Locate servers with Certificate Authority Web Enrollment and Certificate Enrollment Web Service roles

Mishaua 716 Reputation points
2022-10-06T21:35:11.837+00:00

Is there a command to see servers with Certificate Authority Web Enrollment and/or Certificate Enrollment Web Service roles? I see that certutil.exe has a "Web Enrollment Servers" section is that where servers with the "Certificate Enrollment Web Service" should be listed? How about "Certificate Authority Web Enrollment"?

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,782 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Vadims Podāns 9,116 Reputation points MVP
    2022-10-07T07:13:43.577+00:00

    The simple answer is "no". Only CA role is registered in AD, thus CAs support auto-discovery. Other ADCS roles are not registered and doesn't support auto-discovery.

    0 comments No comments

  2. Mishaua 716 Reputation points
    2022-10-20T19:39:46.217+00:00

    I guess you could query ad for computers that have delegation enabled on the computer object to narrow down the roles. What roles besides "Certificate Authority Web Enrollment" require the computer account to have delegation enabled?