Domain Controller Authentication Certificate Template Not Available
The templates are the.
Domain controller authentication certificate template not available. Hard coded in this case means it is in the code it is not configured in any local or domain based policy. To unpublish a certificate template right click the certificate template you want to unpublish in the details pane of the certificate authority console and select delete. It uses radius authentication.
If the domain controller certificate template is not. This is one of the few cases where windows will auto enroll for a certificate without auto enrollment being configured in group policy. If you published the domain controller authentication kerberos certificate template then you should unpublish the certificate templates you included in the superseded templates list.
The non domain member server and the clients that must be able to communicate with it must be configured to use cryptographic certificates based on the x 509 standard. These certificates can be used as an alternate set of credentials. Life is short enjoy it now.
We tried to renew it off of a template that was available but it failed with an expiration message. Sign in to vote. Reply quote answers text html 12 12 2012 9 32 47 am cicely feng 0.
All domain controllers are hard coded to automatically enroll for a certificate based on the domain controller template if it is available for enrollment at a certificate authority in the forest. However certificates based on the domain controller and domain controller authentication certificate templates do not include the kdc authentication object identifier oid which was later added to the kerberos rfc. After some digging we found in our nps that our certificate had expired.
Moved by cicely feng moderator wednesday december 12 2012 9 33 am from directory services tuesday december 11 2012 10 34 pm. Certificate template requires multiple 2 or more registration authority ra signatures in the issuance requirements tab. Domain controller windows server 2000 domain controller authentication windows server 2003 kerberos authentication windows server 2008 and above our modern domain controllers can use any one these 3 certificate templates however we really want your dc s to be using the kerberos authentication template.