Server Certificate Regeneration Issue

Carlos Sanchez 20 Reputation points
2025-10-20T18:01:16.9866667+00:00

Unable to request new certificates with the same key. Purpose is for LDAPS. I noticed the certificates have not been renewed for almost 2 years. When I attempt to renew, I encounter the issue shown in the screenshot below. Can anyone shed a light as to the process for resolving this error. Running "certutil -config - -ping" returns no CA results as well. TIA for any guidance.

User's image

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
0 comments No comments
{count} votes

Answer accepted by question author
  1. VPHAN 11,040 Reputation points Independent Advisor
    2025-10-20T18:34:03.41+00:00

    Hi Carlos Sanchez,

    You are unable to discover a CA because the AD CS service or the CA’s publish information is not available to the domain, and that prevents enrollment using the Active Directory Enrollment Policy. Verify the CA server is online and the Certification Authority service is running on the expected host. Confirm the CA certificate has not expired and that its root/intermediate certificates are present and trusted in the domain and on the server where you request the LDAPS certificate. Check DNS resolution and firewall rules so the client can reach the CA RPC and HTTP endpoints used for enrollment. Inspect the CA’s published enrollment points in Active Directory by checking the msPKI-Enrollment-Servers and ensure the CA’s AIA and CDP are reachable. Review the CA event log for denied enrollment requests and the client Application and System event logs for enrollment errors. The “same key” renewal restriction is often caused by a mismatch between the template settings and the key storage provider type or by CA policy that disallows reuse of the private key. Verify the certificate template allows renewal with the same key and that the template’s CSP/KSP settings match the machine’s key provider. Export and secure a backup of the existing machine certificate and private key before attempting any renewals. If the CA cannot be restored quickly, generate a new key pair, request a new certificate from a reachable CA, and rebind that certificate to LDAPS to restore service immediately. If the CA is available after you restore it, perform a controlled test to renew using the same key and monitor the CA logs for any template or policy rejections.

    If this answer helps, please hit “accept answer” — thanks 🙂


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.