Microsoft-Windows-CertificationAuthority-EnterprisePolicy

EventTitleChannelSampleRule
1113260059Active Directory Certificate Services is configured to use LDAP referrals to …OperationalNN
1113325584The {CertificateTemplateName} Certificate Template was loaded.OperationalNN
1113325585The {CertificateTemplateName} Certificate Template requires …OperationalNN
2187001861The Active Directory Certificate Services Policy contains no valid Certificate …OperationalNN
2187001882Active Directory Certificate Services detected that LDAP referrals are enabled.OperationalNN
2187067399The Enrollee ({EnrolleeName}) has no DNS name registered in the Active …OperationalNN
2187067400The Enrollee ({EnrolleeName}) has no E-Mail name registered in the Active …OperationalNN
2187067405The {CertificateTemplateName} Certificate Template could not be loaded.OperationalNN
2187067411The certificate validity period will be shorter than the …OperationalNN
3260743684Active Directory Certificate Services could not find required Active Directory …OperationalNN
3260743692The Active Directory containing the Certification Authority could not be …OperationalNN
3260743701Initialization failure loading information from the Active Directory containing …OperationalNN
3260743705The requested validity period is invalid.OperationalNN
3260743709The key archival request specified that it should not be persisted in the …OperationalNN
3260809225The Enrollee was not able to successfully authenticate to the Certificate …OperationalNN
3260809226The request was for a certificate template that is not supported by the Active …OperationalNN
3260809227The request does not contain a certificate template extension or the …OperationalNN
3260809230The request specifies conflicting certificate templates: {TemplateNames}.OperationalNN
3260809231The Active Directory connection to {OldDSHostName} has been reestablished to …OperationalNN
3260809234The {CertificateTemplateName} Certificate Template requires the following …OperationalNN
3260809236Renewing a certificate with the {CertificateTemplateName} Certificate Template …OperationalNN
3260809238The requester's Active Directory object is not in the current forest.OperationalNN
3260809239The requester's Active Directory object could not be retrieved.OperationalNN
3260809240Active Directory Certificate Services could not connect to the global catalog …OperationalNN
3260809244An invalid OID has been detected in the EKUOIDsForVolatileRequests configuration …OperationalNN

Event ID 1113260059: Active Directory Certificate Services is configured to use LDAP referrals to request user data from the Active Directory directory service.

#
Channel
Operational

Event ID 1113325584: The {CertificateTemplateName} Certificate Template was loaded.

#
Channel
Operational

Fields #

NameDescription
CertificateTemplateName

Event ID 1113325585: The {CertificateTemplateName} Certificate Template requires {RequiredSignatureCount} signatures; but only {AccepedSignatureCount} were accepted.

#
Channel
Operational

Fields #

NameDescription
CertificateTemplateName
RequiredSignatureCount
AccepedSignatureCount

Event ID 2187001861: The Active Directory Certificate Services Policy contains no valid Certificate Templates.

#
Channel
Operational

Event ID 2187001882: Active Directory Certificate Services detected that LDAP referrals are enabled.

#
Channel
Operational

Message #

Active Directory Certificate Services detected that LDAP referrals are enabled. The current license of Windows does not allow LDAP referrals for Active Directory Certificate Services and this setting will be ignored. To disable LDAP referrals; open a command prompt window; type: certutil -setreg policy\EditFlags -EDITF_ENABLELDAPREFERRALS and press Enter and restart the CA.

Event ID 2187067399: The Enrollee ({EnrolleeName}) has no DNS name registered in the Active Directory.

#
Channel
Operational

Description

The Enrollee ({EnrolleeName}) has no DNS name registered in the Active Directory. The certificate cannot be generated.

Message #

The Enrollee ({EnrolleeName}) has no DNS name registered in the Active Directory. The certificate cannot be generated.

Fields #

NameDescription
EnrolleeName

Event ID 2187067400: The Enrollee ({EnrolleeName}) has no E-Mail name registered in the Active Directory.

#
Channel
Operational

Description

The Enrollee ({EnrolleeName}) has no E-Mail name registered in the Active Directory. The E-Mail name will not be included in the certificate.

Message #

The Enrollee ({EnrolleeName}) has no E-Mail name registered in the Active Directory.  The E-Mail name will not be included in the certificate.

Fields #

NameDescription
EnrolleeName

Event ID 2187067405: The {CertificateTemplateName} Certificate Template could not be loaded.

#
Channel
Operational

Description

The {CertificateTemplateName} Certificate Template could not be loaded. {ErrorCode}.

Message #

The {CertificateTemplateName} Certificate Template could not be loaded.  {ErrorCode}.

Fields #

NameDescription
CertificateTemplateName
ErrorCode

Event ID 2187067411: The certificate validity period will be shorter than the {CertificateTemplateName} Certificate Template specifies; because the template validity pe...

