Windows Server 2003
1825761 Members
2172 Online
109687 Solutions
New Discussion

Re: Trying to install Enterprise Root CA

 
Tommy_6
Regular Advisor

Trying to install Enterprise Root CA

I am trying to install an Enterprise Root CA on my 2003 domain, but Enterprise Root CA and Enterprise Subordinate Root CA are grayed out. I am installing on a domain controller and I am using a top administrative account. I originally had a Enterprise Root CA on this domain, but I had to decommission it to upgrade the server it was residing on. I followed all the steps to properly decommission it, including checking in CN=Public Key Services,CN=Services,CN=Configuration,DC=your,DC=rootdomain,DC=com. But now I cannot install Enterprise Root CA. Any ideas? Thanks in advance.
4 REPLIES 4
Ivan Ferreira
Honored Contributor

Re: Trying to install Enterprise Root CA

Try using this procedure (if you haven't done yet)

http://support.microsoft.com/kb/555151/en-us
Por que hacerlo dificil si es posible hacerlo facil? - Why do it the hard way, when you can do it the easy way?
Tommy_6
Regular Advisor

Re: Trying to install Enterprise Root CA

I ran through this procedure, but still not luck. I did not notice that when I run certutil -dcinfo deleteBad, one of the domain controllers still has an Enterprise Root Certificate. I think this is causing my problems. Does anyone know the syntax to delete this cert? I tried "dsstore" and "certutil" but I am not having any success. Thanks in advance.
Tommy_6
Regular Advisor

Re: Trying to install Enterprise Root CA

Ok, I figured out how to delete the cert. I rebooted the server, but I still do not have the ability to install the Enterprise Root CA. It is still grayed out.
Tommy_6
Regular Advisor

Re: Trying to install Enterprise Root CA

We ended up opening a support call to Microsoft. They sent us an LDIF file to restore the CN=Public Key Services,CN=Services,CN=Configuration,DC=your,DC=rootdomain,DC=com that was deleted. Now everthing works.