Hi,
Did you try to use a account member of enterprise admins when you install the PKI ?
Please don't forget to mark this reply as answer if it help you to fix your issue
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I am not able to create an Enterprise root CA in our Domain. The certocm.log gives the following, which seems an awful lot longer than other logs I saw so far:
402.483.948: Anfang: 04.12.2020 11:45 06.856s
402.488.0: wsmprovhost.exe
402.496.0: GMT + 1.00
104.138.0: certca.dll: 10.0.17763.1 retail
104.138.0: certocm.dll: 10.0.17763.1 retail
114.684.948: <2020/12/4, 11:45:06>: Anfang: CCertSrvSetup::InitializeDefaults
437.556.0:<2020/12/4, 11:45:06>: 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND): SetupStatus
109.7912.0:<2020/12/4, 11:45:06>: 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND)
437.556.0:<2020/12/4, 11:45:06>: 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND): SetupStatus
109.7931.0:<2020/12/4, 11:45:06>: 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND)
437.556.0:<2020/12/4, 11:45:06>: 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND): SetupStatus
109.7912.0:<2020/12/4, 11:45:06>: 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND)
401.335.0:<2020/12/4, 11:45:06>: 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND)
401.432.0:<2020/12/4, 11:45:06>: 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND)
401.1274.0:<2020/12/4, 11:45:06>: 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND): C:\Windows\CAPolicy.inf
454.251.0:<2020/12/4, 11:45:06>: 0x80004005 (-2147467259 E_FAIL): AES-GMAC
454.251.0:<2020/12/4, 11:45:06>: 0x80004005 (-2147467259 E_FAIL): AES-CMAC
437.556.0:<2020/12/4, 11:45:06>: 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND): LDAPFlags
437.556.0:<2020/12/4, 11:45:07>: 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND): LDAPFlags
429.3041.0:<2020/12/4, 11:45:07>: 0x80072095 (WIN32: 8341 ERROR_DS_GENERIC_ERROR)
109.882.1838: <2020/12/4, 11:45:07>: Verfügbarkeitsstatus der Unternehmenszertifizierungsstelle: ENUM_ENTERPRISE_UNAVAIL_REASON_NO_INSTALL_RIGHTS
437.556.0:<2020/12/4, 11:45:07>: 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND): ConfigurationDirectory
454.348.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL)
454.348.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL)
454.348.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL)
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-GMAC
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-CMAC
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-GMAC
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-CMAC
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-GMAC
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-CMAC
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-GMAC
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-CMAC
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-GMAC
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-CMAC
452.730.0:<2020/12/4, 11:45:07>: 0x80090030 (-2146893776 NTE_DEVICE_NOT_READY): Microsoft Platform Crypto Provider
454.705.0:<2020/12/4, 11:45:07>: 0x80090030 (-2146893776 NTE_DEVICE_NOT_READY)
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-GMAC
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-CMAC
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-GMAC
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-CMAC
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-GMAC
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-CMAC
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-GMAC
454.251.0:<2020/12/4, 11:45:07>: 0x80004005 (-2147467259 E_FAIL): AES-CMAC
3109.1429.0:<2020/12/4, 11:45:07>: 0x80090016 (-2146893802 NTE_BAD_KEYSET): 4R-4RCERTSRV-CA
3109.1430.0:<2020/12/4, 11:45:07>: 0x0 (WIN32: 0)
3109.1431.0:<2020/12/4, 11:45:07>: 0x60 (WIN32: 96)
112.341.0:<2020/12/4, 11:45:07>: 0x80090016 (-2146893802 NTE_BAD_KEYSET): Exception at onecore\ds\security\services\ca\fs\crypto\cngcryptofactory.cpp(471): NCryptOpenKey(hProv, &hKey, pwszKeyName, nLegacyKeySpec, acquireToOpenKeyFlags(fAcquire))
HRESULT = 0x80090016
114.883.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::InitializeDefaults
114.3429.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetProviderNameList
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): SHA256
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): DSA
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): SHA384
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): DSA
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): SHA512
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): DSA
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): SHA256
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): DSA
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): SHA384
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): DSA
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): SHA512
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): DSA
114.3506.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetProviderNameList
114.3841.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetHashAlgorithmList
114.3982.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetHashAlgorithmList
