Public Key Policies Propagation Prohibited?


everything in gpo (user settings, account policies, password policies, security options) pulled down except of public key policies.

 

what cause this?

 

rsop shows should enabled when check secpol on client machine, of pkps still in "not configured" state.  i have 2 autoenrollment certificate templates set up, replication working swimmingly (otherwise, i'd wager none of rest of gpo work). 

 

i had issue before locked down dcs much, limited access administrators which blocked pulling of gpos.  allows administrators , users.  there similar issue here wherein user rights assignment policy plays pulling of public key policies?

 

thanks.

hi,

 

as far know, result of domain public key policies not displayed in local security policy console, different local policies. if rsop.msc shows policy enable, believe policy has been applied computer. can confirm checking registry entry hkey_local_machine\software\poilcies\microsoft\cryptography\autoenrollment\aepoilcy.

 

for more information, please refer following article:

 

initialize autoenrollmentpolicy.autoenrollmentoptions

http://msdn.microsoft.com/en-us/library/ee380511(prot.10).aspx

 

if find autoenrollment not work, please check if autoenroll permission configured correctly certificate template. meanwhile, please check if there related events logged.

 

for more information autoenrollment, please refer following article:

 

how autoenrollment works

http://technet.microsoft.com/en-us/library/cc787781(ws.10).aspx


this posting provided "as is" no warranties, , confers no rights.


Windows Server  >  Directory Services



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group