Windows Certificate Services ‘certsrv’ Website displays 403.14
Aug31

Windows Certificate Services ‘certsrv’ Website displays 403.14

KB ID 0001342  Problem I seem to get all the PKI/Certificate services problems! Yesterday I was trying to use the web enrolment portal on a certificate services server, and could not get in locally, (or remotely) via http, (or https) it simply showed me a 403.14 error. HTTP Error 403.14 Forbidden Solution This was an odd one, in IIS Manager select the ‘Certsrv’ virtual directory > Advanced Options > And look at the...

Read More
Certificate Services – Migrate from SHA1 to SHA256
Oct10

Certificate Services – Migrate from SHA1 to SHA256

SHA1 to SHA256 KB ID 0001243  Problem It’s time to start planning! Microsoft will stop their browsers displaying the ‘lock’ icon for services that are secured with a certificate that uses SHA1. This is going to happen in February 2017 so now’s the time to start thinking about testing your PKI environment, and making sure all your applications support SHA2. Note: This includes code that has been signed using...

Read More
Certificate Services – Create a ‘Wildcard Certificate’
Jan11

Certificate Services – Create a ‘Wildcard Certificate’

KB ID 0001128 Problem Now you may be thinking, “If you have your own CA/PKI solution why would you need to create a Wildcard Certificate”? If you can generate as many certificates as you want whats the point? Well today I need to setup ADFS, WAG (Web Application Gateway), and Remote Desktop Services Gateway Server. To make the whole thing wok on my test bench would be a lot less hassle if I could just use one certificate...

Read More
Event ID 53 – ‘The public key does not meet the minimum size required by the specified certificate template’
Nov17

Event ID 53 – ‘The public key does not meet the minimum size required by the specified certificate template’

KB ID 0000967  Problem I’ve been doing a lot of PKI work over the last few days, testing device enrollment and NDES etc, and came across this problem being logged on my issuing/subordinate CA server; Log Name: Application Source: Microsoft-Windows-CertificationAuthority Event ID: 53 Task Category: None Level: Warning Keywords: User: SYSTEM Description: Active Directory Certificate Services denied request 35 because The public...

Read More
NDES – Fails to Issue Certificates (Signature Algorithm)
Nov17

NDES – Fails to Issue Certificates (Signature Algorithm)

KB ID 0001021  Problem I was trying to enroll some ASA firewalls to NDES to get some certificates. Each time the process failed with the following error. % Error in receiving Certificate Authority certificate: status = FAIL, cert length = 0 That’s a pretty generic error, and does not give me a lot to go on. So I thought I would try from another network device, (a Cisco Catalyst switch). It’s a little easier to...

Read More