Internal CA not assigning a Certificate to a wifi device

create share 676 Reputation points
2022-01-09T23:00:49.553+00:00

Hi,

How can we troubleshoot if some laptop devices are not able to get certificates for wifi connectivity from an Internal CA and some are able to get even though they are having the same policies and in the same active directory security group?

Thanks.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 39,931 Reputation points
    2022-01-11T09:24:29.897+00:00

    Hi there,

    Here are some points to check first.

    -Check whether the machine has configured certificate auto-enrollment GPO.
    -Check whether the certificate template is issued on the CA server.
    -Check whether the machine has read, enroll and autoenroll permissions for this certificate template.

    If it does not work above, because certificate templates are stored on DCs, not CA server, please check AD replication is working fine by running repadmin /showrepl and repadmin /replsum.

    Here is a thread as well which discusses the same issue and you can try out some troubleshooting steps from this and see if that helps you to sort the Issue.
    https://learn.microsoft.com/en-us/answers/questions/84204/computer-certificate-autoenrollment-not-working.html

    Troubleshooting SSL related issues (Server Certificate)
    https://learn.microsoft.com/en-us/iis/troubleshoot/security-issues/troubleshooting-ssl-related-issues-server-certificate

    --------------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept it as an answer--

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.