Certificate template not showing

bizcntradmin 191 Reputation points
2020-09-16T09:52:33.62+00:00

Hi Guys,

I have migrated my 2 tier PKI from Windows Server 2012 r2 to Windows Server 2019. Evrything is good except certificate templates are missing. When i check the container in AD sites and services the list of certificate templates is still there, is there a way to make it appear in certificate authority.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,244 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Daisy Zhou 21,361 Reputation points Microsoft Vendor
    2020-09-17T03:54:00.183+00:00

    Hello @bizcntradmin ,

    Thank you for posting here.

    Based on the description, do you mean all the certificate templates are missing or only custom certificate templates are missing when issue certificate templates?

    If all the certificate templates are missing, we can open certificate ttemplate console and check the certificate templates are stored on which DC (if you have one than one DC in the domain).

    For example,

    Here is stored on DC named 2012R2.

    25307-dc.png

    If we connected to another DC, we can see all the certificate templates, maybe there is issue about AD replication.
    25386-dc1.png

    We can whether check AD replication is working fine. On one DC and run repadmin /replsum and repadmin /showrepl * /csv >C:\showrepl.csv to check the there is any issue about AD replication (if there is no any error message, then AD replication is working fine).

    If we mean only custom certificate templates are missing when issue certificate templates. We can check if the "flags" below is 10 or not.

    ADSI\Configuration\Services\Public Key Services\Enrollment Services\right sub CA name->Properties->flags.

    25364-dc2.png

    Hope the information above is helpful. If anything is unclear, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    2 people found this answer helpful.

  2. Thameur-BOURBITA 32,641 Reputation points
    2020-09-16T21:58:58.553+00:00

    Hi,

    The certificate template created through enterprise PKI is saved on configuration partition in the forest level and , it replicated on all domain controllers in the forest. There is no certificate template in AD site level.
    There is no sense to talk about move certificate template from AD site to PKI.

    Please don't forget to mark this reply as answer if it help your to fix your issue

    0 comments No comments

  3. Marlon De Paz 0 Reputation points
    2023-01-18T03:55:09.7833333+00:00

    User's image

    I can't find the Certificate Template here. Anyone can help us on this. Thank you in advance.