In Windows Server 2003, the "Enterprise root CA" option is not available when you try to install the Certificate Services component

Symptoms

In Microsoft Windows Server 2003, the Enterprise root CA option is not available. This issue occurs when you try to install the Certificate Services component and set up a certification authority.

Cause

This issue can occur if the Public Key Services container does not exist in the Active Directory directory service. For example, this issue can occur if the ADSIEdit tool (Adsiedit.msc) was used to delete the Public Key Services container.

Resolution

To resolve this issue, re-create the Public Key Services container, as follows.

Note These steps require the Adsiedit.msc tool. The Adsiedit.msc tool is included when you install Windows Server 2003 Support Tools.
  1. Click Start, click Run, type Adsiedit.msc, and then click OK.
  2. Expand Configuration, and then expand CN=Configuration,dc= Domain Component,dc= Domain Component
  3. Right-click CN=Services, point to New, and then click Object.
  4. Click container, click Next, type Public Key Services, click Next, and then click Finish.
  5. Right-click Public Key Services, point to New, and then click Object.
  6. Click container, click Next, type AIA, click Next, and then click Finish.
  7. Right-click Public Key Services, point to New, and then click Object.
  8. Click container, click Next, type CDP, click Next, and then click Finish.
  9. Right-click Public Key Services, point to New, and then click Object.
  10. Click container, click Next, type Certificate Templates, click Next, and then click Finish.
  11. Right-click Public Key Services, point to New, and then click Object.
  12. Click container, click Next, type Certification Authorities, click Next, and then click Finish.
  13. Right-click Public Key Services, point to New, and then click Object.
  14. Click container, click Next, type Enrollment Services, click Next, and then click Finish.
  15. Right-click Public Key Services, point to New, and then click Object.
  16. Click container, click Next, type KRA, click Next, and then click Finish.
  17. Right-click Public Key Services, point to New, and then click Object.
  18. Click msPKI-Enterprise-OID, click Next, type OID, click Next, and then click Finish.
  19. Try to install the Certificate Services component again.
Proprietà

ID articolo: 938613 - Ultima revisione: 21 giu 2014 - Revisione: 1

Feedback