Microsoft-Windows-CertificationAuthority
355 events across 2 channels
Event ID 5: Active Directory Certificate Services could not find required registry information.
#Description
Active Directory Certificate Services could not find required registry information. The Active Directory Certificate Services may need to be reinstalled.
Message #
Event ID 5: Active Directory Certificate Services could not find required registry information
#Description
Active Directory Certificate Services could not find required registry information. The Active Directory Certificate Services may need to be reinstalled.
Event ID 6: Active Directory Certificate Services issued a certificate for request RequestId for SubjectName.
#Event ID 6: Active Directory Certificate Services issued a certificate for request RequestId for
#Description
Active Directory Certificate Services issued a certificate for request for .
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
SubjectName UnicodeString |
Event ID 7: Active Directory Certificate Services denied request RequestId because Reason.
#Event ID 7: Active Directory Certificate Services denied request RequestId because
#Description
Active Directory Certificate Services denied request because . The request was for .
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
Reason UnicodeString | |
SubjectName UnicodeString |
Event ID 8: Active Directory Certificate Services left request RequestId pending in the queue for SubjectName.
#Event ID 8: Active Directory Certificate Services left request RequestId pending in the queue for
#Description
Active Directory Certificate Services left request pending in the queue for .
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
SubjectName UnicodeString |
Event ID 9: The Active Directory Certificate Services did not start: Unable to load an external policy module.
#Description
The Active Directory Certificate Services did not start: Unable to load an external policy module.
Message #
Event ID 9: The Active Directory Certificate Services did not start: Unable to load an external policy module
#Description
The Active Directory Certificate Services did not start: Unable to load an external policy module.
Event ID 10: Active Directory Certificate Services were unable to build a new certificate or certificate chain: ErrorCode.
#Event ID 10: Active Directory Certificate Services were unable to build a new certificate or certificate chain:
#Description
Active Directory Certificate Services were unable to build a new certificate or certificate chain: .
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 15: Active Directory Certificate Services did not start: Version does not match certif.
#Description
Active Directory Certificate Services did not start: Version does not match certif.dll.
Message #
Event ID 15: Active Directory Certificate Services did not start: Version does not match certif
#Description
Active Directory Certificate Services did not start: Version does not match certif.dll.
Event ID 16: Active Directory Certificate Services did not start: Unable to initialize OLE: ErrorCode.
#Event ID 16: Active Directory Certificate Services did not start: Unable to initialize OLE:
#Description
Active Directory Certificate Services did not start: Unable to initialize OLE: .
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 17: Active Directory Certificate Services did not start: Unable to initialize the database connection for Name.
#Description
Active Directory Certificate Services did not start: Unable to initialize the database connection for Name. CACommonName.
Message #
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"guid": "6A71D062-9AFE-4F35-AD08-52134F85DFB9",
"event_source_name": "",
"event_id": 17,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T23:06:28.978789+00:00",
"event_record_id": 4237,
"correlation": {},
"execution": {
"process_id": 13508,
"thread_id": 10540
},
"channel": "Application",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "MSG_E_DB_INIT_FAILED",
"CACommonName": "EvtGen-Root-CA",
"ErrorCode": "Certificate service has been suspended for a database restore operation. 0x80094006 (-2146877434 CERTSRV_E_SERVER_SUSPENDED)"
},
"message": ""
}
Event ID 17: Active Directory Certificate Services did not start: Unable to initialize the database connection for
#Description
Active Directory Certificate Services did not start: Unable to initialize the database connection for . .
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 17,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:06:28.9787899+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"ErrorCode": "Certificate service has been suspended for a database restore operation. 0x80094006 (-2146877434 CERTSRV_E_SERVER_SUSPENDED)",
"CACommonName": "EvtGen-Root-CA"
}
}
Event ID 19: Active Directory Certificate Services did not start: The Subject Name Template string in the registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentContro...
#Description
Active Directory Certificate Services did not start: The Subject Name Template string in the registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\CACommonName\SubjectTemplate is invalid. An example of a valid string is: CommonName OrganizationalUnit Organization Locality State Country
Message #
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString |
Event ID 19: Active Directory Certificate Services did not start: The Subject Name Template string in the registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\CACommonName\S...
#Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString |
Event ID 20: Active Directory Certificate Services did not start: The Certificate Date Validity Period string in the registry value HKEY_LOCAL_MACHINE\SYSTEM\Cu...
#Description
Active Directory Certificate Services did not start: The Certificate Date Validity Period string in the registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\CACommonName\ValidityPeriod is invalid. Valid strings are "Seconds", "Minutes", "Hours", "Days", "Weeks", "Months" and "Years".
Message #
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString |
Event ID 20: Active Directory Certificate Services did not start: The Certificate Date Validity Period string in the registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\CAC...
#Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString |
Event ID 21: Active Directory Certificate Services could not process request Name due to an error: RequestId.
#Description
Active Directory Certificate Services could not process request Name due to an error: RequestId. The request was for ErrorCode.
Message #
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
ErrorCode UnicodeString | |
SubjectName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"guid": "6A71D062-9AFE-4F35-AD08-52134F85DFB9",
"event_source_name": "",
"event_id": 21,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T20:24:03.969860+00:00",
"event_record_id": 3714,
"correlation": {},
"execution": {
"process_id": 9432,
"thread_id": 6164
},
"channel": "Application",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "MSG_E_PROCESS_REQUEST_FAILED",
"RequestId": "1",
"ErrorCode": "The request's current status does not allow this operation. 0x80094003 (-2146877437 CERTSRV_E_BAD_REQUESTSTATUS)",
"SubjectName": "CN=EvtGen-Root-CA, DC=ludus, DC=domain"
},
"message": ""
}
Event ID 21: Active Directory Certificate Services could not process request RequestId due to an error:
#Description
Active Directory Certificate Services could not process request due to an error: . The request was for .
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
ErrorCode UnicodeString | |
SubjectName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 21,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T20:24:03.9698601+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"ErrorCode": "The request's current status does not allow this operation. 0x80094003 (-2146877437 CERTSRV_E_BAD_REQUESTSTATUS)",
"SubjectName": "CN=EvtGen-Root-CA, DC=ludus, DC=domain",
"RequestId": "1"
}
}
Event ID 22: Active Directory Certificate Services could not process request RequestId due to an error: ErrorCode.
#Description
Active Directory Certificate Services could not process request RequestId due to an error: ErrorCode. The request was for SubjectName. Additional information: AdditionalInformation.
Message #
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
ErrorCode UnicodeString | |
SubjectName UnicodeString | |
AdditionalInformation UnicodeString |
Event ID 22: Active Directory Certificate Services could not process request RequestId due to an error:
#Description
Active Directory Certificate Services could not process request due to an error: . The request was for . Additional information.
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
ErrorCode UnicodeString | |
SubjectName UnicodeString | |
AdditionalInformation UnicodeString |
Event ID 23: Active Directory Certificate Services could not process request RequestId due to an error: ErrorCode.
#Description
Active Directory Certificate Services could not process request RequestId due to an error: ErrorCode. The request was for SubjectName. The certificate would contain an encoded length that is potentially incompatible with older enrollment software. Submit a new request using different length input data for the following field: Field
Message #
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
ErrorCode UnicodeString | |
SubjectName UnicodeString | |
Field UnicodeString |
Event ID 23: Active Directory Certificate Services could not process request RequestId due to an error:
#Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
ErrorCode UnicodeString | |
SubjectName UnicodeString | |
Field UnicodeString |
Event ID 25: Active Directory Certificate Services revoked the certificate for request RequestId for SubjectName.
#Event ID 25: Active Directory Certificate Services revoked the certificate for request RequestId for
#Description
Active Directory Certificate Services revoked the certificate for request for .
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
SubjectName UnicodeString |
Event ID 26: Active Directory Certificate Services for Name was started.
#Description
Active Directory Certificate Services for Name was started.CACommonNameDCSpecifier.
Message #
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
DCSpecifier UnicodeString | |
DCName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"guid": "6A71D062-9AFE-4F35-AD08-52134F85DFB9",
"event_source_name": "",
"event_id": 26,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T20:16:52.465174+00:00",
"event_record_id": 3703,
"correlation": {},
"execution": {
"process_id": 9432,
"thread_id": 1156
},
"channel": "Application",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "MSG_I_SERVER_STARTED",
"CACommonName": "EvtGen-Root-CA",
"DCSpecifier": " DC=",
"DCName": "LAB-DC01.ludus.domain"
},
"message": ""
}
Event ID 26: Active Directory Certificate Services for CACommonName was started
#Description
Active Directory Certificate Services for was started.
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
DCSpecifier UnicodeString | |
DCName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 26,
"level": 4,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T20:16:52.4651741+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"DCName": "JD-DC01-2022.ludus.domain",
"CACommonName": "EvtGen-Root-CA",
"DCSpecifier": " DC="
}
}
Event ID 27: Active Directory Certificate Services did not start: Hierarchical setup is incomplete.
#Description
Active Directory Certificate Services did not start: Hierarchical setup is incomplete. Use the request file in RequestFileName.req to obtain a certificate for this Certificate Server, and use the Certification Authority administration tool to install the new certificate and complete the installation.
Message #
Fields #
| Name | Description |
|---|---|
RequestFileName UnicodeString |
Event ID 27: Active Directory Certificate Services did not start: Hierarchical setup is incomplete
#Fields #
| Name | Description |
|---|---|
RequestFileName UnicodeString |
Event ID 33: Active Directory Certificate Services did not start: Could not create the Certificate Server service thread for CACommonName.
#Event ID 33: Active Directory Certificate Services did not start: Could not create the Certificate Server service thread for
#Description
Active Directory Certificate Services did not start: Could not create the Certificate Server service thread for . .
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString |
Event ID 34: Active Directory Certificate Services did not start: Could not initialize RPC for CACommonName.
#Event ID 34: Active Directory Certificate Services did not start: Could not initialize RPC for
#Description
Active Directory Certificate Services did not start: Could not initialize RPC for . .
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString |
Event ID 35: Active Directory Certificate Services did not start: Could not initialize OLE for CACommonName.
#Event ID 35: Active Directory Certificate Services did not start: Could not initialize OLE for
#Description
Active Directory Certificate Services did not start: Could not initialize OLE for . .
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString |
Event ID 38: Active Directory Certificate Services for Name was stopped.
#Description
Active Directory Certificate Services for Name was stopped.
Message #
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"guid": "6A71D062-9AFE-4F35-AD08-52134F85DFB9",
"event_source_name": "",
"event_id": 38,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T23:05:17.631827+00:00",
"event_record_id": 4209,
"correlation": {},
"execution": {
"process_id": 3920,
"thread_id": 3924
},
"channel": "Application",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "MSG_I_SERVER_STOPPED",
"CACommonName": "EvtGen-Root-CA"
},
"message": ""
}
Event ID 38: Active Directory Certificate Services for CACommonName was stopped
#Description
Active Directory Certificate Services for was stopped.
