmy%23HHA...@TK2MSFTNGP03.phx.gbl...

ronviloria

unread,
Oct 23, 2008, 2:14:41 PM10/23/08
to
Did you ever solve this problem. I am getting the same problem here.

ronviloria

unread,
Oct 23, 2008, 2:14:17 PM10/23/08
to

Paul Adare

unread,
Oct 23, 2008, 2:21:41 PM10/23/08
to
On Thu, 23 Oct 2008 11:14:17 -0700, Ron Viloria wrote:

> Did you ever solve this problem. I am getting the same problem here.

What is the exact problem? You've provided absolutely no context here.

--
Paul Adare
MVP - Identity Lifecycle Manager
http://www.identit.ca

ronviloria

unread,
Oct 24, 2008, 1:12:33 PM10/24/08
to
I see the following application event log message on my Certificate Authority for some computers:

Certificate Services denied request 6678 because DNS name does not exist. 0x800725f2 (WIN32: 9714). The request was for xxxx\xxxx$. Additional information: Denied by Policy Module.

Pretty much the same message in the failed requests of the Certificate Authority.

On other computers the Autoenrollment and request for certificate works fine.

I have removed/added the problem computer from the domain with no difference.

0 new messages