Hello markgreen-2670,
Thank you for posting in our Q&A forum.
The issue may caused by port mostly, please check if all ports that AD CS needed is open on client and CA server, including AD DS ports.
Certificate Services relies on RPC and DCOM to communicate with clients by using random TCP ports that are higher than port 1024.
RPC TCP 135
SMB TCP 445, 139
Randomly allocated high TCP ports
TCP random port number between 1024 - 65535
random port number between 49152 - 65535
For more information about AD CD ports, please read the links below.
Best Regards,
Daisy Zhou
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.