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 38,
"level": 4,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:05:17.6318277+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"CACommonName": "EvtGen-Root-CA"
}
}
Event ID 39: Active Directory Certificate Services did not start: The Certification Authority DCOM class for CACommonName could not be registered.
#Description
Active Directory Certificate Services did not start: The Certification Authority DCOM class for CACommonName could not be registered. ErrorCode. Use the services administration tool to change the Certification Authority logon context.
Message #
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"guid": "{6a71d062-9afe-4f35-ad08-52134f85dfb9}",
"event_source_name": "",
"event_id": 39,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-05-09 21:22:34.260563+00:00",
"event_record_id": 4803,
"correlation": {
"ActivityID": "",
"RelatedActivityID": ""
},
"execution": {
"process_id": 9476,
"thread_id": 8968
},
"channel": "Application",
"computer": "EX-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"CACommonName": "ludus-CA",
"ErrorCode": "The class is configured to run as a security id different from the caller 0x80004015 (-2147467243 CO_E_WRONG_SERVER_IDENTITY)"
},
"message": ""
}
Event ID 39: Active Directory Certificate Services did not start: The Certification Authority DCOM class for CACommonName could not be registered
#Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString |
Event ID 40: Active Directory Certificate Services did not start: Could not initialize DCOM class factories for CACommonName.
#Event ID 40: Active Directory Certificate Services did not start: Could not initialize DCOM class factories for
#Description
Active Directory Certificate Services did not start: Could not initialize DCOM class factories for . .
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString |
Event ID 42: Could not build a certificate chain for CA certificate CACertIdentifier for CACommonName.
#Event ID 42: Could not build a certificate chain for CA certificate CACertIdentifier for
#Description
Could not build a certificate chain for CA certificate for . .
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString | |
CACertIdentifier UnicodeString |
Event ID 43: The "PolicyModuleDescription" Policy Module "MethodName" method caused an exception at address ExceptionAddress.
#Description
The "PolicyModuleDescription" Policy Module "MethodName" method caused an exception at address ExceptionAddress. The exception code is ExceptionCode.
Message #
Fields #
| Name | Description |
|---|---|
PolicyModuleDescription UnicodeString | |
MethodName UnicodeString | |
ExceptionCode UnicodeString | |
ExceptionAddress UnicodeString |
Event ID 43: The "PolicyModuleDescription" Policy Module "MethodName" method caused an exception at address
#Description
The "PolicyModuleDescription" Policy Module "MethodName" method caused an exception at address ExceptionAddress. The exception code is ExceptionCode.
Fields #
| Name | Description |
|---|---|
PolicyModuleDescription UnicodeString | |
MethodName UnicodeString | |
ExceptionCode UnicodeString | |
ExceptionAddress UnicodeString |
Event ID 44: The "Name" Policy Module "PolicyModuleDescription" method returned an error.
#Description
The "Name" Policy Module "PolicyModuleDescription" method returned an error. param4 The returned status code is MethodName. ErrorCode.
Message #
Fields #
| Name | Description |
|---|---|
PolicyModuleDescription UnicodeString | |
MethodName UnicodeString | |
ErrorCode UnicodeString | |
param4 UnicodeString | |
ErrorString UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"guid": "6A71D062-9AFE-4F35-AD08-52134F85DFB9",
"event_source_name": "",
"event_id": 44,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T21:48:47.682649+00:00",
"event_record_id": 3798,
"correlation": {},
"execution": {
"process_id": 3920,
"thread_id": 3924
},
"channel": "Application",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "MSG_E_POLICY_ERROR",
"PolicyModuleDescription": "Windows default",
"MethodName": "Initialize",
"ErrorCode": "0x8007054b (1355)",
"param4": "The Active Directory containing the Certification Authority could not be contacted.\r\n",
"ErrorString": "The specified domain either does not exist or could not be contacted."
},
"message": ""
}
Event ID 44: The "PolicyModuleDescription" Policy Module "MethodName" method returned an error
#Description
The "PolicyModuleDescription" Policy Module "MethodName" method returned an error. ErrorString The returned status code is ErrorCode. param4.
Fields #
| Name | Description |
|---|---|
PolicyModuleDescription UnicodeString | |
MethodName UnicodeString | |
ErrorCode UnicodeString | |
param4 UnicodeString | |
ErrorString UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 44,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T21:48:47.6826498+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"ErrorCode": "0x8007054b (1355)",
"MethodName": "Initialize",
"ErrorString": "The specified domain either does not exist or could not be contacted.",
"param4": "The Active Directory containing the Certification Authority could not be contacted.\n",
"PolicyModuleDescription": "Windows default"
}
}
Event ID 45: The "ExitModuleDescription" Exit Module "MethodName" method caused an exception at address ExceptionAddress.
#Description
The "ExitModuleDescription" Exit Module "MethodName" method caused an exception at address ExceptionAddress. The exception code is ExceptionCode.
Message #
Fields #
| Name | Description |
|---|---|
ExitModuleDescription UnicodeString | |
MethodName UnicodeString | |
ExceptionCode UnicodeString | |
ExceptionAddress UnicodeString |
Event ID 45: The "ExitModuleDescription" Exit Module "MethodName" method caused an exception at address
#Description
The "ExitModuleDescription" Exit Module "MethodName" method caused an exception at address ExceptionAddress. The exception code is ExceptionCode.
Fields #
| Name | Description |
|---|---|
ExitModuleDescription UnicodeString | |
MethodName UnicodeString | |
ExceptionCode UnicodeString | |
ExceptionAddress UnicodeString |
Event ID 46: The "ExitModuleDescription" Exit Module "MethodName" method returned an error.
#Description
The "ExitModuleDescription" Exit Module "MethodName" method returned an error. ErrorString The returned status code is ErrorCode. param4.
Message #
Fields #
| Name | Description |
|---|---|
ExitModuleDescription UnicodeString | |
MethodName UnicodeString | |
ErrorCode UnicodeString | |
param4 UnicodeString | |
ErrorString UnicodeString |
Event ID 46: The "ExitModuleDescription" Exit Module "MethodName" method returned an error
#Description
The "ExitModuleDescription" Exit Module "MethodName" method returned an error. ErrorString The returned status code is ErrorCode. param4.
Fields #
| Name | Description |
|---|---|
ExitModuleDescription UnicodeString | |
MethodName UnicodeString | |
ErrorCode UnicodeString | |
param4 UnicodeString | |
ErrorString UnicodeString |
Event ID 48: Revocation status for a certificate in the chain for CA certificate CACertIdentifier for CACommonName could not be verified because a server is currently unavailable.
#Event ID 48: Revocation status for a certificate in the chain for CA certificate CACertIdentifier for CACommonName could not be verified because a server is currently unavailable
#Description
Revocation status for a certificate in the chain for CA certificate for could not be verified because a server is currently unavailable. .
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString | |
CACertIdentifier UnicodeString |
Event ID 49: A certificate in the chain for CA certificate CACertIdentifier for CACommonName could not be verified because no information is available describing how to check the revoc...
#Description
A certificate in the chain for CA certificate CACertIdentifier for CACommonName could not be verified because no information is available describing how to check the revocation status. ErrorCode.
Message #
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString | |
CACertIdentifier UnicodeString |
Event ID 49: A certificate in the chain for CA certificate CACertIdentifier for CACommonName could not be verified because no information is available describing how to check the revocation status
#Description
A certificate in the chain for CA certificate for could not be verified because no information is available describing how to check the revocation status. .
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString | |
CACertIdentifier UnicodeString |
Event ID 51: A certificate in the chain for CA certificate CACertIdentifier for CACommonName has been revoked.
#Event ID 51: A certificate in the chain for CA certificate CACertIdentifier for CACommonName has been revoked
#Description
A certificate in the chain for CA certificate for has been revoked. .
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString | |
CACertIdentifier UnicodeString |
Event ID 52: Active Directory Certificate Services issued a certificate for request RequestId for SubjectName.
#Event ID 52: Active Directory Certificate Services issued a certificate for request RequestId for
#Description
Active Directory Certificate Services issued a certificate for request for . Additional information.
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
SubjectName UnicodeString | |
AdditionalInformation UnicodeString |
Event ID 53: Active Directory Certificate Services denied request Name because RequestId.
#Description
Active Directory Certificate Services denied request Name because RequestId. The request was for Reason. Additional information: SubjectName.
Message #
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
Reason UnicodeString | |
SubjectName UnicodeString | |
AdditionalInformation UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"guid": "6A71D062-9AFE-4F35-AD08-52134F85DFB9",
"event_source_name": "",
"event_id": 53,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T20:16:58.388339+00:00",
"event_record_id": 3704,
"correlation": {},
"execution": {
"process_id": 9432,
"thread_id": 10184
},
"channel": "Application",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "MSG_DN_CERT_DENIED_WITH_INFO",
"RequestId": "2",
"Reason": "The request contains no certificate template information. 0x80094801 (-2146875391 CERTSRV_E_NO_CERT_TYPE)",
"SubjectName": "CN=EvtGenTestCert, O=Test, L=Test, S=Test, C=US",
"AdditionalInformation": "Denied by Policy Module 0x80094801, The request does not contain a certificate template extension or the CertificateTemplate request attribute.\r\n"
},
"message": ""
}
Detection Rules #
View all rules referencing this event →Sigma # view in coverage
Event ID 53: Active Directory Certificate Services denied request RequestId because
#Description
Active Directory Certificate Services denied request because . The request was for . Additional information.
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
Reason UnicodeString | |
SubjectName UnicodeString | |
AdditionalInformation UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 53,
"level": 3,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T20:16:58.3883392+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"AdditionalInformation": "Denied by Policy Module 0x80094801, The request does not contain a certificate template extension or the CertificateTemplate request attribute.\n",
"Reason": "The request contains no certificate template information. 0x80094801 (-2146875391 CERTSRV_E_NO_CERT_TYPE)",
"SubjectName": "CN=EvtGenTestCert, O=Test, L=Test, S=Test, C=US",
"RequestId": "2"
}
}
Detection Rules #
View all rules referencing this event →Sigma # view in coverage
Event ID 54: Active Directory Certificate Services left request RequestId pending in the queue for SubjectName.
#Event ID 54: Active Directory Certificate Services left request RequestId pending in the queue for
#Description
Active Directory Certificate Services left request pending in the queue for . Additional information.
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
SubjectName UnicodeString | |
AdditionalInformation UnicodeString |
Event ID 56: Active Directory Certificate Services denied request RequestId.
#Event ID 56: Active Directory Certificate Services denied request
#Description
Active Directory Certificate Services denied request . The request was for .
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
SubjectName UnicodeString |
Event ID 57: Active Directory Certificate Services denied request RequestId.
#Event ID 57: Active Directory Certificate Services denied request
#Description
Active Directory Certificate Services denied request . The request was for . Additional information.
