249 questions with Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI) tags

Sort by: Updated
2 answers

Old KDC cert still used

2016 DC the old cert is still being presented for authentication. The new KDC cert is installed on all 2016 servers however only a few servers are using it. I did check the enumeration on the DCs that are affected and the older cert is listed as #1,…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-09-28T14:53:36.12+00:00
Mel Perez 0 Reputation points
answered 2026-09-28T15:32:28.2033333+00:00
Mel Perez 0 Reputation points
1 answer One of the answers was accepted by the question author.

Windows Web Services communication failure saying 503 Service Unavailable

Our microservices hosted on IIS/Windows Servers are failing to communicate with each other, returning 503 Service Unavailable errors. This appears to be caused by an expired Windows Root/Intermediate CA certificate breaking the HTTPS/mTLS mutual…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-09-25T23:36:56.14+00:00
Malzaar 40 Reputation points
commented 2026-09-28T02:05:36.39+00:00
Malzaar 40 Reputation points
1 answer

how to fix error encountered while signing in my pc

hi, in my pc showing every time whenver dsc singing that time showing as " Error encountered while signing: SET The Windows CryptographicService Provider reported an error: ASN1 bad tag value met. Error Code: 2148086027 " please resolve it

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-09-27T01:54:39.73+00:00
DEVA M 0 Reputation points
answered 2026-09-27T16:13:16.9666667+00:00
Allan Solomon Mejia 10,225 Reputation points
3 answers

How do I remove the DeltaCRL location from an intermediate certificate

Our Intermediate CA shows that a there is a DeltaCRL like. It references a list that is not copied over to the webserver host the crl because we have blocked smb file sharing. So my questions are: Should I remove the DeltaCRL is should it be kept? …

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-09-23T21:30:45.73+00:00
Daniel Kaliel 1,441 Reputation points
commented 2026-09-25T12:45:04.8+00:00
James Gamble 170 Reputation points
1 answer

CVE-2026-54121 (Certighost) July 2026 update - what happens after install, any disadvantages, and pre-install checks?

We're planning to install the July 14, 2026 security update for CVE-2026-54121 (Certighost) on our Enterprise CA servers, which currently have EDITF_ENABLECHASECLIENTDC enabled. What will happen if we install this update? Are there any disadvantages of…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-09-14T11:44:37.3333333+00:00
Rajesh Alda 125 Reputation points
answered 2026-09-14T12:17:49.9366667+00:00
Harry Phan 33,400 Reputation points Independent Advisor
1 answer

Renew Certificate

I push dot1x certificate from intune and the certificate itself generated by our internal microsoft ca server. If the certificate will be expired on 2 months then how we can renew the certificate to make sure the dot1.x is not interuppted.

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-09-07T13:10:23.72+00:00
Handian Sudianto 7,471 Reputation points
commented 2026-09-12T07:59:04.8533333+00:00
Handian Sudianto 7,471 Reputation points
2 answers

Windows service 2025 AD CS - I am not able to create PQ CA based on ML-DSA

Hello, I'd like to create a new CA based on PQ algorithm ML-DSA on the Windows Service 2025 server. I am using the version which you can see on the screen below. According to my information it should be sufficient enough to use the ML-DSA algorithm.…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-08-31T12:19:28.7266667+00:00
Tadeáš Janků 0 Reputation points
commented 2026-09-03T15:36:15.06+00:00
Tadeáš Janků 0 Reputation points
2 answers

searching lost certificate of mta

searching lost certificate of mta Searching lost certificate of mta is there any file that save in database microsoft for my MTA certificate

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-08-29T17:39:21.6566667+00:00
faizal zuli 0 Reputation points
answered 2026-08-31T05:42:27.9366667+00:00
Daphne Huynh (WICLOUD CORPORATION) 1,570 Reputation points Microsoft External Staff Moderator
2 answers

Enterprise root CA certificate is nearing expiration. I need help on how to renew without breaking existing trust chains

Our root CA certificate is set to expire 9/8/26. I need help on how to renew without breaking existing trust chains

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-08-27T17:12:24.61+00:00
Budhram, Kevon-admin 0 Reputation points
answered 2026-08-28T00:41:39.5733333+00:00
Hoang Le 6,275 Reputation points Independent Advisor
0 answers

[ARTICLE] Check secureboot CA 2023 certificates are installed on Windows 11

Open powershell application, type following commads one by one ([System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI kek).bytes) -match ‘Microsoft Corporation KEK 2K CA 2023’) ([System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes)…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-03-11T16:43:41.01+00:00
VARADHARAJAN K 9,726 Reputation points Volunteer Moderator
commented 2026-08-27T11:14:32.8466667+00:00
Alex Gopkal 0 Reputation points
5 answers

certificate Auto enrollment is not working

Dears, I’m facing an issue on multiple devices, but not all of them, where AD certificates are not being automatically enrolled from the CA server. I have already tried gpupdate /force along with several other troubleshooting commands, but the issue is…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-08-23T19:27:51.25+00:00
SAIF WAEL 0 Reputation points
commented 2026-08-26T00:13:55.47+00:00
SAIF WAEL 0 Reputation points
2 answers

