Autoenroll fails with: "DNS name does not exist"


"active directory certificate services denied request 7054 because dns name not exist. 0x800725f2 (win32: 9714).  the request domain\computer$.  additional information: denied policy module"

i appriciate here. have searched forums found not exact match. have been issuing computer certificates year our 2k8r2 enterprise ca successfully. far know thing matches behaviour have migrated our win7 clients child domain in primary domain. child domain had full trust , dns suffix on clients correct after migration, had got certificates renewed matching correct domain when migration occured. problem happend couple of days ago, when renew process started. 

template settings: 



 further info: 

manual request not work either.

i can request templates common name subject. (wireless tls not work me way..) 

if @ computer object dnshostname correct

we have added third dc running server 2012.

audit log:

"certificate services denied certificate request.

request id: 7118
requester:<domain\computer$>
attributes:
cdc:<dc.domain.com>
rmd:<computer>

ccm:<computer>

dis"apple-tab-span" style="white-space:pre;"> -2147015182
ski: 4f e5 d6 93 8c 1e 70 17 84 38 cb 52 1x e3 d6 2c e5 3x f0 0d
subject: "

-- domain computers have enroll , autoenroll rights.

i havent seen strange in our dns servers --- 

i hope confuses bit less. looking forward answers. 

i got expensive help microsoft support regarding rather complex problem.

here final words support technician matheesha weerasinghe did great job:

"problem: client computers fail autoenroll certificate. error generated @ ca side @ failure : "dns name not exist"

cause: seems reason have issue because of following gpo.

“always wait network @ startup , add dns”

this gpo configured “primary dns suffix” group policy in “computer configuration\administrative templates\network\dns client” branch. however, have enabled , specified blank value suffix. should put full value like domain.com instead.

as value empty, group policy client configures software\policies\microsoft\system\dnsclient\nv primarydnssuffix empty value. in turn causes primarydnssuffix registry value defined in same place blank value @ os bootup.

when os getcomputernameex (http://msdn.microsoft.com/en-us/library/windows/desktop/ms724301(v=vs.85).aspx) call full dns name, ends doing short value because of gpo configuration. sends short value in cert request , fails policy requirements @ ca "dns name not exist"."

i suspected of our network gpo's beginning, 1 not under attention since did not know setting enabled. technician had make deep tracing of process traffic both on client , server side highlight fault. took him 20 + hours resolve. maybe have been resolved quicker if error message had been more informative.

now have 1 more thing do, clean-up 500 000+ failed requests database. http://secadmins.com/index.php/delete-failed-request-from-the-certificate-services-database/



Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group