Discussion:
help! domain controller won't renew certificate
(too old to reply)
r***@gmail.com
2007-02-05 21:50:12 UTC
Permalink
A year ago, I set up a wireless network using PEAP authentication in
accordance with the instructions in Microsoft's document "Securing
Wireless LANS with PEAP and passwords". Everything worked fine for a
year. Now, user attempts to connect are all being rejected. The only
message I've seen that was at all helpful in the event log, along with
endless messages telling me logons were rejected was one suggesting
there is a kerberos problem somewhere, and I should check my public
key infrastructure. I fired up the certification authority MMC snap
in, and lo and behold, the certificate for the domain controller that
hosts IAS just expired. (It's the same server that hosts the
certification authority). I can't figure out how to get it to renew.
I tried rebooting the server, that didn't help.

Some app note I found on MS's web site suggests there may be a group
policy preventing autoenrollment, but it doesn't say specifically how
to fix it.

One other thing I discovered is if, in the clients, you configure the
wireless network not to validate your server certificate, you're in.

BTW, the expiration period for the certificate I generated in the
process of following the WLAN setup instructions is 25 years, I don't
recall ever generating a certificate that expired in a year.

Anyone have any clue how to get this domain controller to renew its
cert, so clients can connect without disabling 1/2 the authentication?
r***@gmail.com
2007-02-06 14:27:00 UTC
Permalink
I resolved this one on my own, so here's how, in case anyone runs into
the same problem.

First, start certification authority in administrative tools on the
server hosting the certificate server. Go to certificate templates,
right click, click new, certificate template to issue. Click domain
controller, OK, so the certificate server can issue domain controller
certificates.

Close that, open the command prompt at the WLAN tools directory (these
tools come with the "Securing wireless LANS witth PEAP and
passwords" document). Type ComputerCerts.msc. This opens a snap in
in the microsoft management console. I imagine it's possible to get
to this snap in another way, this is just the easiest I found.

The snapin will open in Personal Certificates, where you will see an
expired Domain Controller certificate. Right click on it, click all
tasks, request certificate with same key. (You can't renew an expired
certificate).

After this succeeds, reboot the server (I tried restarting all sorts
of services, like IAS, Cryptographic services, Kerberos, nothing
worked until I rebooted the server).

Continue reading on narkive:
Search results for 'help! domain controller won't renew certificate' (Questions and Answers)
6
replies
who win the match for jonh and randy ortan?
started 2007-08-19 06:00:21 UTC
rugby league
Loading...