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
SubjectName UnicodeString | |
AdditionalInformation UnicodeString |
Event ID 58: A certificate in the chain for CA certificate CACertIdentifier for CACommonName has expired.
#Event ID 58: A certificate in the chain for CA certificate CACertIdentifier for CACommonName has expired
#Description
A certificate in the chain for CA certificate for has expired. .
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString | |
CACertIdentifier UnicodeString |
Event ID 59: Active Directory Certificate Services did not start: Could not connect to the Active Directory for CACommonName.
#Event ID 59: Active Directory Certificate Services did not start: Could not connect to the Active Directory for
#Description
Active Directory Certificate Services did not start: Could not connect to the Active Directory for . .
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString |
Event ID 60: Active Directory Certificate Services refused to process an extremely long request from SubjectName.
#Description
Active Directory Certificate Services refused to process an extremely long request from SubjectName. This may indicate a denial-of-service attack. If the request was rejected in error, modify the MaxIncomingMessageSize registry parameter via certutil -setreg CA\MaxIncomingMessageSize <bytes>. Unless verbose logging is enabled, this error will not be logged again for 20 minutes.
Message #
Fields #
| Name | Description |
|---|---|
SubjectName UnicodeString |
Event ID 60: Active Directory Certificate Services refused to process an extremely long request from
#Fields #
| Name | Description |
|---|---|
SubjectName UnicodeString |
Event ID 62: Active Directory Certificate Services had problems loading valid CRL publication values and has reset the CRL publication to its default settings.
#Description
Active Directory Certificate Services had problems loading valid CRL publication values and has reset the CRL publication to its default settings.
Message #
Event ID 62: Active Directory Certificate Services had problems loading valid CRL publication values and has reset the CRL publication to its default settings
#Description
Active Directory Certificate Services had problems loading valid CRL publication values and has reset the CRL publication to its default settings.
Event ID 63: Active Directory Certificate Services did not start: CACommonName ErrorCode.
#Event ID 63: Active Directory Certificate Services did not start: CACommonName
#Description
Active Directory Certificate Services did not start: .
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString |
Event ID 64: Active Directory Certificate Services cannot publish enrollment access changes to Active Directory.
#Description
Active Directory Certificate Services cannot publish enrollment access changes to Active Directory.
Message #
Event ID 64: Active Directory Certificate Services cannot publish enrollment access changes to Active Directory
#Description
Active Directory Certificate Services cannot publish enrollment access changes to Active Directory.
Event ID 65: Active Directory Certificate Services could not publish a Base CRL for key Name to the following location: CAKeyIdentifier.
#Description
Active Directory Certificate Services could not publish a Base CRL for key Name to the following location: CAKeyIdentifier. URL.param4param5.
Message #
Fields #
| Name | Description |
|---|---|
CAKeyIdentifier UnicodeString | |
URL UnicodeString | |
ErrorMessageText UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
AdditionalErrorMessage UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"guid": "6A71D062-9AFE-4F35-AD08-52134F85DFB9",
"event_source_name": "",
"event_id": 65,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T23:06:22.153985+00:00",
"event_record_id": 4222,
"correlation": {},
"execution": {
"process_id": 13036,
"thread_id": 13344
},
"channel": "Application",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "MSG_E_BASE_CRL_PUBLICATION",
"CAKeyIdentifier": "0",
"URL": "http://crl.ludus.domain/crldist/EvtGen-Root-CA.crl",
"ErrorMessageText": "The specified path is invalid. 0x800700a1 (WIN32/HTTP: 161 ERROR_BAD_PATHNAME)",
"param4": "",
"param5": "",
"AdditionalErrorMessage": ""
},
"message": ""
}
Event ID 65: Active Directory Certificate Services could not publish a Base CRL for key CAKeyIdentifier to the following location:
#Description
Active Directory Certificate Services could not publish a Base CRL for key to the following location: . .
Fields #
| Name | Description |
|---|---|
CAKeyIdentifier UnicodeString | |
URL UnicodeString | |
ErrorMessageText UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
AdditionalErrorMessage UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 65,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:06:22.1539855+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"URL": "http://crl.ludus.domain/crldist/EvtGen-Root-CA.crl",
"AdditionalErrorMessage": "",
"param4": "",
"ErrorMessageText": "The specified path is invalid. 0x800700a1 (WIN32/HTTP: 161 ERROR_BAD_PATHNAME)",
"CAKeyIdentifier": "0",
"param5": ""
}
}
Event ID 66: Active Directory Certificate Services could not publish a Delta CRL for key CAKeyIdentifier to the following location: URL.
#Description
Active Directory Certificate Services could not publish a Delta CRL for key CAKeyIdentifier to the following location: URL. ErrorMessageText.param5AdditionalErrorMessage.
Message #
Fields #
| Name | Description |
|---|---|
CAKeyIdentifier UnicodeString | |
URL UnicodeString | |
ErrorMessageText UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
AdditionalErrorMessage UnicodeString |
Event ID 66: Active Directory Certificate Services could not publish a Delta CRL for key CAKeyIdentifier to the following location:
#Description
Active Directory Certificate Services could not publish a Delta CRL for key to the following location: . .
Fields #
| Name | Description |
|---|---|
CAKeyIdentifier UnicodeString | |
URL UnicodeString | |
ErrorMessageText UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
AdditionalErrorMessage UnicodeString |
Event ID 67: Active Directory Certificate Services made NumberOfAttempts attempts to publish a CRL and will stop publishing attempts until the next CRL is generated.
#Event ID 67: Active Directory Certificate Services made NumberOfAttempts attempts to publish a CRL and will stop publishing attempts until the next CRL is generated
#Description
Active Directory Certificate Services made attempts to publish a CRL and will stop publishing attempts until the next CRL is generated.
Fields #
| Name | Description |
|---|---|
NumberOfAttempts UnicodeString |
Event ID 68: Active Directory Certificate Services successfully published Base CRL(s).
#Description
Active Directory Certificate Services successfully published Base CRL(s).
Message #
Event ID 68: Active Directory Certificate Services successfully published Base CRL(s)
#Description
Active Directory Certificate Services successfully published Base CRL(s).
Event ID 69: Active Directory Certificate Services successfully published Delta CRL(s).
#Description
Active Directory Certificate Services successfully published Delta CRL(s).
Message #
Event ID 69: Active Directory Certificate Services successfully published Delta CRL(s)
#Description
Active Directory Certificate Services successfully published Delta CRL(s).
Event ID 70: Active Directory Certificate Services successfully published Base and Delta CRL(s).
#Description
Active Directory Certificate Services successfully published Base and Delta CRL(s).
Message #
Event ID 70: Active Directory Certificate Services successfully published Base and Delta CRL(s)
#Description
Active Directory Certificate Services successfully published Base and Delta CRL(s).
Event ID 71: Active Directory Certificate Services successfully published Base CRL(s) to server HostName.
#Event ID 71: Active Directory Certificate Services successfully published Base CRL(s) to server
#Description
Active Directory Certificate Services successfully published Base CRL(s) to server .
Fields #
| Name | Description |
|---|---|
HostName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"guid": "{6A71D062-9AFE-4F35-AD08-52134F85DFB9}",
"event_source_name": "",
"event_id": 71,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-05-30T01:38:44.6100892+00:00",
"event_record_id": 253121,
"correlation": {
"ActivityID": "{A34AE51E-3B5A-4697-B3E5-8B64042E4293}"
},
"execution": {
"process_id": 13200,
"thread_id": 11308
},
"channel": "Application",
"computer": "JD-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"HostName": "JD-DC01-2022.ludus.domain"
},
"message": "Active Directory Certificate Services successfully published Base CRL(s) to server JD-DC01-2022.ludus.domain."
}
Event ID 72: Active Directory Certificate Services successfully published Delta CRL(s) to server HostName.
#Event ID 72: Active Directory Certificate Services successfully published Delta CRL(s) to server
#Description
Active Directory Certificate Services successfully published Delta CRL(s) to server .
Fields #
| Name | Description |
|---|---|
HostName UnicodeString |
Event ID 73: Active Directory Certificate Services successfully published Base and Delta CRL(s) to server HostName.
#Event ID 73: Active Directory Certificate Services successfully published Base and Delta CRL(s) to server
#Description
Active Directory Certificate Services successfully published Base and Delta CRL(s) to server .
Fields #
| Name | Description |
|---|---|
HostName UnicodeString |
Event ID 74: Active Directory Certificate Services could not publish a Base CRL for key CAKeyIdentifier to the following location on server HostName: URL.
#Description
Active Directory Certificate Services could not publish a Base CRL for key CAKeyIdentifier to the following location on server HostName: URL. ErrorMessageText.param5AdditionalErrorMessage.
Message #
Fields #
| Name | Description |
|---|---|
CAKeyIdentifier UnicodeString | |
URL UnicodeString | |
ErrorMessageText UnicodeString | |
HostName UnicodeString | |
param5 UnicodeString | |
AdditionalErrorMessage UnicodeString |
Event ID 74: Active Directory Certificate Services could not publish a Base CRL for key CAKeyIdentifier to the following location on server HostName:
#Description
Active Directory Certificate Services could not publish a Base CRL for key to the following location on server : . .
Fields #
| Name | Description |
|---|---|
CAKeyIdentifier UnicodeString | |
URL UnicodeString | |
ErrorMessageText UnicodeString | |
HostName UnicodeString | |
param5 UnicodeString | |
AdditionalErrorMessage UnicodeString |
Event ID 75: Active Directory Certificate Services could not publish a Delta CRL for key CAKeyIdentifier to the following location on server HostName: URL.
#Description
Active Directory Certificate Services could not publish a Delta CRL for key CAKeyIdentifier to the following location on server HostName: URL. ErrorMessageText.param5AdditionalErrorMessage.
Message #
Fields #
| Name | Description |
|---|---|
CAKeyIdentifier UnicodeString | |
URL UnicodeString | |
ErrorMessageText UnicodeString | |
HostName UnicodeString | |
param5 UnicodeString | |
AdditionalErrorMessage UnicodeString |
Event ID 75: Active Directory Certificate Services could not publish a Delta CRL for key CAKeyIdentifier to the following location on server HostName:
#Description
Active Directory Certificate Services could not publish a Delta CRL for key to the following location on server : . .
Fields #
| Name | Description |
|---|---|
CAKeyIdentifier UnicodeString | |
URL UnicodeString | |
ErrorMessageText UnicodeString | |
HostName UnicodeString | |
param5 UnicodeString | |
AdditionalErrorMessage UnicodeString |
Event ID 76: The "PolicyModuleDescription" Policy Module logged the following information: InformationMessage.
#Event ID 76: The "PolicyModuleDescription" Policy Module logged the following information:
#Description
The "PolicyModuleDescription" Policy Module logged the following information: InformationMessage.
