Group security permissions for certificate template not working

12,599

You need to reboot the servers after changing their Security group membership.

Share:
12,599

Related videos on Youtube

JMP
Author by

JMP

Updated on September 18, 2022

Comments

  • JMP
    JMP over 1 year

    I have a certificate template published on my domain-joined Server 2016 Enterprise CA - I'm trying to set up certificate autoenrollment for our internal webservers.

    When the template has read/enroll/autoenroll permissions granted directly to a Computer Account, the computer in question can autoenroll.

    When read/enroll/autoenroll permissions are assigned to the built-in group "Domain Computers", (any) domain joined computers can also autoenroll.

    When security permissions are assigned to a global security group containing computer accounts as members, these computers cannot autoenroll. When using the "request new certificate" from the computer's certificate manager - I can select the template in question, but it fails with the error "The permissions on the certificate template do not allow the current user to enroll for this type of certificate". I can see failures on the CA when doing a GPUpdate on a computer which should have permission to enrol.

    I suspect I'm missing something stupid - any suggestions on things to check?

    • Admin
      Admin over 6 years
      Did you reboot the servers after adding them to this Security group? If not, you'll need to.
    • Admin
      Admin over 6 years
      Herp, that was it. My suspicions were correct. Thanks :)
    • Admin
      Admin over 6 years
      Glad to help...
  • joeqwerty
    joeqwerty over 6 years
    True, but a reboot is usually the quickest, most efficient way. I wanted to keep my answer as simple and as straightforward as possible. Thanks for the assist nonetheless.
  • JMP
    JMP over 6 years
    it's definitely easier, yes :)