Updating the CA configuration in Active Directory

  1. Log on to the Domain Controller with enterprise permissions

  2. Click the Start button, open Run and type dssite.msc and then click OK

  3. Select the top node in the left pane

  4. In the View menu, select Show services node

  5. In the left pane, select the Services and Public Key Services, and then select AIA

image-20251110-105751.png

Figure 109: Active Directory Sites and Services window

  1. In the middle pane, select the CA name as it shows in the Certification Authority MMC Snap-in

  2. In the Action menu, select Properties

  1. Click Security

  1. Click Add

  2. Select Object Types then select Computers, and then click OK

  3. Type the computer name(s) of the other cluster node(s) as the object name and click OK

  4. Make sure that the computer accounts of all cluster nodes have Full Control permissions

  5. Click OK

  6. All cluster nodes also have to be permitted on the Enrollment Services container

  7. In the left pane, select Enrollment Services.

  8. In the middle pane, select the Certificate Authority name

  9. In the Action menu, select Properties. Select the Security tab and click Add....

  10. Select Object Types, select Computers and click OK

19. Type the computer name(s) of the all-cluster node(s) as the object name

  1. Make sure that the computer accounts of all cluster nodes have Full Control permissions

  2. Click OK

  3. In the left pane, select KRA

  4. In the middle pane, select the Certificate Authority name

  5. In the Action menu, select Properties then select the Security tab and click Add

  6. Select Object Types, select Computers and then click OK

  7. Type the computer name of all cluster node as object name and click OK

  8. Make sure that the computer accounts of all cluster nodes have Full Control permissions

  9. Click OK