Fields #
| Name | Description |
|---|---|
PolicyModuleDescription UnicodeString | |
InformationMessage UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"guid": "{6A71D062-9AFE-4F35-AD08-52134F85DFB9}",
"event_source_name": "",
"event_id": 76,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-05-30T01:34:11.3882555+00:00",
"event_record_id": 253093,
"correlation": {},
"execution": {
"process_id": 13200,
"thread_id": 12088
},
"channel": "Application",
"computer": "JD-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PolicyModuleDescription": "Windows default",
"InformationMessage": "The Administrator(v4.1): V1(0.0s) Certificate Template was loaded.\n"
},
"message": "The \"Windows default\" Policy Module logged the following information: The Administrator(v4.1): V1(0.0s) Certificate Template was loaded.\r\n"
}
Event ID 77: The "Name" Policy Module logged the following warning: PolicyModuleDescription.
#Description
The "Name" Policy Module logged the following warning: PolicyModuleDescription.
Message #
Fields #
| Name | Description |
|---|---|
PolicyModuleDescription UnicodeString | |
WarningMessage UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"guid": "6A71D062-9AFE-4F35-AD08-52134F85DFB9",
"event_source_name": "",
"event_id": 77,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T20:24:03.481197+00:00",
"event_record_id": 3713,
"correlation": {},
"execution": {
"process_id": 9432,
"thread_id": 6164
},
"channel": "Application",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "MSG_POLICY_LOG_WARNING",
"PolicyModuleDescription": "Windows default",
"WarningMessage": "The Active Directory connection to LAB-DC01.ludus.domain has been reestablished to LAB-DC01.ludus.domain.\r\n"
},
"message": ""
}
Event ID 77: The "PolicyModuleDescription" Policy Module logged the following warning:
#Description
The "PolicyModuleDescription" Policy Module logged the following warning: WarningMessage.
Fields #
| Name | Description |
|---|---|
PolicyModuleDescription UnicodeString | |
WarningMessage UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 77,
"level": 3,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T20:24:03.4811975+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"WarningMessage": "The Active Directory connection to JD-DC01-2022.ludus.domain has been reestablished to JD-DC01-2022.ludus.domain.\n",
"PolicyModuleDescription": "Windows default"
}
}
Event ID 78: The "PolicyModuleDescription" Policy Module logged the following error: ErrorMessage.
#Event ID 78: The "PolicyModuleDescription" Policy Module logged the following error:
#Description
The "PolicyModuleDescription" Policy Module logged the following error: ErrorMessage.
Fields #
| Name | Description |
|---|---|
PolicyModuleDescription UnicodeString | |
ErrorMessage UnicodeString |
Event ID 79: Active Directory Certificate Services could not publish a Certificate for request RequestId to the following location: DN.
#Description
Active Directory Certificate Services could not publish a Certificate for request RequestId to the following location: DN. ErrorMessageText.param5AdditionalErrorMessage.
Message #
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
DN UnicodeString | |
ErrorMessageText UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
AdditionalErrorMessage UnicodeString |
Event ID 79: Active Directory Certificate Services could not publish a Certificate for request RequestId to the following location:
#Description
Active Directory Certificate Services could not publish a Certificate for request to the following location: . .
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
DN UnicodeString | |
ErrorMessageText UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
AdditionalErrorMessage UnicodeString |
Event ID 80: Active Directory Certificate Services could not publish a Certificate for request RequestId to the following location on server HostName: DN.
#Description
Active Directory Certificate Services could not publish a Certificate for request RequestId to the following location on server HostName: DN. ErrorMessageText.param5AdditionalErrorMessage.
Message #
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
DN UnicodeString | |
ErrorMessageText UnicodeString | |
HostName UnicodeString | |
param5 UnicodeString | |
AdditionalErrorMessage UnicodeString |
Event ID 80: Active Directory Certificate Services could not publish a Certificate for request RequestId to the following location on server HostName:
#Description
Active Directory Certificate Services could not publish a Certificate for request to the following location on server : . .
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
DN UnicodeString | |
ErrorMessageText UnicodeString | |
HostName UnicodeString | |
param5 UnicodeString | |
AdditionalErrorMessage UnicodeString |
Event ID 81: Active Directory Certificate Services key archival is only supported on Advanced Server.
#Event ID 81: Active Directory Certificate Services key archival is only supported on Advanced Server
#Description
Active Directory Certificate Services key archival is only supported on Advanced Server.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 82: Active Directory Certificate Services could only verify NumberOfValidKRACerts of RequiredNumberOfValidKRACerts key recovery certificates required to enable private key archival.
#Description
Active Directory Certificate Services could only verify NumberOfValidKRACerts of RequiredNumberOfValidKRACerts key recovery certificates required to enable private key archival. Requests to archive private keys will not be accepted.
Message #
Fields #
| Name | Description |
|---|---|
NumberOfValidKRACerts UnicodeString | |
RequiredNumberOfValidKRACerts UnicodeString |
Event ID 82: Active Directory Certificate Services could only verify NumberOfValidKRACerts of RequiredNumberOfValidKRACerts key recovery certificates required to enable private key archival
#Description
Active Directory Certificate Services could only verify of key recovery certificates required to enable private key archival. Requests to archive private keys will not be accepted.
Fields #
| Name | Description |
|---|---|
NumberOfValidKRACerts UnicodeString | |
RequiredNumberOfValidKRACerts UnicodeString |
Event ID 83: Active Directory Certificate Services encountered an error loading key recovery certificates.
#Description
Active Directory Certificate Services encountered an error loading key recovery certificates. Requests to archive private keys will not be accepted. Name.
Message #
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"guid": "6A71D062-9AFE-4F35-AD08-52134F85DFB9",
"event_source_name": "",
"event_id": 83,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T23:15:53.245767+00:00",
"event_record_id": 4309,
"correlation": {},
"execution": {
"process_id": 3800,
"thread_id": 11792
},
"channel": "Application",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "MSG_E_LOADING_KRA_CERTS",
"ErrorCode": "The system cannot find the file specified. 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND)"
},
"message": ""
}
Event ID 83: Active Directory Certificate Services encountered an error loading key recovery certificates
#Description
Active Directory Certificate Services encountered an error loading key recovery certificates. Requests to archive private keys will not be accepted.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 83,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:15:53.2457675+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"ErrorCode": "The system cannot find the file specified. 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND)"
}
}
Event ID 84: Active Directory Certificate Services will not use key recovery certificate KRACertIndex because it could not be verified for use as a Key Recovery Agent.
#Description
Active Directory Certificate Services will not use key recovery certificate KRACertIndex because it could not be verified for use as a Key Recovery Agent. KRACertSubjectName ErrorCode.
Message #
Fields #
| Name | Description |
|---|---|
KRACertIndex UnicodeString | |
KRACertSubjectName UnicodeString | |
ErrorCode UnicodeString |
Event ID 84: Active Directory Certificate Services will not use key recovery certificate KRACertIndex because it could not be verified for use as a Key Recovery Agent
#Description
Active Directory Certificate Services will not use key recovery certificate because it could not be verified for use as a Key Recovery Agent.
Fields #
| Name | Description |
|---|---|
KRACertIndex UnicodeString | |
KRACertSubjectName UnicodeString | |
ErrorCode UnicodeString |
Event ID 85: Active Directory Certificate Services ignored key recovery certificate KRACertIndex because it could not be loaded.
#Event ID 85: Active Directory Certificate Services ignored key recovery certificate KRACertIndex because it could not be loaded
#Description
Active Directory Certificate Services ignored key recovery certificate because it could not be loaded.
Fields #
| Name | Description |
|---|---|
KRACertIndex UnicodeString | |
KRACertSubjectName UnicodeString | |
ErrorCode UnicodeString |
Event ID 86: Active Directory Certificate Services could not use the provider specified in the registry for encryption keys.
#Event ID 86: Active Directory Certificate Services could not use the provider specified in the registry for encryption keys
#Description
Active Directory Certificate Services could not use the provider specified in the registry for encryption keys.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 87: Active Directory Certificate Services could not use the default provider for encryption keys.
#Event ID 87: Active Directory Certificate Services could not use the default provider for encryption keys
#Description
Active Directory Certificate Services could not use the default provider for encryption keys.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 88: Active Directory Certificate Services switched to the default provider for encryption keys.
#Event ID 88: Active Directory Certificate Services switched to the default provider for encryption keys
#Description
Active Directory Certificate Services switched to the default provider for encryption keys.
Fields #
| Name | Description |
|---|---|
DefaultProviderName UnicodeString |
Event ID 90: ExceptionLocation: Active Directory Certificate Services detected an exception at address ExceptionAddress.
#Description
ExceptionLocation: Active Directory Certificate Services detected an exception at address ExceptionAddress. Flags = ExceptionFlags. The exception is ErrorCode.
Message #
Fields #
| Name | Description |
|---|---|
ExceptionLocation UnicodeString | |
ExceptionAddress UnicodeString | |
ExceptionFlags UnicodeString | |
ErrorCode UnicodeString |
Event ID 90: ExceptionLocation: Active Directory Certificate Services detected an exception at address
#Description
: Active Directory Certificate Services detected an exception at address . Flags = . The exception is .
Fields #
| Name | Description |
|---|---|
ExceptionLocation UnicodeString | |
ExceptionAddress UnicodeString | |
ExceptionFlags UnicodeString | |
ErrorCode UnicodeString |
Event ID 91: Could not connect to the Active Directory.
#Description
Could not connect to the Active Directory. Active Directory Certificate Services will retry when processing requires Active Directory access.
Message #
Event ID 91: Could not connect to the Active Directory
#Description
Could not connect to the Active Directory. Active Directory Certificate Services will retry when processing requires Active Directory access.
Event ID 92: Active Directory Certificate Services could not update security permissions.
#Event ID 92: Active Directory Certificate Services could not update security permissions
#Description
Active Directory Certificate Services could not update security permissions.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 93: The certificate (#CACertIdentifier) of Active Directory Certificate Services CACommonName does not exist in the certificate store at CN=NTAuthCertificates,CN=Public Key Se...
#Description
The certificate (#CACertIdentifier) of Active Directory Certificate Services CACommonName does not exist in the certificate store at CN=NTAuthCertificates,CN=Public Key Services,CN=Services in the Active Directory's configuration container. The directory replication may not be completed.
Message #
Fields #
| Name | Description |
|---|---|
CACertIdentifier UnicodeString | |
CACommonName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"guid": "{6a71d062-9afe-4f35-ad08-52134f85dfb9}",
"event_source_name": "",
"event_id": 93,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-05-09 10:06:23.998896+00:00",
"event_record_id": 7879,
"correlation": {
"ActivityID": "",
"RelatedActivityID": ""
},
"execution": {
"process_id": 8072,
"thread_id": 8848
},
"channel": "Application",
"computer": "tel2-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"CACertIdentifier": "1",
"CACommonName": "ludus-CA"
},
"message": ""
}
Event ID 93: The certificate (#CACertIdentifier) of Active Directory Certificate Services CACommonName does not exist in the certificate store at CN=NTAuthCertificates,CN=Public Key Services,CN=Services in the ...
