Windows Server 2008R2 cannot renew certificates in windows server 2016

伟 韦 6 Reputation points
2022-07-21T15:45:49.02+00:00

Currently I have a set of Windows Server 2016 AD and ca servers, but there are also many old Windows Server 2008R2 and windwos Server 2016. All intercommunication in the whole environment

But now my windows server 2008 R2 and windows server 2012 cannot renew the certificate to windows server 2016, and the error is reported as RPC service unavailable, but WIndows server 2016 does not have this problem. I tried using Portquery and found that the network communication was all fine, then I tried using get-wmiobject it showed access denied. I followed some links to try to fix DCOM and change some permissions,but it nothing effect。 and I think it's caused by tls1.2, but I tried to change windows server 2008R2 and windows server 2012, but it didn't change
thanks for any help

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,890 questions
{count} vote

1 answer

Sort by: Most helpful
  1. Geoff McKenzie 315 Reputation points
    2025-01-23T05:24:54.23+00:00

    I have two thoughts on this.

    1. less likely unless there are firewalls involved - Newer versions of windows use different ranges of ephemeral ports for RPC.
    2. more likely - Differences between security posture of older versions of OS to newer

    Eitherway, we may need more detailed infromation on warnings and errors in the event log during the enrolment attempts. Also details about are these auto enrol/renew or manually triggered. Any changes to templates, etc.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.