I am logged into a Domain Controller running Server 2008 R2 and the domain/forest functional level is server to 2008. When implementing KCD for Windows Clients to request certificates via the proxy to ADCS, I get an 'Access Denied'.
I am using ADUC on the domain controller, going to properties on the CEP/CES Server object....selecting the Delegation tab...adding as a KCD to the SUBCA server object for HOST and RPCSS services...when hitting 'Apply' I get Access Denied. I have full rights both objects, tried as a Domain Admin and Enterprise Admin....hitting a wall.