question

Gorf-1867 avatar image
0 Votes"
Gorf-1867 asked DaisyZhou-MSFT commented

Windows Certificate Services will not publish a certificate template.

There are a lot of discussions on here about this problem, and I have spent all day exploring every one of them. All the servers involved in this are Windows 2019. 2 domain controllers and a certificate authority server. After installing the Certificate Services feature, I then also installed the Web Enrollment stuff. But when I go to my server's enrollment site, I am greeted with this error:

82994-screen-shot-2021-03-30-at-174541.png


I've chased down several options. I validated permissions via:
https://www.altaro.com/hyper-v/windows-ssl-certificate-templates/

I verified LDAP object configurations via:
https://docs.microsoft.com/en-US/troubleshoot/windows-server/windows-security/no-certificate-templates-be-found

I verified the configuration from this site:
https://docs.microsoft.com/en-us/answers/questions/96739/certificate-template-not-showing.html

I'm running out of options. The template is clearly there:
82960-screen-shot-2021-03-30-at-174552.png

I'm completely out of ideas. I'm frustrated by this. Has anyone got any other ideas?


windows-server-security
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

What is the version of the Web Server template (v2,v3,v4)? AFAIK only V2 templates are supported for web enrollment pages. See https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/cng-templates-not-appear-certificate-web-enrollment for more information

Martin

0 Votes 0 ·
DaisyZhou-MSFT avatar image
1 Vote"
DaisyZhou-MSFT answered DaisyZhou-MSFT commented

Hello @Gorf-1867,

Thank you for posting here.

Beside the "Supply in the request" subject name.

1.Could you please check if the computer group or the specific computer has read and enroll permissions, and Authenticated Users group has read permission.
83154-web-server-1.png

2.Also, please check if you can see this certificate template via MMC on the same machine.
83097-web1.png

Should you have any question or concern, please feel free to let us know.



Best Regards,
Daisy Zhou



web-server-1.png (45.5 KiB)
web1.png (19.3 KiB)
· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Aw! Thank you. I think what I forgot to do after altering the permissions was to republish the template. Correcting the permissions appears to have solved this. Thanks!

0 Votes 0 ·

Hello @Gorf-1867,
Thank you for your update and accepting my reply as answer. I am very glad that the information is helpful and the problem has been solved.
As always, if there is any question in future, we warmly welcome you to post in this forum again. We are happy to assist you!

Best Regards,
Daisy Zhou

0 Votes 0 ·
dimiro avatar image
1 Vote"
dimiro answered Gorf-1867 commented

try to check this option in "subject name -> supply in the request"
after, you need to republish your template.

82948-2021-03-30-23-21-29-window.png



· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thanks! I did make this change, but it appears that the underlying issue was permissions!

1 Vote 1 ·