#Fields #
| Name | Description |
|---|---|
CACertIdentifier UnicodeString | |
CACommonName UnicodeString |
Event ID 94: Active Directory Certificate Services CACommonName can not open the certificate store at CN=NTAuthCertificates,CN=Public Key Services,CN=Services in the Acti...
#Event ID 94: Active Directory Certificate Services CACommonName can not open the certificate store at CN=NTAuthCertificates,CN=Public Key Services,CN=Services in the Active Directory's configuration container
#Description
Active Directory Certificate Services can not open the certificate store at CN=NTAuthCertificates,CN=Public Key Services,CN=Services in the Active Directory's configuration container.
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString |
Event ID 95: Security permissions are corrupted or missing.
#Description
Security permissions are corrupted or missing. The Active Directory Certificate Services may need to be reinstalled.
Message #
Event ID 95: Security permissions are corrupted or missing
#Description
Security permissions are corrupted or missing. The Active Directory Certificate Services may need to be reinstalled.
Event ID 96: Active Directory Certificate Services could not create an encryption certificate.
#Event ID 96: Active Directory Certificate Services could not create an encryption certificate
#Description
Active Directory Certificate Services could not create an encryption certificate. . .
Fields #
| Name | Description |
|---|---|
Disposition UnicodeString | |
ErrorCode UnicodeString |
Event ID 97: Active Directory Certificate Services CACommonName will reduce the maximum lifetime of the issued certificate for request RequestId because the CA certificate lifet...
#Description
Active Directory Certificate Services CACommonName will reduce the maximum lifetime of the issued certificate for request RequestId because the CA certificate lifetime is shorter than the registry validity period. Consider renewing the CA certificate or reducing the registry validity period.
Message #
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
RequestId UnicodeString |
Event ID 97: Active Directory Certificate Services CACommonName will reduce the maximum lifetime of the issued certificate for request RequestId because the CA certificate lifetime is shorter than the registry ...
#Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
RequestId UnicodeString |
Event ID 98: Active Directory Certificate Services encountered errors validating configured key recovery certificates.
#Description
Active Directory Certificate Services encountered errors validating configured key recovery certificates. Requests to archive private keys will no longer be accepted.
Message #
Event ID 98: Active Directory Certificate Services encountered errors validating configured key recovery certificates
#Description
Active Directory Certificate Services encountered errors validating configured key recovery certificates. Requests to archive private keys will no longer be accepted.
Event ID 99: Active Directory Certificate Services could not create cross certificate Version to certify its own root certificates.
#Event ID 99: Active Directory Certificate Services could not create cross certificate Version to certify its own root certificates
#Description
Active Directory Certificate Services could not create cross certificate to certify its own root certificates. . .
Fields #
| Name | Description |
|---|---|
Version UnicodeString | |
Disposition UnicodeString | |
ErrorCode UnicodeString |
Event ID 100: Active Directory Certificate Services did not start: Could not load or verify the current CA certificate.
#Event ID 100: Active Directory Certificate Services did not start: Could not load or verify the current CA certificate
#Description
Active Directory Certificate Services did not start: Could not load or verify the current CA certificate. .
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString |
Event ID 101: Active Directory Certificate Services created CA cross certificate Version for CACommonName.
#Event ID 101: Active Directory Certificate Services created CA cross certificate Version for
#Description
Active Directory Certificate Services created CA cross certificate for .
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
Version UnicodeString |
Event ID 102: Active Directory Certificate Services could not create cross certificate Version to certify its own root certificates.
#Description
Active Directory Certificate Services could not create cross certificate Version to certify its own root certificates. The ExtensionOid extension is inconsistent. Disposition. ErrorCode.
Message #
Fields #
| Name | Description |
|---|---|
Version UnicodeString | |
ExtensionOid UnicodeString | |
Disposition UnicodeString | |
ErrorCode UnicodeString |
Event ID 102: Active Directory Certificate Services could not create cross certificate Version to certify its own root certificates
#Description
Active Directory Certificate Services could not create cross certificate to certify its own root certificates. The extension is inconsistent. . .
Fields #
| Name | Description |
|---|---|
Version UnicodeString | |
ExtensionOid UnicodeString | |
Disposition UnicodeString | |
ErrorCode UnicodeString |
Event ID 103: Active Directory Certificate Services added the root certificate of certificate chain Name to the downloaded Trusted Root Certification Authorities E...
#Description
Active Directory Certificate Services added the root certificate of certificate chain CACertIdentifier to the downloaded Trusted Root Certification Authorities Enterprise store on the CA computer. This store will be updated from the Certification Authorities container in Active Directory the next time Group Policy is applied. To verify that the CA certificate is published correctly in Active Directory, run the following command: certutil -viewstore "LDAPPath" (you must include the quotation marks when you run this command). If the root CA certificate is not present, use the Certificates console on the root CA computer to export the certificate to a file, and then run the following command to publish it to Active Directory: Certutil -dspublish %certificatefilename% Root.
Message #
Fields #
| Name | Description |
|---|---|
CACertIdentifier UnicodeString | |
LDAPPath UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"guid": "6A71D062-9AFE-4F35-AD08-52134F85DFB9",
"event_source_name": "",
"event_id": 103,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T20:16:52.134648+00:00",
"event_record_id": 3702,
"correlation": {},
"execution": {
"process_id": 9432,
"thread_id": 1156
},
"channel": "Application",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "MSG_E_MISSING_POLICY_ROOT",
"CACertIdentifier": "0",
"LDAPPath": "ldap:///CN=EvtGen-Root-CA,CN=Certification Authorities,CN=Public Key Services,CN=Services,CN=Configuration,DC=ludus,DC=domain?cACertificate?base?objectClass=certificationAuthority"
},
"message": ""
}
Event ID 103: Active Directory Certificate Services added the root certificate of certificate chain CACertIdentifier to the downloaded Trusted Root Certification Authorities Enterprise store on the CA computer
#Fields #
| Name | Description |
|---|---|
CACertIdentifier UnicodeString | |
LDAPPath UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 103,
"level": 3,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T20:16:52.1346485+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"LDAPPath": "ldap:///CN=EvtGen-Root-CA,CN=Certification Authorities,CN=Public Key Services,CN=Services,CN=Configuration,DC=ludus,DC=domain?cACertificate?base?objectClass=certificationAuthority",
"CACertIdentifier": "0"
}
}
Event ID 104: Active Directory Certificate Services published certificate CACertIdentifier to DN.
#Description
Active Directory Certificate Services published certificate CACertIdentifier to DN.
Message #
Fields #
| Name | Description |
|---|---|
CACertIdentifier UnicodeString | |
DN UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"guid": "{6a71d062-9afe-4f35-ad08-52134f85dfb9}",
"event_source_name": "",
"event_id": 104,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-05-09 10:06:24.168850+00:00",
"event_record_id": 7881,
"correlation": {
"ActivityID": "",
"RelatedActivityID": ""
},
"execution": {
"process_id": 8072,
"thread_id": 8848
},
"channel": "Application",
"computer": "tel2-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"CACertIdentifier": "1",
"DN": "CN=ludus-CA,CN=AIA,CN=Public Key Services,CN=Services,CN=Configuration,DC=ludus,DC=domain"
},
"message": ""
}
Event ID 104: Active Directory Certificate Services published certificate CACertIdentifier to
#Description
Active Directory Certificate Services published certificate to .
Fields #
| Name | Description |
|---|---|
CACertIdentifier UnicodeString | |
DN UnicodeString |
Event ID 105: Active Directory Certificate Services deleted invalid certificate CACertIdentifier from DN.
#Event ID 105: Active Directory Certificate Services deleted invalid certificate CACertIdentifier from
#Description
Active Directory Certificate Services deleted invalid certificate from .
Fields #
| Name | Description |
|---|---|
CACertIdentifier UnicodeString | |
DN UnicodeString |
Event ID 106: Active Directory Certificate Services cannot add certificate CACertIdentifier to DN.
#Event ID 106: Active Directory Certificate Services cannot add certificate CACertIdentifier to
#Description
Active Directory Certificate Services cannot add certificate to . . .
Fields #
| Name | Description |
|---|---|
CACertIdentifier UnicodeString | |
DN UnicodeString | |
DSErrorMessage UnicodeString | |
AdditionalErrorMessage UnicodeString |
Event ID 107: Active Directory Certificate Services cannot delete invalid certificate CACertIdentifier from DN.
#Event ID 107: Active Directory Certificate Services cannot delete invalid certificate CACertIdentifier from
#Description
Active Directory Certificate Services cannot delete invalid certificate from . . .
Fields #
| Name | Description |
|---|---|
CACertIdentifier UnicodeString | |
DN UnicodeString | |
DSErrorMessage UnicodeString | |
AdditionalErrorMessage UnicodeString |
Event ID 108: Active Directory Certificate Services could not delete a Certificate for request RequestId from the following location: DN.
#Description
Active Directory Certificate Services could not delete a Certificate for request RequestId from the following location: DN. ErrorMessageText.param5AdditionalErrorMessage.
Message #
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
DN UnicodeString | |
ErrorMessageText UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
AdditionalErrorMessage UnicodeString |
Event ID 108: Active Directory Certificate Services could not delete a Certificate for request RequestId from the following location:
#Description
Active Directory Certificate Services could not delete a Certificate for request from the following location: . .
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
DN UnicodeString | |
ErrorMessageText UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
AdditionalErrorMessage UnicodeString |
Event ID 109: Active Directory Certificate Services could not delete a Certificate for request RequestId from the following location on server HostName: DN.
#Description
Active Directory Certificate Services could not delete a Certificate for request RequestId from the following location on server HostName: DN. ErrorMessageText.param5AdditionalErrorMessage.
Message #
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
DN UnicodeString | |
ErrorMessageText UnicodeString | |
HostName UnicodeString | |
param5 UnicodeString | |
AdditionalErrorMessage UnicodeString |
Event ID 109: Active Directory Certificate Services could not delete a Certificate for request RequestId from the following location on server HostName:
#Description
Active Directory Certificate Services could not delete a Certificate for request from the following location on server : . .
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString | |
DN UnicodeString | |
ErrorMessageText UnicodeString | |
HostName UnicodeString | |
param5 UnicodeString | |
AdditionalErrorMessage UnicodeString |
Event ID 110: Active Directory Certificate Services could not initialize the performance counters.
#Description
Active Directory Certificate Services could not initialize the performance counters.
Message #
Event ID 110: Active Directory Certificate Services could not initialize the performance counters
#Description
Active Directory Certificate Services could not initialize the performance counters.
Event ID 111: Active Directory Certificate Services upgrade failed because the upgrade path could not be determined.
