Windows 2016 Certificate Service will not start.

MEYER, JASON 1 Reputation point
2021-04-07T14:31:03.49+00:00

After a careless mistake of deleting the computer account for the CA, I get this error. Active Directory Certificate Services did not start: Could not load or verify the current CA certificate. servername The system cannot find the file specified. 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND).

I was able to restore the computer account using AD Admin Center and I can login via RDC and a domain admin user. But the above error still appears. I migrated from 2008 R2 about a year ago and still have that backup from the OLD CA. its not used for much really, just computer certificates in my domain.

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,900 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Daisy Zhou 28,821 Reputation points Microsoft Vendor
    2021-04-08T02:42:07.017+00:00

    Hello @MEYER, JASON ,

    Thank you for posting here.

    As I understand, you have one-tier enterprise CA in your AD domain.

    Based on the description "still have that backup from the OLD CA.", do you mean you still have the old CA backup before deleting the computer account for the CA in AD?

    If so, you can try to restore the CA backup to the restored the computer, then check if it helps.

    Step-By-Step: Migrating The Active Directory Certificate Service From Windows Server 2008 R2 to 2019
    https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-migrating-the-active-directory-certificate-service/ba-p/697674

    Tip: You can do similar test in your lab first, if everything is OK, you can do it in your production environment.

    Should you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.