If you have updated from a Windows 2000 domain, you may have to change the group type into a domain local group.
For more information about this topic, click the following article number to view the article in the Microsoft Knowledge Base:
281271�
Certification Authority configuration to publish certificates in Active Directory of trusted domain
Certificate servers publish certificates to user objects in the directory service. They are allowed to do this because they are in the Cert Publishers group, which has write access to the 'userCertificate' attribute on the user object.
The problem occurs when a certificate server in one domain tries to issue a certificate to a user in another domain.
WORKAROUND
To work around this issue, use one of the following methods:
- Manually add the CA computer to the Cert Publishers group on the child domain. This process cannot be performed during Setup because the child domain may not yet exist when the CA is configured.
NOTE: This only works in a Windows Server 2003-based environment, not a Windows 2000 environment.
- Use the Delegation Wizard to manually add the root domain's Cert Publisher group to every user object in the child domain.