Microsoft KB Archive/239452

= "Access Denied" When Requesting Certificate Through Web Access =

Article ID: 239452

Article Last Modified on 3/1/2007

-

APPLIES TO


 * Microsoft Windows 2000 Server
 * Microsoft Windows 2000 Advanced Server
 * Microsoft Windows 2000 Datacenter Server

-



This article was previously published under Q239452



SYMPTOMS
It is possible to request a certificate from a Microsoft Certificate Authority with a Web browser.

The request is usually issued to the Certificate Authority (CA) in the form of "http:// /certsrv" (where  can be the FQDN or IP address of the Certificate Authority).

When you do so, the following message may be received:

Event Type: Warning

Event Source: CertSvc

Event Category: None

Event ID: 53

Date: Date

Time: Time

User: N/A

Computer: ComputerCA

Description: Certificate Services denied request % because Access is denied. 0x80070005 (WIN32: 5). The request was for (Unknown Subject). Additional information: Denied by Policy Module.

If you use the Certificate Management console to request the certificate, you may receive the following error message when you start the Microsoft Management Console (MMC) snap-in:

Cannot find a Certificate Authority to Process this Request.



CAUSE
This behavior can occur for the following reasons:
 * The Certificate Authority service is not running.
 * You do not have Read and Enroll permission for the template of the certificate that you are requesting.



RESOLUTION
To resolve this issue:
 * Start the Certificate Services service.
 * Grant Read and Enroll access for the template to the appropriate user or group by using the Sites and Services snap-in. You can set the access rights on the Security tab by expanding the following items: Services, Public Key Services, Certificate Templates. Note that the Show Services Node check box must be selected on the View menu to see the Services tab.



STATUS
Microsoft has confirmed that this is a problem in the Microsoft products that are listed at the beginning of this article.



MORE INFORMATION
When a CA is installed, domain users and domain administrators are granted Enroll access, but authenticated users are granted Read access by default. This causes problems with child and parent domains, depending on where the CA is installed. This also causes some templates not to appear in the list of available templates in a Web browser.

Keywords: kberrmsg kbprb KB239452

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.