187 questions with Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI) tags

Sort by: Updated
2 answers

Windows Computers Intune joined, have intermittent disconnect to AD/ print services.

We have several windows computers joined to Intune; while communicating to a on prem DC on Server 2025. Several months before I joined, the windows computers started having issues connecting to the print servers. They will get the "unable to…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-12-15T03:09:44.5133333+00:00
Jon (Admin) 0 Reputation points
answered 2025-12-15T03:53:32.9366667+00:00
Harry Phan 10,690 Reputation points Independent Advisor
2 answers One of the answers was accepted by the question author.

How to convert subordinate Issuing CA to Enterprise CA?

Have a two tier PKI infrastructure with a (non-domain joined) Enterprise PKI and a domain joined, AD integrated issuing PKI. Certificates are used only for internal purposes. A single domain joined enterprise PKI would be sufficient and would eliminate…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-12-09T10:17:39.7266667+00:00
Franz Schenk 386 Reputation points
commented 2025-12-09T13:38:57.9633333+00:00
Franz Schenk 386 Reputation points
3 answers One of the answers was accepted by the question author.

Certificate Template Issued from CA Server Not Showing on Client During Certificate Request

Hello, I am trying to set up ADFS from a client server that has joined the domain with an ADDS server. The ADDS server also has a CA installed. The problem is that I already created a certificate template, added "Domain Computers" in the…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-12-04T08:23:06.2266667+00:00
Arya Abdul Azis 20 Reputation points
accepted 2025-12-05T09:52:40.1366667+00:00
Arya Abdul Azis 20 Reputation points
3 answers One of the answers was accepted by the question author.

license document

We lost the license document and the CD. What should we do? We only have the backup key windows server 2022 ROK 16core invoice 4100754 @bangkok thailand

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-12-01T07:23:05.4433333+00:00
Chiraphan Thapthap 20 Reputation points
commented 2025-12-04T01:44:53.2833333+00:00
Brian Huynh (WICLOUD CORPORATION) 2,335 Reputation points Microsoft External Staff Moderator
2 answers

Certificate Authority Migration - CDP Location #1 Unable to Download

I am following the guide published here https://v4.hkg1.meaqua.org/en-us/troubleshoot/windows-server/certificates-and-public-key-infrastructure-pki/move-certification-authority-to-another-server To Migrate Certificate authority from an ancient server…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-11-20T20:50:10.2533333+00:00
Justin Mattingly 0 Reputation points
commented 2025-12-04T00:53:59.4+00:00
Kate Pham (WICLOUD CORPORATION) 430 Reputation points Microsoft External Staff Moderator
5 answers

Cannot get OCSP working even though all certs are fine

Hi, I am creating an internal PKI service. I have got an offline RootCA and 2 standalone SubCa's. These are operational and signing certificates. I have created ocsp certs with No Rev Check & OCSP Signing OIDs added. The online responder is up and…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-11-19T13:50:38.03+00:00
Matt Axton 5 Reputation points
answered 2025-12-01T16:46:23.64+00:00
Matt Axton 5 Reputation points
2 answers

Windows Admin Center Can't Access .local Domain After .com Cert Install

This is a new install of Admin Center. I initially installed it using the self signed cert and setup our new cluster. So I can see several servers and they are currently working as of this writing. Our domain is .local. But I installed a wildcard…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-11-04T18:08:47.92+00:00
Joe Hinkle 0 Reputation points
edited an answer 2025-11-28T08:00:40.3+00:00
Kate Pham (WICLOUD CORPORATION) 430 Reputation points Microsoft External Staff Moderator
3 answers One of the answers was accepted by the question author.

SubjectAltName custom policy module in MIM CM

Hi.   We are setting up a Microsoft-based smartcard issuance production system consisting of a CA server, AD server that will contain the SQL as well, and a MIM portal server. We have an old system currently running FIM 2010 (on 2008r2 servers) in a…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-11-25T07:57:57.02+00:00
PID_Uri 20 Reputation points
accepted 2025-11-26T13:15:52.6466667+00:00
PID_Uri 20 Reputation points
4 answers

Certificate-based authentication failing for domain-joined devices

We have successfully setup Certificate Base Authentication with our Hybrid environment. Many months later we are unable to log in locally using certificates. We get 2 errors when trying to log in. Signing in with a smart card isn't supported for…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-11-05T17:48:00.7666667+00:00
Anthony Montaleone 0 Reputation points
answered 2025-11-23T08:43:23.0133333+00:00
VPHAN 11,040 Reputation points Independent Advisor
8 answers

Remove old Windows 2012 R2 AD Cs and set up new in Windows 2025

I have a Windows 2012 R2 with AD CS installed. Is it possible to simply remove the feature. I plan to set up a new one in a WIndows 2025. I want to set up new as the old name is not right. Currently the AD CS in the old server is only issues certificates…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-11-03T09:56:43.64+00:00
Zulkefli Aris 0 Reputation points
accepted 2025-11-13T11:19:29.0433333+00:00
Zulkefli Aris 0 Reputation points
2 answers

Setting up Two CEP Services for Cross Forest Certificate Enrollment defaults to old CA

I am trying to implement a new CA to replace our old one. I had implemented the current CA, we use cross-forest cert enrollment for a trusted domain. It has been working for a long time. I have added a new CA with new certs and keys and roots. I'm…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-11-11T18:12:39.2466667+00:00
ComputerHabit 1,051 Reputation points
edited a comment 2025-11-12T14:02:59.94+00:00
ComputerHabit 1,051 Reputation points
3 answers One of the answers was accepted by the question author.