#Event ID 111: Active Directory Certificate Services upgrade failed because the upgrade path could not be determined
#Description
Active Directory Certificate Services upgrade failed because the upgrade path could not be determined.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 112: Active Directory Certificate Services upgrade failed because information required for the upgrade was unavailable.
#Event ID 112: Active Directory Certificate Services upgrade failed because information required for the upgrade was unavailable
#Description
Active Directory Certificate Services upgrade failed because information required for the upgrade was unavailable.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 113: A portion of the Active Directory Certificate Services upgrade failed: Could not create CertEnroll folder and/or shared folder with proper permissi...
#Event ID 113: A portion of the Active Directory Certificate Services upgrade failed: Could not create CertEnroll folder and/or shared folder with proper permissions
#Description
A portion of the Active Directory Certificate Services upgrade failed: Could not create CertEnroll folder and/or shared folder with proper permissions.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 114: A portion of the Active Directory Certificate Services upgrade failed: Could not create virtual roots.
#Event ID 114: A portion of the Active Directory Certificate Services upgrade failed: Could not create virtual roots
#Description
A portion of the Active Directory Certificate Services upgrade failed: Could not create virtual roots.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 115: A portion of the Active Directory Certificate Services upgrade failed: Could not update server registry entries.
#Event ID 115: A portion of the Active Directory Certificate Services upgrade failed: Could not update server registry entries
#Description
A portion of the Active Directory Certificate Services upgrade failed: Could not update server registry entries.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 116: A portion of the Active Directory Certificate Services upgrade failed: Could not create web configuration file.
#Event ID 116: A portion of the Active Directory Certificate Services upgrade failed: Could not create web configuration file
#Description
A portion of the Active Directory Certificate Services upgrade failed: Could not create web configuration file.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 117: A portion of the Active Directory Certificate Services upgrade failed: Could not create revocation page.
#Event ID 117: A portion of the Active Directory Certificate Services upgrade failed: Could not create revocation page
#Description
A portion of the Active Directory Certificate Services upgrade failed: Could not create revocation page.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 118: A portion of the Active Directory Certificate Services upgrade failed: Could not upgrade key containers.
#Event ID 118: A portion of the Active Directory Certificate Services upgrade failed: Could not upgrade key containers
#Description
A portion of the Active Directory Certificate Services upgrade failed: Could not upgrade key containers.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 121: A portion of the Active Directory Certificate Services upgrade failed: Could not install new templates.
#Event ID 121: A portion of the Active Directory Certificate Services upgrade failed: Could not install new templates
#Description
A portion of the Active Directory Certificate Services upgrade failed: Could not install new templates.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 122: A portion of the Active Directory Certificate Services upgrade failed: Could not update service description.
#Event ID 122: A portion of the Active Directory Certificate Services upgrade failed: Could not update service description
#Description
A portion of the Active Directory Certificate Services upgrade failed: Could not update service description.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 123: A portion of the Active Directory Certificate Services upgrade failed: Could not update security settings.
#Event ID 123: A portion of the Active Directory Certificate Services upgrade failed: Could not update security settings
#Description
A portion of the Active Directory Certificate Services upgrade failed: Could not update security settings.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 124: Active Directory Certificate Services upgrade succeeded.
#Description
Active Directory Certificate Services upgrade succeeded. Active Directory Certificate Services settings have been upgraded successfully.
Message #
Event ID 124: Active Directory Certificate Services upgrade succeeded
#Description
Active Directory Certificate Services upgrade succeeded. Active Directory Certificate Services settings have been upgraded successfully.
Event ID 125: Active Directory Certificate Services upgrade failed.
#Event ID 125: Active Directory Certificate Services upgrade failed
#Description
Active Directory Certificate Services upgrade failed. Active Directory Certificate Services settings have not been upgraded.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 126: Current information about advanced features supported by this Certification Authority is not available from the domain controller.
#Event ID 126: Current information about advanced features supported by this Certification Authority is not available from the domain controller
#Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 127: Key recovery certificate KRACertIndex is about to expire soon and will not be used upon expiration.
#Description
Key recovery certificate KRACertIndex is about to expire soon and will not be used upon expiration. Contact your adminstrator to renew this certificate. KRACertSubjectName ErrorCode.
Message #
Fields #
| Name | Description |
|---|---|
KRACertIndex UnicodeString | |
KRACertSubjectName UnicodeString | |
ErrorCode UnicodeString |
Event ID 127: Key recovery certificate KRACertIndex is about to expire soon and will not be used upon expiration
#Description
Key recovery certificate is about to expire soon and will not be used upon expiration. Contact your adminstrator to renew this certificate.
Fields #
| Name | Description |
|---|---|
KRACertIndex UnicodeString | |
KRACertSubjectName UnicodeString | |
ErrorCode UnicodeString |
Event ID 128: An Authority Key Identifier was passed as part of the certificate request RequestId.
#Description
An Authority Key Identifier was passed as part of the certificate request RequestId. This feature has not been enabled. To enable specifying a CA key for certificate signing, run: "certutil -setreg ca\UseDefinedCACertInRequest 1" and then restart the service.
Message #
Fields #
| Name | Description |
|---|---|
RequestId UnicodeString |
Event ID 128: An Authority Key Identifier was passed as part of the certificate request
#Fields #
| Name | Description |
|---|---|
RequestId UnicodeString |
Event ID 129: An invalid OID has been detected in the EnabledEKUForDefinedCACert configuration setting.
#Description
An invalid OID has been detected in the EnabledEKUForDefinedCACert configuration setting. To resolve, run: "certutil -getreg ca\EnabledEKUForDefinedCACert" to identify the invalid OID and correct it. The default OID ("1.3.6.1.5.5.7.3.9") will be used.
Message #
Event ID 129: An invalid OID has been detected in the EnabledEKUForDefinedCACert configuration setting
#Event ID 130: Active Directory Certificate Services could not create a certificate revocation list.
#Description
Active Directory Certificate Services could not create a certificate revocation list. ErrorMessageText. This may cause applications that need to check the revocation status of certificates issued by this CA to fail. You can recreate the certificate revocation list manually by running the following command: "certutil -CRL". If the problem persists, restart Certificate Services.
Message #
Fields #
| Name | Description |
|---|---|
ErrorMessageText UnicodeString |
Event ID 130: Active Directory Certificate Services could not create a certificate revocation list
#Fields #
| Name | Description |
|---|---|
ErrorMessageText UnicodeString |
Event ID 131: An invalid OID has been detected in the EKUOIDsForPublishExpiredCertInCRL configuration setting.
#Description
An invalid OID has been detected in the EKUOIDsForPublishExpiredCertInCRL configuration setting. To resolve, run: "certutil -getreg ca\EKUOIDsForPublishExpiredCertInCRL" to identify the invalid OID and correct it. The default OIDs ("1.3.6.1.5.5.7.3.3" and "1.3.6.1.4.1.311.61.1.1") will be used.
Message #
Event ID 131: An invalid OID has been detected in the EKUOIDsForPublishExpiredCertInCRL configuration setting
#Event ID 132: The certification authority (CA) was unable to perform a decryption operation.
#Description
The certification authority (CA) was unable to perform a decryption operation. This error can occur when an advanced encryption algorithm such as Advanced Encryption Standard (AES) is used and the CA has not been configured to use a CryptoAPI Next Generation (CNG) key storage provider. If this error occurred during certificate enrollment, check the certificate template to ensure that advanced encryption for key archival is not enabled.
Message #
Event ID 132: The certification authority (CA) was unable to perform a decryption operation
#Event ID 133: The certification authority (CA) failed to encode a server extension required to validate a certificate or certification revocation list (CRL).
#Description
The certification authority (CA) failed to encode a server extension required to validate a certificate or certification revocation list (CRL). The CA will not issue any certificates or CRLs that do not contain this extension. To correct this problem, use the Certification Authority snap-in to remove any Unicode characters in the URLs for the AIA, CDP, and IDP extensions, then restart the CA.
Message #
Event ID 133: The certification authority (CA) failed to encode a server extension required to validate a certificate or certification revocation list (CRL)
#Event ID 134: A certificate in the chain for CA certificate CACertIdentifier for CACommonName has expired.
#Event ID 134: A certificate in the chain for CA certificate CACertIdentifier for CACommonName has expired
#Description
A certificate in the chain for CA certificate for has expired. .
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString | |
ErrorCode UnicodeString | |
CACertIdentifier UnicodeString |
Event ID 135: Active Directory Certificate Services successfully created dummy key pair required for pre-signing.
#Event ID 135: Active Directory Certificate Services successfully created dummy key pair required for pre-signing
#Description
Active Directory Certificate Services successfully created dummy key pair required for pre-signing.
Fields #
| Name | Description |
|---|---|
ProvType UnicodeString | |
KeyLength UnicodeString | |
AlgorithmName UnicodeString |
Event ID 136: Active Directory Certificate Services could not create dummy key pair required for pre-signing.
#Event ID 136: Active Directory Certificate Services could not create dummy key pair required for pre-signing
#Description
Active Directory Certificate Services could not create dummy key pair required for pre-signing. This will cause requests for pre-signing to fail.
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString | |
ProvType UnicodeString | |
KeyLength UnicodeString | |
AlgorithmName UnicodeString |
Event ID 138: Active Directory Certificate Services did not start: Unable to initialize OLE Security: ErrorCode.
#Event ID 138: Active Directory Certificate Services did not start: Unable to initialize OLE Security:
#Description
Active Directory Certificate Services did not start: Unable to initialize OLE Security: .
Fields #
| Name | Description |
|---|---|
ErrorCode UnicodeString |
Event ID 139: Active Directory Certificate Services did not start: The registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\.
#Event ID 139: Active Directory Certificate Services did not start: The registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\CACommonName\CRLMaxPartitions is either not config...
#Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString |
Event ID 140: Active Directory Certificate Services did not start: The registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\.
#Event ID 140: Active Directory Certificate Services did not start: The registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\CACommonName\CRLMaxPartitions should be greater th...
#Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString |
Event ID 141: Active Directory Certificate Services did not start: LDAP URLs should not be selected in the CDP extension when CRL partitioning feature is enabled.
#Event ID 141: Active Directory Certificate Services did not start: LDAP URLs should not be selected in the CDP extension when CRL partitioning feature is enabled
#Description
Active Directory Certificate Services did not start: LDAP URLs should not be selected in the CDP extension when CRL partitioning feature is enabled.
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString |
Event ID 142: Active Directory Certificate Services did not start: <CRLPartitionIndex> MUST be included in the URLs configured for the CDP extension when CRL par...
#Event ID 142: Active Directory Certificate Services did not start: <CRLPartitionIndex> MUST be included in the URLs configured for the CDP extension when CRL partitioning feature is enabled
#Description
Active Directory Certificate Services did not start: <CRLPartitionIndex> MUST be included in the URLs configured for the CDP extension when CRL partitioning feature is enabled.
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString |
Event ID 143: Active Directory Certificate Services did not start: At least one of the URLs configured in the CDP extension MUST be selected to include the IDP e...
