Home All Groups Group Topic Archive Search About

Invalid Domain Controller Certificate

Author
23 Mar 2005 8:15 AM
HJ
Dear all,

I have installed Windows Server 2003 and configured it for Smart Card Logon.
That is, the server has a Domain Controller role; and had Certificate
Services installed. The server is the Enterprise Root CA.

Everything worked for two days.

After two days, I found that the Smart Card Logon does not work. There are
two events in the System Event Log:

Event Type: Error
Event Source: Kerberos
Event Category: None
Event ID: 9
Date: 3/17/2005
Time: 5:28:42 PM
User: N/A
Computer: SYSIM
Description:
The client has failed to validate the Domain Controller certificate for
sysim.imdom.local. The following error was returned from the certificate
validation process: The revocation function was unable to check revocation
because the revocation server was offline.


Event Type: Warning
Event Source: KDC
Event Category: None
Event ID: 20
Date: 3/17/2005
Time: 5:27:26 PM
User: N/A
Computer: SYSIM
Description:
The currently selected KDC certificate was once valid, but now is invalid
and no suitable replacement was found. Smartcard logon may not function
correctly if this problem is not remedied. Have the system administrator
check on the state of the domain's public key infrastructure.

Any help is appreciated. Thanks.

Author
23 Mar 2005 3:48 PM
Todd J Heron
"HJ" <H*@discussions.microsoft.com> wrote in message
news:FD338F04-D6FF-4F8C-A9DC-3F19552DF40C@microsoft.com...
>"I have installed Windows Server 2003 and configured it for Smart Card
>Logon. That is, the server has a Domain Controller role; and had
>Certificate
Services installed. The server is the Enterprise Root CA. Everything worked
for two days.  After two days, I found that the Smart Card Logon does not
work. There are two events in the System Event Log"  <snipped>

Was this domain previously renamed?

--
Todd J Heron, MCSE
Windows Server 2003/2000/NT; CCA
----------------------------------------------------------------------------
This posting is provided "as is" with no warranties and confers no rights.
Are all your drivers up to date? click for free checkup

Author
24 Mar 2005 12:51 AM
HJ
>
> Was this domain previously renamed?
>
No, this is a fresh installation.
Author
16 May 2005 12:11 PM
Svatos, Jan
I have similar problem.
If domain WAS renamed, what it means?

Show quoteHide quote
"Todd J Heron" wrote:

> "HJ" <H*@discussions.microsoft.com> wrote in message
> news:FD338F04-D6FF-4F8C-A9DC-3F19552DF40C@microsoft.com...
> >"I have installed Windows Server 2003 and configured it for Smart Card
> >Logon. That is, the server has a Domain Controller role; and had
> >Certificate
> Services installed. The server is the Enterprise Root CA. Everything worked
> for two days.  After two days, I found that the Smart Card Logon does not
> work. There are two events in the System Event Log"  <snipped>
>
> Was this domain previously renamed?
>
> --
> Todd J Heron, MCSE
> Windows Server 2003/2000/NT; CCA
> ----------------------------------------------------------------------------
> This posting is provided "as is" with no warranties and confers no rights.
>
>

Bookmark and Share