#
Channel
Operational

Message #

The certificate validity period will be shorter than the {CertificateTemplateName} Certificate Template specifies; because the template validity period is longer than the maximum certificate validity period allowed by the CA.  Consider renewing the CA certificate; reducing the template validity period; or increasing the registry validity period.

Fields #

NameDescription
CertificateTemplateName

Event ID 3260743684: Active Directory Certificate Services could not find required Active Directory information.

#
Channel
Operational

Event ID 3260743692: The Active Directory containing the Certification Authority could not be contacted.

#
Channel
Operational

Event ID 3260743701: Initialization failure loading information from the Active Directory containing the Certification Authority.

#
Channel
Operational

Event ID 3260743705: The requested validity period is invalid.

#
Channel
Operational

Message #

The requested validity period is invalid. Confirm that the validity period or expiration date and time specified in the request does not extend beyond the validity period of the CA certificate; the certificate template; and the CA. The validity period of the CA can be verified by running the following commands: certutil -getreg ca\validityPeriod & certutil -getreg ca\ValdityPeriodUnits.

Event ID 3260743709: The key archival request specified that it should not be persisted in the database.

#
Channel
Operational

Description

The key archival request specified that it should not be persisted in the database. Key Archival requests must always be persisted.

Message #

The key archival request specified that it should not be persisted in the database. Key Archival requests must always be persisted.

Event ID 3260809225: The Enrollee was not able to successfully authenticate to the Certificate Service.

#
Channel
Operational

Description

The Enrollee was not able to successfully authenticate to the Certificate Service. Please check your security settings.

Message #

The Enrollee was not able to successfully authenticate to the Certificate Service.  Please check your security settings.

Event ID 3260809226: The request was for a certificate template that is not supported by the Active Directory Certificate Services policy: {CertificateTemplateName}.

#
Channel
Operational

Fields #

NameDescription
CertificateTemplateName

Event ID 3260809227: The request does not contain a certificate template extension or the {RequestAttributeName} request attribute.

#
Channel
Operational

Fields #

NameDescription
RequestAttributeName

Event ID 3260809230: The request specifies conflicting certificate templates: {TemplateNames}.

#
Channel
Operational

Fields #

NameDescription
TemplateNames

Event ID 3260809231: The Active Directory connection to {OldDSHostName} has been reestablished to {NewDSHostName}.

#
Channel
Operational

Fields #

NameDescription
OldDSHostName
NewDSHostName

Event ID 3260809234: The {CertificateTemplateName} Certificate Template requires the following issuance policies that signing certificates did not include: {MissingIssu...

#
Channel
Operational

Description

The {CertificateTemplateName} Certificate Template requires the following issuance policies that signing certificates did not include: {MissingIssuancePolicyOIDsInSigningCertificate}.

Message #

The {CertificateTemplateName} Certificate Template requires the following issuance policies that signing certificates did not include: {MissingIssuancePolicyOIDsInSigningCertificate}.

Fields #

NameDescription
CertificateTemplateName
MissingIssuancePolicyOIDsInSigningCertificate

Event ID 3260809236: Renewing a certificate with the {CertificateTemplateName} Certificate Template failed because the renewal overlap period is longer than the certifi...

#
Channel
Operational

Description

Renewing a certificate with the {CertificateTemplateName} Certificate Template failed because the renewal overlap period is longer than the certificate validity period.

Message #

Renewing a certificate with the {CertificateTemplateName} Certificate Template failed because the renewal overlap period is longer than the certificate validity period.

Fields #

NameDescription
CertificateTemplateName

Event ID 3260809238: The requester's Active Directory object is not in the current forest.

#
Channel
Operational

Description

The requester's Active Directory object is not in the current forest. Cross forest enrollment is not enabled. {RequesterName} {ErrorCode}.

Message #

The requester's Active Directory object is not in the current forest.  Cross forest enrollment is not enabled.  {RequesterName}  {ErrorCode}

Fields #

NameDescription
RequesterName
ErrorCode

Event ID 3260809239: The requester's Active Directory object could not be retrieved.

#
Channel
Operational

Description

The requester's Active Directory object could not be retrieved. {RequesterName} {ErrorCode}.

Message #

The requester's Active Directory object could not be retrieved.  {RequesterName}  {ErrorCode}

Fields #

NameDescription
RequesterName
ErrorCode

Event ID 3260809240: Active Directory Certificate Services could not connect to the global catalog server.

#
Channel
Operational

Description

Active Directory Certificate Services could not connect to the global catalog server. {RequesterName} {ErrorCode}.

Message #

Active Directory Certificate Services could not connect to the global catalog server.  {RequesterName}  {ErrorCode}

Fields #

NameDescription
RequesterName
ErrorCode

Event ID 3260809244: An invalid OID has been detected in the EKUOIDsForVolatileRequests configuration setting.

#
Channel
Operational

Message #

An invalid OID has been detected in the EKUOIDsForVolatileRequests configuration setting. To resolve; run: 'certutil -getreg policy\EKUOIDsForVolatileRequests' to identify the invalid OID and correct it.