#Event ID 143: Active Directory Certificate Services did not start: At least one of the URLs configured in the CDP extension MUST be selected to include the IDP extension in the issued CRLs
#Description
Active Directory Certificate Services did not start: At least one of the URLs configured in the CDP extension MUST be selected to include the IDP extension in the issued CRLs.
Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString |
Event ID 144: Active Directory Certificate Services did not start: The current configuration of the CA does not allow for the support of the CRL partitioning fea...
#Message #
Event ID 144: Active Directory Certificate Services did not start: The current configuration of the CA does not allow for the support of the CRL partitioning feature
#Event ID 145: The Subject Key Identifier (SKI) computed by the certification authority (CA) differs from the value provided in the request.
#Event ID 145: The Subject Key Identifier (SKI) computed by the certification authority (CA) differs from the value provided in the request
#Fields #
| Name | Description |
|---|---|
SKIRequested UnicodeString | |
SKIGenerated UnicodeString |
Event ID 146: Active Directory Certificate Services did not start: The registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\.
#Event ID 146: Active Directory Certificate Services did not start: The registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\CACommonName\CRLFlags is set to an invalid value
#Fields #
| Name | Description |
|---|---|
CACommonName UnicodeString |
Event ID 1113194502: Active Directory Certificate Services issued a certificate for request {RequestId} for {SubjectName}.
#Event ID 1113194504: Active Directory Certificate Services left request {RequestId} pending in the queue for {SubjectName}.
#Event ID 1113194521: Active Directory Certificate Services revoked the certificate for request {RequestId} for {SubjectName}.
#Event ID 1113194522: Active Directory Certificate Services for {CACommonName} was started.
#Description
Active Directory Certificate Services for {CACommonName} was started.{DCSpecifier}{DCName}.
Message #
Fields #
| Name | Description |
|---|---|
CACommonName | |
DCSpecifier | |
DCName |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 26,
"level": 4,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T20:16:52.4651741+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"DCName": "JD-DC01-2022.ludus.domain",
"CACommonName": "EvtGen-Root-CA",
"DCSpecifier": " DC="
}
}
Event ID 1113194525: Active Directory Certificate Services issued a new Certificate Revocation List for {param1}.
#Event ID 1113194534: Active Directory Certificate Services for {CACommonName} was stopped.
#Description
Active Directory Certificate Services for {CACommonName} was stopped.
Message #
Fields #
| Name | Description |
|---|---|
CACommonName |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 38,
"level": 4,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:05:17.6318277+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"CACommonName": "EvtGen-Root-CA"
}
}
Event ID 1113194548: Active Directory Certificate Services issued a certificate for request {RequestId} for {SubjectName}.
#Event ID 1113194550: Active Directory Certificate Services left request {RequestId} pending in the queue for {SubjectName}.
#Event ID 1113194551: Active Directory Certificate Services unrevoked the certificate for request {RequestId} for {SubjectName}.
#Event ID 1113194552: Active Directory Certificate Services denied request {RequestId}.
#Event ID 1113194553: Active Directory Certificate Services denied request {RequestId}.
#Event ID 1113194564: Active Directory Certificate Services successfully published Base CRL(s).
#Description
Active Directory Certificate Services successfully published Base CRL(s).
Message #
Event ID 1113194565: Active Directory Certificate Services successfully published Delta CRL(s).
#Description
Active Directory Certificate Services successfully published Delta CRL(s).
Message #
Event ID 1113194566: Active Directory Certificate Services successfully published Base and Delta CRL(s).
#Description
Active Directory Certificate Services successfully published Base and Delta CRL(s).
Message #
Event ID 1113194567: Active Directory Certificate Services successfully published Base CRL(s) to server {HostName}.
#Event ID 1113194568: Active Directory Certificate Services successfully published Delta CRL(s) to server {HostName}.
#Event ID 1113194569: Active Directory Certificate Services successfully published Base and Delta CRL(s) to server {HostName}.
#Event ID 1113194572: The '{PolicyModuleDescription}' Policy Module logged the following information: {InformationMessage}.
#Event ID 1113194597: Active Directory Certificate Services created CA cross certificate {Version} for {CACommonName}.
#Event ID 1113194620: Active Directory Certificate Services upgrade succeeded.
#Description
Active Directory Certificate Services upgrade succeeded. Active Directory Certificate Services settings have been upgraded successfully.
Message #
Event ID 2186936327: Active Directory Certificate Services denied request {RequestId} because {Reason}.
#Event ID 2186936368: Revocation status for a certificate in the chain for CA certificate {CACertIdentifier} for {CACommonName} could not be verified because a server is...
#Event ID 2186936369: A certificate in the chain for CA certificate {CACertIdentifier} for {CACommonName} could not be verified because no information is available descr...
#Event ID 2186936373: Active Directory Certificate Services denied request {RequestId} because {Reason}.
#Description
Active Directory Certificate Services denied request {RequestId} because {Reason}. The request was for {SubjectName}. Additional information: {AdditionalInformation}.
Message #
Fields #
| Name | Description |
|---|---|
RequestId | |
Reason | |
SubjectName | |
AdditionalInformation |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 53,
"level": 3,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T20:16:58.3883392+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"AdditionalInformation": "Denied by Policy Module 0x80094801, The request does not contain a certificate template extension or the CertificateTemplate request attribute.\n",
"Reason": "The request contains no certificate template information. 0x80094801 (-2146875391 CERTSRV_E_NO_CERT_TYPE)",
"SubjectName": "CN=EvtGenTestCert, O=Test, L=Test, S=Test, C=US",
"RequestId": "2"
}
}
Event ID 2186936382: Active Directory Certificate Services had problems loading valid CRL publication values and has reset the CRL publication to its default settings.
#Description
Active Directory Certificate Services had problems loading valid CRL publication values and has reset the CRL publication to its default settings.
Message #
Event ID 2186936397: The '{PolicyModuleDescription}' Policy Module logged the following warning: {WarningMessage}.
#Description
The '{PolicyModuleDescription}' Policy Module logged the following warning: {WarningMessage}.
Message #
Fields #
| Name | Description |
|---|---|
PolicyModuleDescription | |
WarningMessage |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 77,
"level": 3,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T20:24:03.4811975+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"WarningMessage": "The Active Directory connection to JD-DC01-2022.ludus.domain has been reestablished to JD-DC01-2022.ludus.domain.\n",
"PolicyModuleDescription": "Windows default"
}
}
Event ID 2186936399: Active Directory Certificate Services could not publish a Certificate for request {RequestId} to the following location: {DN}.
#Event ID 2186936400: Active Directory Certificate Services could not publish a Certificate for request {RequestId} to the following location on server {HostName}: {DN}.
#Description
Active Directory Certificate Services could not publish a Certificate for request {RequestId} to the following location on server {HostName}: {DN}. {ErrorMessageText}.{param5}{AdditionalErrorMessage}.
Message #
Fields #
| Name | Description |
|---|---|
RequestId | |
HostName | |
DN | |
ErrorMessageText | |
param5 | |
AdditionalErrorMessage |
Event ID 2186936406: Active Directory Certificate Services could not use the provider specified in the registry for encryption keys.
#Event ID 2186936408: Active Directory Certificate Services switched to the default provider for encryption keys.
#Event ID 2186936413: The certificate (#{CACertIdentifier}) of Active Directory Certificate Services {CACommonName} does not exist in the certificate store at CN=NTAuthC...
#Event ID 2186936414: Active Directory Certificate Services {CACommonName} can not open the certificate store at CN=NTAuthCertificates;CN=Public Key Services;CN=Services...
#Event ID 2186936417: Active Directory Certificate Services {CACommonName} will reduce the maximum lifetime of the issued certificate for request {RequestId} because the...
#Event ID 2186936423: Active Directory Certificate Services added the root certificate of certificate chain {CACertIdentifier} to the downloaded Trusted Root Certificati...
#Message #
Fields #
| Name | Description |
|---|---|
CACertIdentifier | |
LDAPPath |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 103,
"level": 3,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T20:16:52.1346485+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"LDAPPath": "ldap:///CN=EvtGen-Root-CA,CN=Certification Authorities,CN=Public Key Services,CN=Services,CN=Configuration,DC=ludus,DC=domain?cACertificate?base?objectClass=certificationAuthority",
"CACertIdentifier": "0"
}
}
Event ID 2186936424: Active Directory Certificate Services published certificate {CACertIdentifier} to {DN}.
#Event ID 2186936425: Active Directory Certificate Services deleted invalid certificate {CACertIdentifier} from {DN}.
#Event ID 2186936428: Active Directory Certificate Services could not delete a Certificate for request {RequestId} from the following location: {DN}.
#Event ID 2186936429: Active Directory Certificate Services could not delete a Certificate for request {RequestId} from the following location on server {HostName}: {DN}.
#Event ID 2186936430: Active Directory Certificate Services could not initialize the performance counters.
#Description
Active Directory Certificate Services could not initialize the performance counters.
Message #
Event ID 2186936433: A portion of the Active Directory Certificate Services upgrade failed: Could not create CertEnroll folder and/or shared folder with proper permissi...
#Event ID 2186936434: A portion of the Active Directory Certificate Services upgrade failed: Could not create virtual roots.
#Event ID 2186936435: A portion of the Active Directory Certificate Services upgrade failed: Could not update server registry entries.
#Event ID 2186936436: A portion of the Active Directory Certificate Services upgrade failed: Could not create web configuration file.
#Event ID 2186936437: A portion of the Active Directory Certificate Services upgrade failed: Could not create revocation page.
#Event ID 2186936438: A portion of the Active Directory Certificate Services upgrade failed: Could not upgrade key containers.
#Event ID 2186936439: A portion of the Active Directory Certificate Services upgrade failed: Could not register CertSrv request.
#Event ID 2186936440: A portion of the Active Directory Certificate Services upgrade failed: Could not register CertSrv admin.
#Event ID 2186936441: A portion of the Active Directory Certificate Services upgrade failed: Could not install new templates.
#Event ID 2186936442: A portion of the Active Directory Certificate Services upgrade failed: Could not update service description.
#Event ID 2186936443: A portion of the Active Directory Certificate Services upgrade failed: Could not update security settings.
#Event ID 2186936447: Key recovery certificate {KRACertIndex} is about to expire soon and will not be used upon expiration.
#Event ID 2186936448: An Authority Key Identifier was passed as part of the certificate request {RequestId}.
#Event ID 2186936449: An invalid OID has been detected in the EnabledEKUForDefinedCACert configuration setting.
#Message #
Event ID 2186936451: An invalid OID has been detected in the EKUOIDsForPublishExpiredCertInCRL configuration setting.
#Message #
Event ID 3260678149: Active Directory Certificate Services could not find required registry information.
#Description
Active Directory Certificate Services could not find required registry information. The Active Directory Certificate Services may need to be reinstalled.
