dambrosioj Posted April 15, 2015 Report post Posted April 15, 2015 We recently switched our SCCM environment over to HTTPS/PKI and everything has been working well. We were now wanting to include MAC's into our environment for some asset reporting. But we recently started to notice some errors on teh enrollment server. If we re-image a MAC, and re-enroll it to SCCM it creates another record and cert I believe. So what I was doing was deleting the old record which seemed like not a big deal till we started getting the errors below. Our MAC clients are not bound by to AD by the way either. Failed to revoke Certificate on CA: ******\DUQCA1 with serial number: 1*******00000000573F. Check CA permission.ICertAdmin2 RevokeCertificate failed: Access is denied. Do we need to make the user able to revoke the permissions also? I did not see this in the step by step from Microsoft. What would best practice be? Quote Share this post Link to post Share on other sites More sharing options...