Web Enrollment - No certificate templates could be found

I migrated a Windows 2008 R2 root enterprise CA to Windows 2012 R2.  All looks like its working well except that I cant get Web Enrollment to work.  Upon selecting to submit a certificate request, I get the message:

No certificate templates could be found.  You do not have permission to request a certificate from this CA, or an error occurred while accessing the Active Directory.

Certificate enrollment does work through the Certificates MMC, in fact I was able to create a certificate to secure the CAs Default Web Site.

I have done everything I can find on the Internet to fix this, including:

Any of you seen anything like this and maybe have an idea how to reme

August 21st, 2015 8:41pm

* Bump *

Nobody has anything?

Free Windows Admin Tool Kit Click here and download it now
August 28th, 2015 11:01pm

Hi,

Sorry for the delay.

First, please make sure that the user which you used to logon the web enrollment service has the read and enroll permission on the template.

Secondary, please check if the delegation of the web enrollment service server has been configured in domain controller. We should choose the "Trust this computer for delegation to any service (Kerberos only)".

If it doesn't work, we may enable the audit on the CA server to check the detailed error information about the enrollment failure.

Best Regards.

August 30th, 2015 10:48pm

Thank you for helping, Steven.

The templates in question allow Authenticated Users to Read, Write and Enroll.

I made the delegation change per your second instruction and rebooted the CA server but I still get the same error.

Please advise how I should enable auditing and I'll be happy to do it and report back with anything of interest.

Thanks again!

Free Windows Admin Tool Kit Click here and download it now
August 31st, 2015 1:51am

Hi,

We can enable the audit in the properties of the CA server.

Here is the screenshot of my lab server:

Best Regards.

August 31st, 2015 3:02am

After I enable the auditing, where do I look for the information to post back?
Free Windows Admin Tool Kit Click here and download it now
August 31st, 2015 8:09pm

Hi,

If the CA server receives the request, we can find the event of the enrollment failure in the event log.

Here is a screenshot of my lab:

Best Regards.

September 9th, 2015 10:27pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics