Certificate Authority (CA) untrusted - KDC_ERROR_CLIENT_NOT_TRUSTED

bob dee 1 Reputation point
2022-05-20T07:56:39.873+00:00

I have 2 CAs configured, 1 on the DC (KDC) and 1 on an arbitrary AD-connected server. I installed the secondary CA on a different server as I couldn't find a way to have 2 CAs running off the same server. If this is wrong please let me know.

DC issued certs work fine. However, when trying to authenticate with certs issued by the arbitrary server, I get the following error:
Kerberos SessionError: KDC_ERROR_CLIENT_NOT_TRUSTED(Reserved for PKINIT)

Under adsi.msc and dsa.msc on the DC, I see no entries for:
CN=Certification Authorities,CN=Public Key Services,CN=Services,CN=Configuration,DC=xxx,DC=xxx

'certutil' output from the DC shows both CAs, but it appears like I'm missing a step to trust certs from CAs issued from servers other than the KDC/DC.

Appreciate any assistance here.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,898 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. rr-4098 1,196 Reputation points
    2022-05-22T08:22:50.513+00:00

    Is the DC the enterprise root CA, and the other server the subordinate? Also be careful on installing CA services on a DC. You may set yourself up for issues later on as listed in the following article:

    https://www.securew2.com/blog/should-i-install-ad-cs-on-domain-controller

    0 comments No comments