114.3768.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetKeyLengthList
114.3816.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetKeyLengthList
114.3841.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetHashAlgorithmList
114.3982.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetHashAlgorithmList
114.3768.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetKeyLengthList
114.3816.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetKeyLengthList
114.3841.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetHashAlgorithmList
114.3982.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetHashAlgorithmList
114.3768.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetKeyLengthList
114.3816.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetKeyLengthList
114.3841.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetHashAlgorithmList
114.3982.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetHashAlgorithmList
114.3768.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetKeyLengthList
114.3816.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetKeyLengthList
114.3841.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetHashAlgorithmList
114.3982.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetHashAlgorithmList
114.3768.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetKeyLengthList
114.3816.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetKeyLengthList
114.3841.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetHashAlgorithmList
114.3982.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetHashAlgorithmList
114.3768.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetKeyLengthList
114.3816.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetKeyLengthList
114.3841.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetHashAlgorithmList
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): SHA256
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): DSA
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): SHA384
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): DSA
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): SHA512
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): DSA
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD5
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): DSA
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD4
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): DSA
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD2
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): DSA
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): SHA256
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): DSA
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): SHA384
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): DSA
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): SHA512
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): DSA
114.3982.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetHashAlgorithmList
114.3768.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetKeyLengthList
114.3816.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetKeyLengthList
114.3841.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetHashAlgorithmList
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD5
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD4
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD2
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
114.3982.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetHashAlgorithmList
114.3768.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetKeyLengthList
114.3816.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetKeyLengthList
114.3841.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetHashAlgorithmList
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD5
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD4
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD2
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
114.3982.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetHashAlgorithmList
114.3768.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetKeyLengthList
114.3816.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetKeyLengthList
114.3841.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetHashAlgorithmList
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD5
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD4
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD2
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
114.3982.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetHashAlgorithmList
114.3768.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetKeyLengthList
114.3816.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetKeyLengthList
114.3841.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetHashAlgorithmList
114.3982.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetHashAlgorithmList
114.3768.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetKeyLengthList
114.3816.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetKeyLengthList
114.3841.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetHashAlgorithmList
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD5
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD4
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD2
