Hello @Pe ter ,
Thank you for posting here.
How did you set up CEP and CES? What documents did you refer?
For the CES a seperate server ist used. The application pool for the CES is running under a gmsa with constrained delegation for the configured CA.
If i configure the CES instance, with named gmsa, using username/password authentication, the enrollment for a certificate works as intended.
If i configure the CES instance, with named gmsa, using certificate authentication, the enrollment for a certificate for a requesting client fails with the error message:
"-214348933 WS_E_ENDPOINT_FAULT_RECEIVED"
No errors are logged on the CES or CA.
Maybe the following articles are helpful.
Configuring Certificate Enrollment Web Service for certificate key-based renewal on a custom port
https://learn.microsoft.com/en-us/windows-server/identity/solution-guides/certificate-enrollment-certificate-key-based-renewal
Certificate Enrollment Web Services
https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/certificate-enrollment-web-services/ba-p/397385
Please check if PKIview.msc status including root CA entries and sub CA entries are all OK.
Should you have any question or concern, please feel free to let us know.
Best Regards,
Daisy Zhou
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.