Windows Certificate server web enrollment authentication error

Royal D Costa 241 Reputation points
2023-06-21T05:53:44.6233333+00:00

I installed certificate authority on windows server 2012 R2, configured web enrollment feature as well. when I browse the Web enrollment URL with IP address everything works fine. but when I browse the same with DNS name is asks for authentication and when I provide domain admin credentials it throws below error. could someone help me to resolve this.

User's image

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,229 questions
0 comments No comments
{count} votes

Accepted answer
  1. Limitless Technology 44,406 Reputation points
    2023-06-21T12:15:19.89+00:00

    Hello,

    Thank you for your question and for reaching out with your question today.

    HTTP Error 401 indicates that the request requires user authentication. In your case, when accessing the Web enrollment URL with the DNS name, it prompts for authentication, and even after providing domain admin credentials, it throws the error.

    Here are a few steps you can take to troubleshoot and resolve this issue:

    1. Verify DNS resolution: Ensure that the DNS name you are using is correctly resolving to the IP address of the server hosting the web enrollment site. You can do this by running a ping or nslookup command from the machine where you are accessing the URL.
    2. Check IIS authentication settings: Open the Internet Information Services (IIS) Manager on the Windows Server 2012 R2 machine. Navigate to the website hosting the web enrollment URL and check the authentication settings. Make sure that "Anonymous Authentication" is enabled and other authentication methods (such as Windows Authentication) are disabled for the virtual directory or application.
    3. Verify permissions: Ensure that the user account used for anonymous authentication (usually the IUSR account) has appropriate permissions to access the necessary files and folders for the web enrollment site.
    4. Restart IIS: Try restarting the IIS service on the server. Sometimes, a simple restart can resolve temporary authentication issues.
    5. Check event logs: Examine the Event Viewer logs on the Windows Server 2012 R2 machine for any related errors or warnings. Look for entries in the Security or Application logs that might provide more details about the authentication failure.
    6. Verify SSL certificate bindings: Confirm that the SSL certificate used by the web enrollment site is properly bound to the DNS name you are using to access it. Ensure that the certificate is trusted and valid.
    7. Test from a different machine: Try accessing the web enrollment URL with the DNS name from a different machine to determine if the issue is specific to the client machine or if it persists across multiple systems.

    By following these steps, you should be able to diagnose and resolve the HTTP Error 401 you are encountering when accessing the Web enrollment URL with the DNS name.

    I used AI provided by ChatGPT to formulate part of this response. I have verified that the information is accurate before sharing it with you.

    If the reply was helpful, please don’t forget to upvote or accept as answer.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Sebastian Cerazy 316 Reputation points
    2024-10-08T06:50:47.1166667+00:00

    Lots of words and not really any solution

    i have the exact same on 1 machine (Chrome under W10 22H2 worked fine, upgraded in-place to W11 24H2 and same Chrome no longer allows login to certsrv )

    Authentication requests pops up all the time, does not accept user/password, on cancel gives 401

    Same user on another machine (Server 2022) can login just fine

    Anybody has any more ideas?

    Seb

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.