Integrating ADDS/ADCS/NDES
Hello, nice to meet you.
My name is Alex and i'm new in the group. I'm not an expert AD Administrator, but if is there any way that i can help you all, just ask. =)
Well... i'm trying to solve a puzzle regarding the ADDS (2008 R2 Std) and ADCS (2008 R2 Enterprise) using the NDES (Network Device
Enrollment Service) to integrate it with a Cisco ASA emulator on GNS3. The following picture represents my network lab:
windows7-cliente01.corp.local
-> Is a client computer of domain corp.local
adds.corp.local
--> Is a Active Directory Domain Services (DC) for the network.
adcs.corp.local
--> Is a Active Directory Certificate Services;
--> It has a Network Device Enrollment Service installed;
My problem with this scenario is that i can't get the NDES to work properly. I've installed the service without problems during
the wizard using the following data:
--> Username: CORP\Administrador
On the next page, i've leave the defaults and continued pressing "Next" and then "Finish"
When i open the NDES page, i get a 500 Internal Error from IIS. On "Event Viewer", i got two errors for the NDES and the following
ID:
ID 8 - The Network Device Enrollment Service cannot retrieve information about the Certification Authority.
ID 2 - The Network Device Enrollment Service cannot be started.
I copied the codes and i came to this page to translate the code and see a sugestion for the problem... but the resolution page was
blank for these two codes - http://technet.microsoft.com/en-us/library/ff955644(v=ws.10).aspx
I've tried to uninstall the NDES and reinstall again, but no success. I didn't got errors when removing and installing the NDES. Is
there any way i can track down the problem, or raise the debug? Thanks again for the help. =)
July 31st, 2012 5:12pm
Hi Alex,
Thanks for posting in Microsoft TechNet forums.
Please check the article below to see if it can be helpful to you:
AD CS: Troubleshooting Network Device Enrollment Service
http://technet.microsoft.com/en-us/library/ff955644(v=ws.10).aspx
In the meantime, we can also try IIS forum if the error is related to IIS:
http://forums.iis.net/
Regards
Kevin
Free Windows Admin Tool Kit Click here and download it now
August 2nd, 2012 12:06am
Hi Alex,
Thanks for posting in Microsoft TechNet forums.
Please check the article below to see if it can be helpful to you:
AD CS: Troubleshooting Network Device Enrollment Service
http://technet.microsoft.com/en-us/library/ff955644(v=ws.10).aspx
In the meantime, we can also try IIS forum if the error is related to IIS:
http://forums.iis.net/
Regards
Kevin
August 2nd, 2012 12:09am