PKI - Certificate Templates: DACL assessment

Hi everyone, I've created a script to assess the grant on SubCA templates in the Security tab. The resulting script returns a .csv file and an .html file. Can you tell me if it's working properly for you and if it's structured and written properly? I…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-10-17T09:20:49.8066667+00:00
49885604 235 Reputation points
accepted 2025-11-07T11:01:30.91+00:00
49885604 235 Reputation points
1 answer

Strong Certificate Mapping Enforcement for offline certificate requests

Hello folks, In our corporate network 802.1X affects all devices. So far, we requested certificate for network printers using our internal CA, so we installed these certificates on our network printers. How can I add the OID 1.3.6.1.4.1.311.25.2…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-11-05T12:04:06.8933333+00:00
Federico 0 Reputation points
commented 2025-11-06T15:09:27.19+00:00
Federico 0 Reputation points
3 answers

Renew / Recreate User Certificates

We have several remote users that their user certificates have expired. We are using a single Windows Server CA. I am trying to renew or create new certificates for the users, export the certificate and send the certificate to the users. When I try to…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-11-03T15:13:54.6666667+00:00
Daniel Andryszak 121 Reputation points
answered 2025-11-04T12:09:35.4333333+00:00
Harry Phan 10,690 Reputation points Independent Advisor
1 answer One of the answers was accepted by the question author.

I need to install an SSL certificate on a Windows Server 2022 Standard and Go Daddy wants me to choose my server type. What is the server type?

I am not an IT person and I need to install a new SSL certificate on our server. I found out we have a Microsoft Server 2022 Standard. Go Daddy wants me to choose from the below list of server types to download the certificate, but I don't know how to…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-10-30T19:50:54.5966667+00:00
QIC Christi 20 Reputation points
edited the question 2025-11-03T06:27:28.13+00:00
Kate Pham (WICLOUD CORPORATION) 430 Reputation points Microsoft External Staff Moderator
2 answers

RPC Server Unavailable (0x800706ba) when adding Certificate Template on Local CA/DC

I'm encountering an issue when trying to add a new certificate template to issue on my Certification Authority (CA) server. The CA is installed on a local server that also functions as a Domain Controller (DC) in my environment. When I navigate to…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-10-22T23:48:49.2733333+00:00
Jorenzo Lucero 0 Reputation points
answered 2025-10-25T04:19:56.72+00:00
Harry Phan 10,690 Reputation points Independent Advisor
1 answer One of the answers was accepted by the question author.

Server Certificate Regeneration Issue

Unable to request new certificates with the same key. Purpose is for LDAPS. I noticed the certificates have not been renewed for almost 2 years. When I attempt to renew, I encounter the issue shown in the screenshot below. Can anyone shed a light as to…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-10-20T18:01:16.9866667+00:00
Carlos Sanchez 20 Reputation points
accepted 2025-10-21T19:49:06.16+00:00
Carlos Sanchez 20 Reputation points
1 answer

add a custom extension to a subordinate CA certificate

Hi. I'm deploying a subordinate CA and need to add a custom extension to the issuing CA's certificate, the value of which is loaded from a file. I tried adding the following section to capolicy.inf: [Extensions] 1.2.3.4.5.6.7.8.9.10 =…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-10-20T15:46:47.8566667+00:00
Вячеслав Овсянкин 0 Reputation points
commented 2025-10-21T11:17:34.6966667+00:00
Вячеслав Овсянкин 0 Reputation points
1 answer One of the answers was accepted by the question author.

Question about renewing internal Certificate Authority (AD CS) certificate on Domain Controller - Windows Server 2012 R2

Hello everyone, I have a question regarding the renewal process of an internal certificate issued by my Certificate Authority (CA) in a Windows Server 2012 R2 environment. The server that acts as the primary Domain Controller also has the following roles…

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-10-14T20:01:37.3+00:00
Ezequiel Bomfim 40 Reputation points
commented 2025-10-15T11:19:55.9133333+00:00
Ezequiel Bomfim 40 Reputation points
1 answer

licence windows server 2022 ne passe pas

Bonjour , nous avons acquerir un windows server 2022 64 bits std mais la cle de produit ne passe pas

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
asked 2025-09-30T10:43:28.9533333+00:00
OGOUNIRAN SODIKI 0 Reputation points
answered 2025-09-30T11:51:43.6366667+00:00
Chen Tran 4,860 Reputation points Independent Advisor