243 questions with Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI) tags
Windows service 2025 AD CS - I am not able to create PQ CA based on ML-DSA
Hello, I'd like to create a new CA based on PQ algorithm ML-DSA on the Windows Service 2025 server. I am using the version which you can see on the screen below. According to my information it should be sufficient enough to use the ML-DSA algorithm.…
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
searching lost certificate of mta
searching lost certificate of mta Searching lost certificate of mta is there any file that save in database microsoft for my MTA certificate
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
Enterprise root CA certificate is nearing expiration. I need help on how to renew without breaking existing trust chains
Our root CA certificate is set to expire 9/8/26. I need help on how to renew without breaking existing trust chains
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
[ARTICLE] Check secureboot CA 2023 certificates are installed on Windows 11
Open powershell application, type following commads one by one ([System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI kek).bytes) -match ‘Microsoft Corporation KEK 2K CA 2023’) ([System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes)…
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
certificate Auto enrollment is not working
Dears, I’m facing an issue on multiple devices, but not all of them, where AD certificates are not being automatically enrolled from the CA server. I have already tried gpupdate /force along with several other troubleshooting commands, but the issue is…
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
Generate Device Cerificate
Cuurenly we deploy device certificate from intune where intune will contact CA server on onprem and intune push the deployment to the endpoint. Now for testing purpose i want to deploy the certificate to non intune device, so how we can generate the…
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
Certificate Error - Subject Alternative Name
Dear, We are receiving the following message/error!!!. It is a Default Web Site in a IIS. In different forums, it is indicated that the error is because the URL names to be resolved in the certificate do not match. How do we verify this on the…
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
How to fix AD CS auto-enrollment stalls and Event ID 64 on domain clients, and how to debug proxy endpoints and clear stale RPC keys?
How to fix AD CS auto-enrollment stalls and Event ID 64 on domain clients, and how to debug proxy endpoints and clear stale RPC keys?
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
Public Key Infrastructure (PKI) CA Private Key HSM Communication LossRoot CA Stops Publishing CRLs After HSM Network Outage
Hi everyone, We have an offline enterprise Root CA whose private key is protected by a network-attached HSM. During a scheduled CRL publication window, the HSM network interface briefly went down while our network team was performing…
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
PKCS Device Certificate
Is UPN can work if the PKCS set to device certificate?
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
Adding new OCSP online responder server to already running array controller.
I'm in a process of adding a newly build server running on windows 25 as a array member directly from array controller but repeatdely getting error RPC server not available. Want to know the ports and protocal involved in adding a newly build OCSP server…
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
Windows Server 2025 AD CS certsrv.msc displays random Unicode characters in empty rows after Refresh
Environment: Windows Server 2025 (24H2) updated July 2026 ISO image Active Directory Certificate Services installed Certification Authority MMC snap-in (certsrv.msc) Issue: After adding a certificate request (Pending Requests / Issued Certificates…
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
Using RSA Token for RDP instead of Windows password
I am currently trying to configure our rdp sessions to prompt for RSA instead of a windows password, I tried registry edits and local GPO, is there something I'm missing, I assumed this would be a simple setup
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
Safe PKI Issuing CA OS Migration (2019 to 2022): Backup/Restore Strategy Without Deleting Old CA First
Hi Everyone, I am planning an in-place upgrade/migration of an Active Directory-Integrated Enterprise Issuing CA running on Windows Server 2019 to a new Windows Server 2022 virtual machine. Key Requirements & Constraints: Quick Rollback: I want…
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
Can a single NDES server support multiple certificate templates?
Hello Team, My internal PKI team mentioned that a Network Device Enrollment Service (NDES) server can only be configured to issue one certificate template, and that supporting multiple templates on a single NDES instance isn't possible. Is this statement…
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
Do I need to renew/re-sign the Issuing CA certificate after changing CDP/AIA URLs?
Hello, I have a Microsoft two-tier PKI with the following architecture: Offline Root CA Enterprise Issuing Subordinate CA I am changing the PKI architecture by adding a dedicated IIS server that will host: CRL Distribution Points (CDP) Authority…
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
Server 2022 certificate logon fails with "hash algorithm not supported on server"
Hi, I have a Windows Server 2022 in our domain where I want do log onto via RDP. Authentication should be handled via smartcard/certificate. The certificate was created as a smartcard certificate on the local CA which is trusted by the server. Whenever I…
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
Work Folders sync failing with sync relationship error
When a subset of users tries to sync Work Folders, they cannot access the sync options because it fails with "sync relationship could not be established." What's the certificate / AD FS dependency check for Work Folders?
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
Cert private key permission changes
Hello, We're implementing a new Windows Event Collector using HTTPS. I have followed various online guides from Microsoft and others and I have a working environment. The only issue I ran in to was having to assign the NETWORK SERVICE account read only…
Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
ADFS Token-Signing Cert Expired (Auto-rollover bypassed) / Need safe manual rollover steps
Hi team, We have a P1 incident on ADFS. The automated token-signing certificate rollover failed to trigger, and current cert is already expired. Federated login for all integrated apps is currently down. We need to execute a manual certificate renewal…