<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Firewall Rules for Active Directory Certificate Services</title><link>http://blogs.technet.com/b/pki/archive/2010/06/25/firewall-roles-for-active-directory-certificate-services.aspx</link><description>Below is a list of ports that need to be opened on Active Directory Certificate Services servers to enable HTTP and DCOM based enrollment 
 The information was developed by Microsoft Consultant Services during one of our customer engagements 
 
 </description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Firewall Rules for Active Directory Certificate Services</title><link>http://blogs.technet.com/b/pki/archive/2010/06/25/firewall-roles-for-active-directory-certificate-services.aspx#3529005</link><pubDate>Fri, 26 Oct 2012 14:14:42 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3529005</guid><dc:creator>Marc Puverel</dc:creator><description>&lt;p&gt;Following the article at the following URL: &lt;a rel="nofollow" target="_new" href="http://blogs.technet.com/b/askds/archive/2007/11/06/how-to-troubleshoot-certificate-enrollment-in-the-mmc-certificate-snap-in.aspx"&gt;blogs.technet.com/.../how-to-troubleshoot-certificate-enrollment-in-the-mmc-certificate-snap-in.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;It appears that port 135 - TCP has to be open for RPC EPM. Basically for mmc and auto-enrollment scenarios.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3529005" width="1" height="1"&gt;</description></item><item><title>re: Firewall Rules for Active Directory Certificate Services</title><link>http://blogs.technet.com/b/pki/archive/2010/06/25/firewall-roles-for-active-directory-certificate-services.aspx#3485723</link><pubDate>Fri, 09 Mar 2012 16:10:13 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3485723</guid><dc:creator>cadlau</dc:creator><description>&lt;p&gt;I still get these errors on the Domain Controllers running 2008 R2 to a 2003 Enterprise CA. I have TCP 135 (RPC) open already, but I highly suspect it maybe the &amp;quot;Random port above port 1023&amp;quot; requirement as noted in the table. I hate to have to open up all ports above this. Any other way to make this a specific port? I can map the cahost computer from domain controller as \\cahost\ and I will see CertEnroll Share.&lt;/p&gt;
&lt;p&gt;Event ID: 13&lt;/p&gt;
&lt;p&gt;User: SYSTEM&lt;/p&gt;
&lt;p&gt;Source: CertificateServicesClient-CertEnroll&lt;/p&gt;
&lt;p&gt;Certificate enrollment for Local system failed to enroll for a DomainController certificate with request ID N/A from cahostname.my-domain.com\cahostname (The RPC server is unavailable. 0x800706ba (WIN32: 1722)).&lt;/p&gt;
&lt;p&gt;Event ID: 6&lt;/p&gt;
&lt;p&gt;User: N/A&lt;/p&gt;
&lt;p&gt;Source: CertificateServicesClient-AutoEnrollment&lt;/p&gt;
&lt;p&gt;Automatic certificate enrollment for local system failed (0x800706ba) The RPC server is unavailable.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3485723" width="1" height="1"&gt;</description></item><item><title>re: Firewall Rules for Active Directory Certificate Services</title><link>http://blogs.technet.com/b/pki/archive/2010/06/25/firewall-roles-for-active-directory-certificate-services.aspx#3477850</link><pubDate>Mon, 30 Jan 2012 14:51:25 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3477850</guid><dc:creator>Sycane</dc:creator><description>&lt;p&gt;Has anyone got any relevant information regarding port usage when certificates are requested via MMC and the Certificates snap-in?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3477850" width="1" height="1"&gt;</description></item><item><title>re: Firewall Rules for Active Directory Certificate Services</title><link>http://blogs.technet.com/b/pki/archive/2010/06/25/firewall-roles-for-active-directory-certificate-services.aspx#3475343</link><pubDate>Fri, 13 Jan 2012 15:48:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3475343</guid><dc:creator>Walter Chomak</dc:creator><description>&lt;p&gt;I can submit and retrieve certs just fine with https. I have also successfully automated the process with certutil. It works perfect on a regular workgroup server - but on the same network. What must be done to do so from a workgroup machine that is outisde the network? 443 access only. THANKS!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3475343" width="1" height="1"&gt;</description></item><item><title>re: Firewall Rules for Active Directory Certificate Services</title><link>http://blogs.technet.com/b/pki/archive/2010/06/25/firewall-roles-for-active-directory-certificate-services.aspx#3471928</link><pubDate>Mon, 19 Dec 2011 15:10:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3471928</guid><dc:creator>Sycane</dc:creator><description>&lt;p&gt;The table data seems to only provide information for Web Enrollment, what ports are required between a requesting host and an Enterprise CA?&lt;/p&gt;
