您的位置:首页 > 其它

密钥发行中心(KDC)找不到相应的证书用于智能卡登录,或者无法验证 KDC 证书。如果不解决该问题,智能卡登录可能不会正常工作。若要更正该问题,请使用 certutil.exe 验证现有的 KDC 证书或注册新的 KDC 证书。

2010-05-20 10:00 2096 查看
密钥发行中心(KDC)找不到相应的证书用于智能卡登录,或者无法验证 KDC 证书。如果不解决该问题,智能卡登录可能不会正常工作。若要更正该问题,请使用 certutil.exe 验证现有的 KDC 证书或注册新的 KDC 证书。

参考windows 联机帮助解决。不过是英文的,

Delete the domain controller certificate that is no longer valid

To delete the domain controller certificate that is no longer valid:

On the domain controller in which the issue is occurring, click
Start
, and then click Run
.

Type mmc.exe
, and then press ENTER.

If the User Account Control
dialog box appears, confirm
that the action it displays is what you want, and then click
Continue
.

Click File
, and then click Add/Remove
Snap-in

.

Click Certificates
, and then click
Add
.

Click Computer account
, click Next
, and
then click Finish
.

Click OK
to open the Certificates snap-in.

Expand Certificates (Local computer)
, expand
Personal
, and then click Certificates
.

Right-click the old domain controller certificate, and then click
Delete
.

Click Yes
, confirming that you want to delete the
certificate.

After the certificate is deleted, follow the procedure in the "Request a new
certificate" section.

Request a new certificate

To request a new certificate:

Expand Certificates (Local
computer)

, right-click Personal
, and then click
Request New Certificate
.

Complete the appropriate information in the Certificate Enrollment Wizard
for a domain controller certificate.

Close the Certificates snap-in.

Verify

To perform this procedure, you must be a member of the Domain

Admins
group, or you must have been delegated the
appropriate authority.

To verify that the Kerberos Key Distribution Center (KDC) certificate is
available and working properly:

Log on to a computer within your domain.

Click Start
, point to All Programs
, click
Accessories
, right-click Command Prompt
, and
then click Run as administrator
.

If the User Account Control
dialog box appears, confirm
that the action it displays is what you want, and then click
Continue
.

At the command prompt, type certutil -dcinfo verify
, and
then press ENTER.

If you receive a successful verification, the Kerberos KDC certificate is
installed and operating correctly.

Related Management Information

KDC
Certificate Availability
内容来自用户分享和网络整理,不保证内容的准确性,如有侵权内容,可联系管理员处理 点击这里给我发消息
标签: 
相关文章推荐