Microsoft-Windows-EnrollmentWebService

Event ID 1: The Certificate Enrollment Web Service has started.

#
Channel
Admin
Task
CertificateEnrollmentServer

Event ID 2: The Certificate Enrollment Web Service failed to start.

#
Channel
Admin
Task
CertificateEnrollmentServer

Description

The Certificate Enrollment Web Service failed to start. Confirm that the Certificate Enrollment Web Service is properly installed, and restart Internet Information Services (IIS) by using iisreset.exe. If the problem persists, enable tracing in the web.config file, restart IIS, attempt to enroll for a certificate again from any client, and then contact Microsoft Customer Service and Support with the trace file information. Error

Message #

The Certificate Enrollment Web Service failed to start. Confirm that the Certificate Enrollment Web Service is properly installed, and restart Internet Information Services (IIS) by using iisreset.exe. If the problem persists, enable tracing in the web.config file, restart IIS, attempt to enroll for a certificate again from any client, and then contact Microsoft Customer Service and Support with the trace file information. %1

Fields #

NameDescription
Error Int32

Event ID 3: The Certificate Enrollment Web Service failed to start.

#
Channel
Admin
Task
CertificateEnrollmentServer

Description

The Certificate Enrollment Web Service failed to start. The certification authority (CA) "CAConfig" is not an enterprise CA.

Message #

The Certificate Enrollment Web Service failed to start. The certification authority (CA) "%1" is not an enterprise CA.

Fields #

NameDescription
CAConfig UnicodeString

Event ID 4: The Certificate Enrollment Web Service failed to start.

#
Channel
Admin
Task
CertificateEnrollmentServer

Description

The Certificate Enrollment Web Service failed to start. A valid certification authority (CA) configuration is not specified in the web.config file. Please specify a CA configuration in the web.config file.

Message #

The Certificate Enrollment Web Service failed to start. A valid certification authority (CA) configuration is not specified in the web.config file. Please specify a CA configuration in the web.config file.

Event ID 5: The Certificate Enrollment Web Service has been stopped.

#
Channel
Admin
Task
CertificateEnrollmentServer

Event ID 6: The Certificate Enrollment Web Service is in renewal-only mode.

#
Channel
Admin
Task
CertificateEnrollmentServer

Description

The Certificate Enrollment Web Service is in renewal-only mode. New enrollment requests cannot be processed when the Certificate Enrollment Web Service is in renewal-only mode. If you want to enable new enrollment requests, configure both the CA and the Certificate Enrollment Web Service for new enrollment requests.

Message #

The Certificate Enrollment Web Service is in renewal-only mode. New enrollment requests cannot be processed when the Certificate Enrollment Web Service is in renewal-only mode. If you want to enable new enrollment requests, configure both the CA and the Certificate Enrollment Web Service for new enrollment requests.

Fields #

NameDescription
CAConfig UnicodeString

Event ID 7: The Certificate Enrollment Web Service is attempting to use renewal-only mode, but certification authority (CA) "CAConfig" does not support this mode.

#
Channel
Admin
Task
CertificateEnrollmentServer

Description

The Certificate Enrollment Web Service is attempting to use renewal-only mode, but certification authority (CA) "CAConfig" does not support this mode. To use renewal-only mode, configure the Certificate Enrollment Web Service to use a CA that is installed on a computer that is running at least Windows Server 2008 R2. Then, configure the CA by running the following command on the CA: certutil -setreg policy\editflags +EDITF_ENABLERENEWONBEHALFOF. Otherwise, disable renewal-only mode. If no action is taken, subsequent requests will be rejected.

Message #

The Certificate Enrollment Web Service is attempting to use renewal-only mode, but certification authority (CA) "%1" does not support this mode. To use renewal-only mode, configure the Certificate Enrollment Web Service to use a CA that is installed on a computer that is running at least Windows Server 2008 R2. Then, configure the CA by running the following command on the CA: certutil -setreg policy\editflags +EDITF_ENABLERENEWONBEHALFOF. Otherwise, disable renewal-only mode. If no action is taken, subsequent requests will be rejected.

Fields #

NameDescription
CAConfig UnicodeString

Event ID 8: The Certificate Enrollment Web Service cannot read the version or the configuration flags from certification authority (CA) "CAConfig.

#
Channel
Admin
Task
CertificateEnrollmentServer

Description

The Certificate Enrollment Web Service cannot read the version or the configuration flags from certification authority (CA) "CAConfig." On the Security tab of the CA property sheet, grant Read permission to the account used by the Certificate Enrollment Web Service application pool. If no action is taken, subsequent requests will be rejected.

Message #

The Certificate Enrollment Web Service cannot read the version or the configuration flags from certification authority (CA) "%1." On the Security tab of the CA property sheet, grant Read permission to the account used by the Certificate Enrollment Web Service application pool. If no action is taken, subsequent requests will be rejected.

Fields #

NameDescription
CAConfig UnicodeString

Event ID 9: The Certificate Enrollment Web Service is attempting to use renewal-only mode, but certification authority (CA) "CAConfig" does not support this mode.

#
Channel
Admin
Task
CertificateEnrollmentServer

Description

The Certificate Enrollment Web Service is attempting to use renewal-only mode, but certification authority (CA) "CAConfig" does not support this mode. To use renewal-only mode, configure the CA by running the following command on the CA: certutil -setreg policy\editflags +EDITF_ENABLERENEWONBEHALFOF. Otherwise, disable renewal-only mode. If no action is taken, subsequent requests will be rejected.

Message #

The Certificate Enrollment Web Service is attempting to use renewal-only mode, but certification authority (CA) "%1" does not support this mode. To use renewal-only mode, configure the CA by running the following command on the CA: certutil -setreg policy\editflags +EDITF_ENABLERENEWONBEHALFOF. Otherwise, disable renewal-only mode. If no action is taken, subsequent requests will be rejected.

Fields #

NameDescription
CAConfig UnicodeString

Event ID 10: The Certificate Enrollment Web Service cannot operate because an incompatible configuration was selected.

#
Channel
Admin
Task
CertificateEnrollmentServer

Description

The Certificate Enrollment Web Service cannot operate because an incompatible configuration was selected. To resolve this issue, remove the Certificate Enrollment Web Service. If you want to use key based renewal, enable both client certificate authentication and renewal-only mode. If you want to use user name and password authentication or Windows authentication, disable key based renewal, and then run Setup again.

Message #

The Certificate Enrollment Web Service cannot operate because an incompatible configuration was selected. To resolve this issue, remove the Certificate Enrollment Web Service. If you want to use key based renewal, enable both client certificate authentication and renewal-only mode. If you want to use user name and password authentication or Windows authentication, disable key based renewal, and then run Setup again.

Event ID 11: The Certificate Enrollment Web Service is enabled for key based renewal.

#
Channel
Admin
Task
CertificateEnrollmentServer

Description

The Certificate Enrollment Web Service is enabled for key based renewal. Client certificates without subject information in the Active Directory database can be used to renew certificates.

Message #

The Certificate Enrollment Web Service is enabled for key based renewal. Client certificates without subject information in the Active Directory database can be used to renew certificates.

Provenance

ETW provider GUID c3cba89d-b3d1-48f1-be6c-9b317a3cf3d5

Defined in certadm.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.4767, captured 2026-06-02 — Manifest XML pack, 1.9 MB