Locate servers with Certificate Authority Web Enrollment and Certificate Enrollment Web Service roles

Mishaua 741 Reputation points
2022-10-06T21:35:11.837+00:00

Is there a command to see servers with Certificate Authority Web Enrollment and/or Certificate Enrollment Web Service roles? I see that certutil.exe has a "Web Enrollment Servers" section is that where servers with the "Certificate Enrollment Web Service" should be listed? How about "Certificate Authority Web Enrollment"?

Windows for business | Windows Server | Devices and deployment | Configure application groups
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Vadims Podāns 9,186 Reputation points MVP
    2022-10-07T07:13:43.577+00:00

    The simple answer is "no". Only CA role is registered in AD, thus CAs support auto-discovery. Other ADCS roles are not registered and doesn't support auto-discovery.

    0 comments No comments

  2. Mishaua 741 Reputation points
    2022-10-20T19:39:46.217+00:00

    I guess you could query ad for computers that have delegation enabled on the computer object to narrow down the roles. What roles besides "Certificate Authority Web Enrollment" require the computer account to have delegation enabled?


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.