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
114.3982.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetHashAlgorithmList
114.3768.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetKeyLengthList
114.3816.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetKeyLengthList
114.3841.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetHashAlgorithmList
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD5
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD4
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD2
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
114.3982.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetHashAlgorithmList
114.3768.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetKeyLengthList
114.3816.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetKeyLengthList
114.3841.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetHashAlgorithmList
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD5
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD4
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
420.1793.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): MD2
420.1794.0:<2020/12/4, 11:45:07>: 0x80091002 (-2146889726 CRYPT_E_UNKNOWN_ALGO): CryptOIDInfoECCParameters
114.3982.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetHashAlgorithmList
114.3768.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetKeyLengthList
114.3816.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetKeyLengthList
114.4005.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetPrivateKeyContainerList
420.185.0:<2020/12/4, 11:45:07>: 0x80090016 (-2146893802 NTE_BAD_KEYSET): Microsoft Base Cryptographic Provider v1.0
420.192.0:<2020/12/4, 11:45:07>: 0x80090016 (-2146893802 NTE_BAD_KEYSET)
114.4116.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetPrivateKeyContainerList
114.4005.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetPrivateKeyContainerList
420.185.0:<2020/12/4, 11:45:07>: 0x80090016 (-2146893802 NTE_BAD_KEYSET): Microsoft Base DSS Cryptographic Provider
420.192.0:<2020/12/4, 11:45:07>: 0x80090016 (-2146893802 NTE_BAD_KEYSET)
114.4116.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetPrivateKeyContainerList
114.4005.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetPrivateKeyContainerList
203.382.0:<2020/12/4, 11:45:07>: 0x80090010 (-2146893808 NTE_PERM)
203.736.0:<2020/12/4, 11:45:07>: 0x80090010 (-2146893808 NTE_PERM)
114.4059.0:<2020/12/4, 11:45:07>: 0x80090010 (-2146893808 NTE_PERM)
0.363.965: <2020/12/4, 11:45:07>: Meldungsfeld: Microsoft-Active Directory-Zertifikatdienste: Fehler beim Active Directory-Zertifikatdienste-Setup mit folgendem Fehlercode: Zugriff verweigert 0x80090010 (-2146893808 NTE_PERM): Zugriff verweigert 0x80090010 (-2146893808 NTE_PERM)
114.4116.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetPrivateKeyContainerList: Fehler beim Active Directory-Zertifikatdienste-Setup mit folgendem Fehlercode: Zugriff verweigert 0x80090010 (-2146893808 NTE_PERM): Zugriff verweigert 0x80090010 (-2146893808 NTE_PERM)
114.4005.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetPrivateKeyContainerList
420.185.0:<2020/12/4, 11:45:07>: 0x80090016 (-2146893802 NTE_BAD_KEYSET): Microsoft Enhanced Cryptographic Provider v1.0
420.192.0:<2020/12/4, 11:45:07>: 0x80090016 (-2146893802 NTE_BAD_KEYSET)
114.4116.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetPrivateKeyContainerList
114.4005.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetPrivateKeyContainerList
420.185.0:<2020/12/4, 11:45:07>: 0x80090016 (-2146893802 NTE_BAD_KEYSET): Microsoft Strong Cryptographic Provider
420.192.0:<2020/12/4, 11:45:07>: 0x80090016 (-2146893802 NTE_BAD_KEYSET)
114.4116.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetPrivateKeyContainerList
114.4005.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetPrivateKeyContainerList
114.4116.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetPrivateKeyContainerList
114.4005.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetPrivateKeyContainerList
114.4116.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetPrivateKeyContainerList
114.4005.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetPrivateKeyContainerList
114.4116.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetPrivateKeyContainerList
114.4005.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetPrivateKeyContainerList
114.4116.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetPrivateKeyContainerList
114.4005.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetPrivateKeyContainerList
114.4116.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetPrivateKeyContainerList
114.4005.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetPrivateKeyContainerList
452.783.0:<2020/12/4, 11:45:07>: 0x80090009 (-2146893815 NTE_BAD_FLAGS)
203.544.0:<2020/12/4, 11:45:07>: 0x80090009 (-2146893815 NTE_BAD_FLAGS): Microsoft Smart Card Key Storage Provider
114.4048.0:<2020/12/4, 11:45:07>: 0x80090009 (-2146893815 NTE_BAD_FLAGS)
0.363.965: <2020/12/4, 11:45:07>: Meldungsfeld: Microsoft-Active Directory-Zertifikatdienste: Fehler beim Active Directory-Zertifikatdienste-Setup mit folgendem Fehlercode: Ungültige Optionen angegeben 0x80090009 (-2146893815 NTE_BAD_FLAGS): Ungültige Optionen angegeben 0x80090009 (-2146893815 NTE_BAD_FLAGS)
