7.0

Table Of Contents
Table 59. Enrollment Server Connectivity
Status Text Description
This domain <Domain Name> does
not exist on the <FQDN>
enrollment server.
The True SSO connector has been configured to use this enrollment server for this
domain, but the enrollment server has not yet been configured to connect to this
domain. If the state remains for longer than one minute, you need to check the state
of the broker currently responsible for refreshing the enrollment configuration.
The <FQDN> enrollment server's
connection to the domain <Domain
Name> is still being established.
The enrollment server has not been able to connect to a domain controller in this
domain. If this state remains for longer than a minute, you might have to verify
that name resolution from the enrollment server to the domain is correct, and that
there is network connectivity between the enrollment server and the domain.
The <FQDN> enrollment server's
connection to the domain <Domain
Name> is stopping or in a
problematic state.
The enrollment server has connected to a domain controller in the domain, but it
has not been able to read the PKI information from the domain controller. If this
happens, then there is likely a problem with the actual domain controller. This
issue can also happen if DNS is not configured correctly. Check the log file on the
enrollment server to see what domain controller the enrollment server is trying to
use, and verify that the domain controller is fully operational.
The <FQDN> enrollment server has
not yet read the enrollment
properties from a domain
controller.
This state is transitional, and is only displayed during startup of the enrollment
server, or when a new domain has been added to the environment. This state
usually lasts less than one minute. If this state lasts longer than a minute, either the
network is extremely slow, or there is an issue causing difficulties accessing the
domain controller.
The <FQDN> enrollment server has
read the enrollment properties at
least once, but has not been able to
reach a domain controller for some
time.
As long as the enrollment server reads the PKI configuration from a domain
controller, it keeps polling for changes once every two minutes. This status will be
set if the domain controller (DC) has been unreachable for a short period of time.
Typically this inability to contact the DC might mean the enrollment server cannot
detect any changes in PKI configuration. As long the certificate servers can still
access a domain controller, certificates can still be issued.
The <FQDN> enrollment server has
read the enrollment properties at
least once but either has not been
able to reach a domain controller
for an extended time or another
issue exists.
If the enrollment server has not been able to reach the domain controller for an
extended period, then this state is displayed. The enrollment server will then try to
discover an alternative domain controller for this domain. If a certificate server can
still access a domain controller, then certificates can still be issued, but if this state
remains for more than one minute, it means the enrollment server has lost access to
all domain controllers for the domain, and it is likely that certificates can no longer
be issued.
Table 510. Enrollment Certificate Status
Status Text Description
A valid enrollment certificate for
this domain's <domain name>
forest is not installed on the
<FQDN> enrollment server, or it
may have expired
No enrollment certificate for this domain has been installed, or the certificate is
invalid or has expired. The enrollment certificate must be issued by an enterprise
CA that is trusted by the forest this domain is a member of. Verify that you have
completed the steps in the View Administration document, which describes how to
install the enrollment certificate on the enrollment server. You can also open the
MMC, certificate management snap-in, opening the local computer store. Open the
Personal certificate container and verify that the certificate is installed, and that it
is valid. You can also open the enrollment server log file. The enrollment server
will log additional information about the state of any certificate it located.
Chapter 5 Authenticating Users Without Requiring Credentials
VMware, Inc. 87