Wednesday, August 24, 2011

AD Certificate Services MP throws EventID 1400: The permissions on this certification authority do not allow the current user to enroll for certificates. 0x80094011

Bumped into this issue. The AD Certificate Services MP was imported but the Views for the Certificate Authorities stayed empty.

So it was time to investigate. On the MS and RMS nothing strange was shown. The OpsMgr log of the CA showed this error however: CARoleDiscovery.vbs : Unable to determine the Common Name of the CA hosted by xxxxxxxxxxxxxx. Cause: CCertRequest: :GetCAProperty: The permissions on this certification authority do not allow the current user to enroll for certificates. 0x80094011
image

So the script couldn’t run.

After having adjusted the account (SYSTEM) to have enough permissions, all Views present in the MP were populated.
image

No comments: