User Tools

Site Tools


microsoft:ca

Microsoft - Certificate Authority

Blogposts/Articles

Certificates with RSA key <1024 bits blocked after KB 2661254

NDES/SCEP

Auto-enrollment

Domain Controller certificate auto-enrollment

In short: If an Enterprise CA is available and the Domain Controllers certificate is published (it is by default) Domain Controllers will auto-enroll to the Domain Controllers certificate template, (even) when auto-enrollment is not configured via GPO.

Morgan Simonsen's Blog - Active Directory Domain Controllers and certificate auto-enrollment
The things that are better left unspoken - TODO: Upgrade the Certificates for your Windows Server 2016-based Domain Controllers (and up) to enable Windows Hello for Business Hybrid Scenarios

SAN certificates

Notes

Verify certificate

Problem: Submitting a request via the Certification Authority console results in error

Error:

The request contains no certificate template information.
0x80094801 (-2146875391)
Denied by Policy Module 0x80094801, The request does not
contain a certificate template extension or the Certificate Template
request attribute.

Solution: Use the following to request the certificate:

certreq.exe -submit -attrib "CertificateTemplate:WebServer" c:\setup\certificate.req

Then select the CA that should sign the certificate and save the signed certificate somewhere. Source:ExchangeInbox.com - Replacing the Exchange 2007 Self-Signed Certificate (Part 2)

microsoft/ca.txt · Last modified: 2023/07/19 14:01 by bas