114.4116.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetPrivateKeyContainerList: Fehler beim Active Directory-Zertifikatdienste-Setup mit folgendem Fehlercode: Ungültige Optionen angegeben 0x80090009 (-2146893815 NTE_BAD_FLAGS): Ungültige Optionen angegeben 0x80090009 (-2146893815 NTE_BAD_FLAGS)
114.4005.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetPrivateKeyContainerList
452.783.0:<2020/12/4, 11:45:07>: 0x80090009 (-2146893815 NTE_BAD_FLAGS)
203.544.0:<2020/12/4, 11:45:07>: 0x80090009 (-2146893815 NTE_BAD_FLAGS): Microsoft Smart Card Key Storage Provider
114.4048.0:<2020/12/4, 11:45:07>: 0x80090009 (-2146893815 NTE_BAD_FLAGS)
0.363.965: <2020/12/4, 11:45:07>: Meldungsfeld: Microsoft-Active Directory-Zertifikatdienste: Fehler beim Active Directory-Zertifikatdienste-Setup mit folgendem Fehlercode: Ungültige Optionen angegeben 0x80090009 (-2146893815 NTE_BAD_FLAGS): Ungültige Optionen angegeben 0x80090009 (-2146893815 NTE_BAD_FLAGS)
114.4116.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetPrivateKeyContainerList: Fehler beim Active Directory-Zertifikatdienste-Setup mit folgendem Fehlercode: Ungültige Optionen angegeben 0x80090009 (-2146893815 NTE_BAD_FLAGS): Ungültige Optionen angegeben 0x80090009 (-2146893815 NTE_BAD_FLAGS)
114.4005.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetPrivateKeyContainerList
452.783.0:<2020/12/4, 11:45:07>: 0x80090009 (-2146893815 NTE_BAD_FLAGS)
203.544.0:<2020/12/4, 11:45:07>: 0x80090009 (-2146893815 NTE_BAD_FLAGS): Microsoft Smart Card Key Storage Provider
114.4048.0:<2020/12/4, 11:45:07>: 0x80090009 (-2146893815 NTE_BAD_FLAGS)
0.363.965: <2020/12/4, 11:45:07>: Meldungsfeld: Microsoft-Active Directory-Zertifikatdienste: Fehler beim Active Directory-Zertifikatdienste-Setup mit folgendem Fehlercode: Ungültige Optionen angegeben 0x80090009 (-2146893815 NTE_BAD_FLAGS): Ungültige Optionen angegeben 0x80090009 (-2146893815 NTE_BAD_FLAGS)
114.4116.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetPrivateKeyContainerList: Fehler beim Active Directory-Zertifikatdienste-Setup mit folgendem Fehlercode: Ungültige Optionen angegeben 0x80090009 (-2146893815 NTE_BAD_FLAGS): Ungültige Optionen angegeben 0x80090009 (-2146893815 NTE_BAD_FLAGS)
114.4005.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetPrivateKeyContainerList
452.783.0:<2020/12/4, 11:45:07>: 0x80090009 (-2146893815 NTE_BAD_FLAGS)
203.544.0:<2020/12/4, 11:45:07>: 0x80090009 (-2146893815 NTE_BAD_FLAGS): Microsoft Smart Card Key Storage Provider
114.4048.0:<2020/12/4, 11:45:07>: 0x80090009 (-2146893815 NTE_BAD_FLAGS)
0.363.965: <2020/12/4, 11:45:07>: Meldungsfeld: Microsoft-Active Directory-Zertifikatdienste: Fehler beim Active Directory-Zertifikatdienste-Setup mit folgendem Fehlercode: Ungültige Optionen angegeben 0x80090009 (-2146893815 NTE_BAD_FLAGS): Ungültige Optionen angegeben 0x80090009 (-2146893815 NTE_BAD_FLAGS)
114.4116.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetPrivateKeyContainerList: Fehler beim Active Directory-Zertifikatdienste-Setup mit folgendem Fehlercode: Ungültige Optionen angegeben 0x80090009 (-2146893815 NTE_BAD_FLAGS): Ungültige Optionen angegeben 0x80090009 (-2146893815 NTE_BAD_FLAGS)
114.3302.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetSupportedCATypes
114.3362.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetSupportedCATypes
114.3137.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::SetCASetupProperty
114.3226.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::SetCASetupProperty
114.4625.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetExistingCACertificates
114.4779.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetExistingCACertificates
114.3137.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::SetCASetupProperty
114.3226.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::SetCASetupProperty
114.4625.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::GetExistingCACertificates
114.4779.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::GetExistingCACertificates
114.3137.948: <2020/12/4, 11:45:07>: Anfang: CCertSrvSetup::SetCASetupProperty
114.3226.949: <2020/12/4, 11:45:07>: Ende: CCertSrvSetup::SetCASetupProperty
402.326.949: Ende: 04.12.2020 12:15 07.505s
We previously had a misconfigured CA in the domain, which I removed according to Microsofts Guides. So as of now, we don't have anything CA-like in our domain.
The Server which I want to configure now is completely new and freshly installed (Server 2019, latest available updates). It has no roles other than the AD-Certificate Services, which is supposed to be its only purpose.
Edit: The Account I use for this is definitively an enterprise admin. I verified this on the domaincontroller as well as with whoami /groups
In fact, it does not matter which account I use, even our "all-purpose-admin", which has every right there is to have isn't allowed to create the CA.
Hi,
Did you try to use a account member of enterprise admins when you install the PKI ?
Please don't forget to mark this reply as answer if it help you to fix your issue
Hi,
I am glad to hear that your issue was successfully resolved\I am pleased to know that the information is helpful to you. If there is anything else we can do for you, please feel free to post in the forum.
Best Regards,
Vicky