Event Id | 29 |
Source | HRA |
Description | Microsoft Health Registration Authority denied the certificate request with the correlation-id %1 at %2 for (principal: %3). Either no certificate servers are configured or the certificate servers that are configured are not available. Contact the Health Registration Authority for more information |
Event Information | According to Microsoft : Diagnose : This error might be caused by one of the following conditions:
CA server(s) are not correctly configured to issue health certificates with HRA Resolution : Configure AD CS This error condition indicates that HRA contacted a CA server, but that the CA server is not configured to issue NAP health certificates. To perform this procedure, you must be a member of the Administrators group, or you must have been delegated the appropriate authority. To configure CA servers to issue health certificates, HRA must be granted permission to request and issue health certificates on behalf of NAP clients. If the CA server is an enterprise CA, you must also publish a certificate template with application policy extensions for client authentication and system health authentication. The CA must also be able to issue certificates automatically, without administrator approval. If your HRA and NAP CA are running on the same computer, Network Service must be granted permissions to issue, manage, and request certificates. If your HRA and NAP CA are running on different computers, these permissions must be granted to the computer name for your HRA server. HRA should be granted permission to manage the CA server so that it can remove expired records from the CA database.
Next, the new certificate template must be made available for enrollment requests. Cause : Active Directory Certificate Services (AD CS) is not responding to HRA Resolution : Install or enable AD CS This error condition indicates that HRA was unable to contact the CA server, possibly due to a network issue. Check the names and availability of CA servers configured in HRA and confirm that Active Directory Certificate Services (AD CS) is running on each CA server. To perform this procedure, you must be a member of the Administrators group, or you must have been delegated the appropriate authority.
To start AD CS:
Health Registration Authority (HRA) does not have a valid Certification Authority (CA) server configuration Resolution : Configure CA servers in HRA This error condition indicates that HRA has a CA server configuration that is not valid. Check the names of CA servers configured in HRA, and make sure that HRA is configured with the correct CA server properties and certificate settings. To perform this procedure, you must be a member of the Administrators group, or you must have been delegated the appropriate authority. Add or remove a CA To add a CA to HRA:
Configure CA settings in HRA To configure certification authority wait time, certificate validity period, operational mode, policyOID settings, and template settings:
|
Reference Links | Event ID 29 from HRA |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.