Message #
Event ID 3260678153: The Active Directory Certificate Services did not start: Unable to load an external policy module.
#Description
The Active Directory Certificate Services did not start: Unable to load an external policy module.
Message #
Event ID 3260678154: Active Directory Certificate Services were unable to build a new certificate or certificate chain: {ErrorCode}.
#Event ID 3260678159: Active Directory Certificate Services did not start: Version does not match certif.
#Description
Active Directory Certificate Services did not start: Version does not match certif.dll.
Message #
Event ID 3260678160: Active Directory Certificate Services did not start: Unable to initialize OLE: {ErrorCode}.
#Event ID 3260678161: Active Directory Certificate Services did not start: Unable to initialize the database connection for {CACommonName}.
#Description
Active Directory Certificate Services did not start: Unable to initialize the database connection for {CACommonName}. {ErrorCode}.
Message #
Fields #
| Name | Description |
|---|---|
CACommonName | |
ErrorCode |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 17,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:06:28.9787899+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"ErrorCode": "Certificate service has been suspended for a database restore operation. 0x80094006 (-2146877434 CERTSRV_E_SERVER_SUSPENDED)",
"CACommonName": "EvtGen-Root-CA"
}
}
Event ID 3260678163: Active Directory Certificate Services did not start: The Subject Name Template string in the registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentContro...
#Event ID 3260678164: Active Directory Certificate Services did not start: The Certificate Date Validity Period string in the registry value HKEY_LOCAL_MACHINE\SYSTEM\Cu...
#Event ID 3260678165: Active Directory Certificate Services could not process request {RequestId} due to an error: {ErrorCode}.
#Description
Active Directory Certificate Services could not process request {RequestId} due to an error: {ErrorCode}. The request was for {SubjectName}.
Message #
Fields #
| Name | Description |
|---|---|
RequestId | |
ErrorCode | |
SubjectName |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 21,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T20:24:03.9698601+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"ErrorCode": "The request's current status does not allow this operation. 0x80094003 (-2146877437 CERTSRV_E_BAD_REQUESTSTATUS)",
"SubjectName": "CN=EvtGen-Root-CA, DC=ludus, DC=domain",
"RequestId": "1"
}
}
Event ID 3260678166: Active Directory Certificate Services could not process request {RequestId} due to an error: {ErrorCode}.
#Event ID 3260678167: Active Directory Certificate Services could not process request {RequestId} due to an error: {ErrorCode}.
#Event ID 3260678171: Active Directory Certificate Services did not start: Hierarchical setup is incomplete.
#Event ID 3260678172: Active Directory Certificate Services did not start: The Certificate Revocation List Period string is invalid in the registry value HKEY_LOCAL_MACH...
#Event ID 3260678177: Active Directory Certificate Services did not start: Could not create the Certificate Server service thread for {CACommonName}.
#Event ID 3260678178: Active Directory Certificate Services did not start: Could not initialize RPC for {CACommonName}.
#Event ID 3260678179: Active Directory Certificate Services did not start: Could not initialize OLE for {CACommonName}.
#Event ID 3260678183: Active Directory Certificate Services did not start: The Certification Authority DCOM class for {CACommonName} could not be registered.
#Event ID 3260678184: Active Directory Certificate Services did not start: Could not initialize DCOM class factories for {CACommonName}.
#Event ID 3260678185: Active Directory Certificate Services did not start: Could not initialize DCOM Security Context for {CACommonName}.
#Event ID 3260678186: Could not build a certificate chain for CA certificate {CACertIdentifier} for {CACommonName}.
#Event ID 3260678187: The '{PolicyModuleDescription}' Policy Module '{MethodName}' method caused an exception at address {ExceptionAddress}.
#Event ID 3260678188: The '{PolicyModuleDescription}' Policy Module '{MethodName}' method returned an error.
#Description
The '{PolicyModuleDescription}' Policy Module '{MethodName}' method returned an error. {ErrorString} The returned status code is {ErrorCode}. {param4}.
Message #
Fields #
| Name | Description |
|---|---|
PolicyModuleDescription | |
MethodName | |
ErrorString | |
ErrorCode | |
param4 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 44,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T21:48:47.6826498+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"ErrorCode": "0x8007054b (1355)",
"MethodName": "Initialize",
"ErrorString": "The specified domain either does not exist or could not be contacted.",
"param4": "The Active Directory containing the Certification Authority could not be contacted.\n",
"PolicyModuleDescription": "Windows default"
}
}
Event ID 3260678189: The '{ExitModuleDescription}' Exit Module '{MethodName}' method caused an exception at address {ExceptionAddress}.
#Event ID 3260678190: The '{ExitModuleDescription}' Exit Module '{MethodName}' method returned an error.
#Event ID 3260678195: A certificate in the chain for CA certificate {CACertIdentifier} for {CACommonName} has been revoked.
#Event ID 3260678202: A certificate in the chain for CA certificate {CACertIdentifier} for {CACommonName} has expired.
#Event ID 3260678203: Active Directory Certificate Services did not start: Could not connect to the Active Directory for {CACommonName}.
#Event ID 3260678204: Active Directory Certificate Services refused to process an extremely long request from {SubjectName}.
#Event ID 3260678207: Active Directory Certificate Services did not start: {CACommonName} {ErrorCode}.
#Event ID 3260678208: Active Directory Certificate Services cannot publish enrollment access changes to Active Directory.
#Description
Active Directory Certificate Services cannot publish enrollment access changes to Active Directory.
Message #
Event ID 3260678209: Active Directory Certificate Services could not publish a Base CRL for key {CAKeyIdentifier} to the following location: {URL}.
#Description
Active Directory Certificate Services could not publish a Base CRL for key {CAKeyIdentifier} to the following location: {URL}. {ErrorMessageText}.{param5}{AdditionalErrorMessage}.
Message #
Fields #
| Name | Description |
|---|---|
CAKeyIdentifier | |
URL | |
ErrorMessageText | |
param5 | |
AdditionalErrorMessage |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 65,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:06:22.1539855+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"URL": "http://crl.ludus.domain/crldist/EvtGen-Root-CA.crl",
"AdditionalErrorMessage": "",
"param4": "",
"ErrorMessageText": "The specified path is invalid. 0x800700a1 (WIN32/HTTP: 161 ERROR_BAD_PATHNAME)",
"CAKeyIdentifier": "0",
"param5": ""
}
}
Event ID 3260678210: Active Directory Certificate Services could not publish a Delta CRL for key {CAKeyIdentifier} to the following location: {URL}.
#Event ID 3260678211: Active Directory Certificate Services made {NumberOfAttempts} attempts to publish a CRL and will stop publishing attempts until the next CRL is gen...
#Event ID 3260678218: Active Directory Certificate Services could not publish a Base CRL for key {CAKeyIdentifier} to the following location on server {HostName}: {URL}.
#Description
Active Directory Certificate Services could not publish a Base CRL for key {CAKeyIdentifier} to the following location on server {HostName}: {URL}. {ErrorMessageText}.{param5}{AdditionalErrorMessage}.
Message #
Fields #
| Name | Description |
|---|---|
CAKeyIdentifier | |
HostName | |
URL | |
ErrorMessageText | |
param5 | |
AdditionalErrorMessage |
Event ID 3260678219: Active Directory Certificate Services could not publish a Delta CRL for key {CAKeyIdentifier} to the following location on server {HostName}: {URL}.
#Event ID 3260678222: The '{PolicyModuleDescription}' Policy Module logged the following error: {ErrorMessage}.
#Event ID 3260678225: Active Directory Certificate Services key archival is only supported on Advanced Server.
#Event ID 3260678226: Active Directory Certificate Services could only verify {NumberOfValidKRACerts} of {RequiredNumberOfValidKRACerts} key recovery certificates requir...
#Event ID 3260678227: Active Directory Certificate Services encountered an error loading key recovery certificates.
#Description
Active Directory Certificate Services encountered an error loading key recovery certificates. Requests to archive private keys will not be accepted. {ErrorCode}.
Message #
Fields #
| Name | Description |
|---|---|
ErrorCode |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificationAuthority",
"event_id": 83,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:15:53.2457675+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"ErrorCode": "The system cannot find the file specified. 0x80070002 (WIN32: 2 ERROR_FILE_NOT_FOUND)"
}
}
Event ID 3260678228: Active Directory Certificate Services will not use key recovery certificate {KRACertIndex} because it could not be verified for use as a Key Recove...
#Event ID 3260678229: Active Directory Certificate Services ignored key recovery certificate {KRACertIndex} because it could not be loaded.
#Event ID 3260678231: Active Directory Certificate Services could not use the default provider for encryption keys.
#Event ID 3260678234: {ExceptionLocation}: Active Directory Certificate Services detected an exception at address {ExceptionAddress}.
#Event ID 3260678235: Could not connect to the Active Directory.
#Description
Could not connect to the Active Directory. Active Directory Certificate Services will retry when processing requires Active Directory access.
Message #
Event ID 3260678236: Active Directory Certificate Services could not update security permissions.
#Event ID 3260678239: Security permissions are corrupted or missing.
#Description
Security permissions are corrupted or missing. The Active Directory Certificate Services may need to be reinstalled.
Message #
Event ID 3260678240: Active Directory Certificate Services could not create an encryption certificate.
#Event ID 3260678242: Active Directory Certificate Services encountered errors validating configured key recovery certificates.
#Description
Active Directory Certificate Services encountered errors validating configured key recovery certificates. Requests to archive private keys will no longer be accepted.
Message #
Event ID 3260678243: Active Directory Certificate Services could not create cross certificate {Version} to certify its own root certificates.
#Event ID 3260678244: Active Directory Certificate Services did not start: Could not load or verify the current CA certificate.
#Event ID 3260678246: Active Directory Certificate Services could not create cross certificate {Version} to certify its own root certificates.
#Event ID 3260678250: Active Directory Certificate Services cannot add certificate {CACertIdentifier} to {DN}.
#Event ID 3260678251: Active Directory Certificate Services cannot delete invalid certificate {CACertIdentifier} from {DN}.
#Event ID 3260678255: Active Directory Certificate Services upgrade failed because the upgrade path could not be determined.
#Event ID 3260678256: Active Directory Certificate Services upgrade failed because information required for the upgrade was unavailable.
#Event ID 3260678269: Active Directory Certificate Services upgrade failed.
#Event ID 3260678270: Current information about advanced features supported by this Certification Authority is not available from the domain controller.
#Event ID 3260678274: Active Directory Certificate Services could not create a certificate revocation list.
#Event ID 3260678276: The certification authority (CA) was unable to perform a decryption operation.
#Message #
Event ID 3260678277: The certification authority (CA) failed to encode a server extension required to validate a certificate or certification revocation list (CRL).
#Message #
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 6a71d062-9afe-4f35-ad08-52134f85dfb9
Defined in certsrv.exe, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.4767, captured 2026-06-02