&lt;p&gt;Not wanting to presume anything (but without having tested) I suspect this would be TCP/135 + high ports.&lt;/p&gt;
&lt;p&gt;Some clarity from a point of authority would be appreciated.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3471928" width="1" height="1"&gt;</description></item><item><title>re: Firewall Rules for Active Directory Certificate Services</title><link>http://blogs.technet.com/b/pki/archive/2010/06/25/firewall-roles-for-active-directory-certificate-services.aspx#3444592</link><pubDate>Mon, 01 Aug 2011 23:50:59 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3444592</guid><dc:creator>Kurt L Hudson MSFT</dc:creator><description>&lt;p&gt;I just removed port 440 based on the result of an internal conversation about that port not being needed.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3444592" width="1" height="1"&gt;</description></item><item><title>re: Firewall Rules for Active Directory Certificate Services</title><link>http://blogs.technet.com/b/pki/archive/2010/06/25/firewall-roles-for-active-directory-certificate-services.aspx#3434675</link><pubDate>Thu, 09 Jun 2011 23:45:26 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3434675</guid><dc:creator>Markus</dc:creator><description>&lt;p&gt;When did kerberos start using tcp/440?&lt;/p&gt;
&lt;p&gt;My understandin was it used tcp/88, upd/88 and tcp/464.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3434675" width="1" height="1"&gt;</description></item><item><title>re: Firewall Rules for Active Directory Certificate Services</title><link>http://blogs.technet.com/b/pki/archive/2010/06/25/firewall-roles-for-active-directory-certificate-services.aspx#3375439</link><pubDate>Thu, 16 Dec 2010 09:31:09 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3375439</guid><dc:creator>Lylian L</dc:creator><description>&lt;p&gt;Thanks a lot for your article. Not found out There !!!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3375439" width="1" height="1"&gt;</description></item><item><title>re: Firewall Rules for Active Directory Certificate Services</title><link>http://blogs.technet.com/b/pki/archive/2010/06/25/firewall-roles-for-active-directory-certificate-services.aspx#3356501</link><pubDate>Mon, 20 Sep 2010 10:17:15 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3356501</guid><dc:creator>Tom Aafloen</dc:creator><description>&lt;p&gt;Hello!&lt;/p&gt;
&lt;p&gt;Doesn&amp;#39;t RPC TCP 135 (RPC Endpoint Mapper) also have to be open? How else can clients find out what random port above 1023 is being used at any given time?&lt;/p&gt;
&lt;p&gt;It is possible to set the random port being used by the CA server to a fixed value (with DCOM, Static Endpoint), is this supported by Microsoft?&lt;/p&gt;
&lt;p&gt;I love this blog, keep it updated!&lt;/p&gt;
&lt;p&gt;Sincerly Yours&lt;/p&gt;
&lt;p&gt;Tom Aafloen, Sweden&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3356501" width="1" height="1"&gt;</description></item><item><title>re: Firewall Roles for Active Directory Certificate Services</title><link>http://blogs.technet.com/b/pki/archive/2010/06/25/firewall-roles-for-active-directory-certificate-services.aspx#3340734</link><pubDate>Mon, 28 Jun 2010 01:33:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3340734</guid><dc:creator>Siki</dc:creator><description>&lt;p&gt;Just a minor correction. Should DCOM/RPC state: &amp;quot;Random port above port 1023&amp;quot; rather than &amp;quot;1024&amp;quot;. I believe RPC uses &amp;gt;=1024 (includes 1024).&lt;/p&gt;
&lt;p&gt;Otherwise, good summary.&lt;/p&gt;
&lt;p&gt;Siki&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3340734" width="1" height="1"&gt;</description></item></channel></rss>