Event ID/Source search
Keyword searchExample: Windows cannot unload your registry file
Event ID: 74 Source: CertSvc
Certificate Services could not publish a Base CRL for key <key> to the following location on server <location>. Insufficient access rights to perform the operation. <error code> (WIN32: <Win32 error code>). ldap: 0x32: 00002098: SecErr: DSID-03150646 problem 4003 (INSUFF_ACCESS_RIGHTS) data 0.
|English: Request a translation of the event description in plain English.|
This error occurs when the certificate services tries to publish a CRL or Delta CRL to the listed container. This can happen after a recovery of a crashed server, or a hardware replacement. When you restore the certificate service configuration and database along with the server certificate, you must make sure that the server name does not change for the certificate to be valid. This error happens because the security for the CDP container is still set with the SID of the old server, but there is no entry for the new server. So, before rebuilding the server, some cleaning has to be done in the AD:
- remove the account of the old or crashed server.
- clean up the DNS if applicable
- in AD Sites and Services, locate the following container: Services\Public Key Services\CDP\<server name>\<server name>. For each entry, in the Properties\Security Tab, remove the entry for the old SID and add an entry for the computer account of the new server, giving it Full Control permissions.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated