Forum Discussion

christian31's avatar
christian31
Brass Contributor
Nov 17, 2020

Cross Forest certificate Enrollment problem

Hi,

 

I have a two forest setup with two way trust(ForestA and ForestB). in ForestB there is a child domain(ForestBchild)

I have successfully setup Cross forest enrollment in both forest. CA is on ForestA and forestB don't have CA.

I tested issuing workstation authentication template with security settings domain computers auto enroll, enroll and read for all forest and child domain.

In ForestB(parent domain) computers are deployed by the certificate but in the child some were failed error "Denied by Policy Module 0x8007202b, The requester's Active Directory object is not in the current forest. Cross forest enrollment is not enabled"

 

What must be the problem with my setup?

2 Replies

  • teppner's avatar
    teppner
    Copper Contributor

    Hello christian31,

     

    I came across this thread on TechNet, maybe it will help you :

    https://social.technet.microsoft.com/Forums/ie/en-US/59393068-76ff-46df-874e-ae19057ea223/server-2012-r2-quotcross-forest-enrollment-is-not-enabledquot?forum=winserversecurity

     

    Thierry

    • christian31's avatar
      christian31
      Brass Contributor
      Hi!

      I have seen this link and knowing that my setup is working on other computers. I don't know whats wrong since some computers was successsfully deployed by the CA and some were not. with that error message in the failed request in the CA server in forestA

Resources