Generate Device Cerificate

Cuurenly we deploy device certificate from intune where intune will contact CA server on onprem and intune push the deployment to the endpoint. Now for testing purpose i want to deploy the certificate to non intune device, so how we can generate the…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-08-12T14:46:59.0866667+00:00
Handian Sudianto 7,471 Reputation points
commented 2026-08-14T14:49:08.8+00:00
Allan Solomon Mejia 10,225 Reputation points
1 answer One of the answers was accepted by the question author.

Certificate Error - Subject Alternative Name

Dear, We are receiving the following message/error!!!. It is a Default Web Site in a IIS. In different forums, it is indicated that the error is because the URL names to be resolved in the certificate do not match. How do we verify this on the…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-07-31T19:15:32.95+00:00
Lucas Peñaloza 671 Reputation points
accepted 2026-08-12T14:35:05.72+00:00
Lucas Peñaloza 671 Reputation points
1 answer

How to fix AD CS auto-enrollment stalls and Event ID 64 on domain clients, and how to debug proxy endpoints and clear stale RPC keys?

How to fix AD CS auto-enrollment stalls and Event ID 64 on domain clients, and how to debug proxy endpoints and clear stale RPC keys?

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-08-10T05:49:30.5866667+00:00
Isabella Brown 20 Reputation points
edited an answer 2026-08-11T01:16:36.1633333+00:00
Allan Solomon Mejia 10,225 Reputation points
1 answer

Public Key Infrastructure (PKI) CA Private Key HSM Communication LossRoot CA Stops Publishing CRLs After HSM Network Outage

Hi everyone, We have an offline enterprise Root CA whose private key is protected by a network-attached HSM. During a scheduled CRL publication window, the HSM network interface briefly went down while our network team was performing…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-08-10T09:01:52.91+00:00
Mikko Hämäläinen 20 Reputation points
edited an answer 2026-08-11T01:11:56.5+00:00
Allan Solomon Mejia 10,225 Reputation points
1 answer One of the answers was accepted by the question author.

PKCS Device Certificate

Is UPN can work if the PKCS set to device certificate?

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-08-09T23:59:05.2666667+00:00
Handian Sudianto 7,471 Reputation points
accepted 2026-08-10T23:58:30.02+00:00
Handian Sudianto 7,471 Reputation points
1 answer

Adding new OCSP online responder server to already running array controller.

I'm in a process of adding a newly build server running on windows 25 as a array member directly from array controller but repeatdely getting error RPC server not available. Want to know the ports and protocal involved in adding a newly build OCSP server…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-08-06T04:27:59.4133333+00:00
Aditya Singh 0 Reputation points
answered 2026-08-10T01:32:50.2133333+00:00
Domic Vo 34,165 Reputation points Independent Advisor
1 answer

Windows Server 2025 AD CS certsrv.msc displays random Unicode characters in empty rows after Refresh

Environment: Windows Server 2025 (24H2) updated July 2026 ISO image Active Directory Certificate Services installed Certification Authority MMC snap-in (certsrv.msc) Issue: After adding a certificate request (Pending Requests / Issued Certificates…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-08-07T19:24:10.44+00:00
Sebastian 0 Reputation points
commented 2026-08-09T15:59:23.9166667+00:00
Sebastian 0 Reputation points
1 answer

Using RSA Token for RDP instead of Windows password

I am currently trying to configure our rdp sessions to prompt for RSA instead of a windows password, I tried registry edits and local GPO, is there something I'm missing, I assumed this would be a simple setup

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-08-06T15:25:18.6666667+00:00
Johnny 0 Reputation points
answered 2026-08-07T01:23:59.74+00:00
Allan Solomon Mejia 10,225 Reputation points
1 answer One of the answers was accepted by the question author.

Safe PKI Issuing CA OS Migration (2019 to 2022): Backup/Restore Strategy Without Deleting Old CA First

Hi Everyone, I am planning an in-place upgrade/migration of an Active Directory-Integrated Enterprise Issuing CA running on Windows Server 2019 to a new Windows Server 2022 virtual machine. Key Requirements & Constraints: Quick Rollback: I want…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2026-07-28T07:16:47.07+00:00
Sreeram Raju 40 Reputation points
commented 2026-08-04T00:16:06.7266667+00:00
Steven Nguyen (WICLOUD CORPORATION) 415 Reputation points Microsoft External Staff Moderator