ADLDS SSL - fatal error occured when attempting to access the SSL server credential private key
hi all,
i having trouble installation of internal domain pki cert on adlds. have used pki other server ssl know part valid.
upon import of pfx computer personal certificates, have verified okay via indication have private key corresponds certificate. checking certification path, leads root pki , well.
i restart adlds , try connect ssl , no go. server event logs indicate schannel error:
a fatal error occured when attempting access ssl server credential private key. error code returned cryptographic module 0x8009030d. internal error state 10001.
following ms adlds instructions ssl states add network service rights machinekeys file. doesnt type of rights assume read & execute. unsure file change attributes apply of them.
restarting adlds instance doesnt solve problem. tried launching certificates mmc , instead of computer, used service , picked adlds instance. under personal imported pfx, restarted adlds, still no luck.
i doing file level audting on machinekeys folder , see security failures via network service. gives?
hi,
based on process monitor, private key file trying access 4d0e9759c3974f256ec070ade1ad673f_***-*** in c:\programdata\microsoft\crypto\keys.
2:23:13.1867291 am lsass.exe 480 createfile c:\programdata\microsoft\crypto\keys\4d0e9759c3974f256ec070ade1ad673f_***-*** access denied desired access: generic read, disposition: open, options: sequential access, synchronous io non-alert, non-directory file, attributes: n/a, sharemode: read, allocationsize: n/a, impersonating: nt authority\network service
it seems that cng being used in environment , therefore folder path different. please grant read permission network service on file , check result.
thanks.
this posting provided "as is" no warranties, , confers no rights. please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.
Windows Server > Directory Services
Comments
Post a Comment