No renewal event (1001) - Key Vault Virtual machine extension

Marcin Słowikowski 35 Reputation points
2024-01-03T12:37:01.7533333+00:00

How can I troubleshoot linkOnRenewal (IIS Certificate Rebind) using the Windows version of KV virtual machine extension? When I create a new version of the certificate in KV, then it installs cert but there is no renewal (1001) event in Windows Event Viewer. No errors in the extension log file

Azure Key Vault
Azure Key Vault
An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
1,119 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,155 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,881 questions
{count} vote

2 answers

Sort by: Most helpful
  1. Marcin Słowikowski 35 Reputation points
    2024-03-12T13:22:28.2533333+00:00

    After more than two months, I received information from Microsoft Support that it was a problem on the Azure side and has been resolved.

    2 people found this answer helpful.

  2. JamesTran-MSFT 36,371 Reputation points Microsoft Employee
    2024-01-03T21:22:57.0166667+00:00

    @Marcin Słowikowski

    Thank you for your post!

    When it comes to troubleshooting linkOnRenewal (IIS Certificate Rebind), I found some related issues to hopefully help point you in the right direction. If you're still having issues afterwards, please let me know.

    I understand that when you create a new version of the certificate within the KV, it's installed but there's no Event ID 1001 within Windows Event Viewer or within the extension log file. To troubleshoot this, can you try the following:

    1. Ensure you configured auto-rebind by enabling automatic rebinding of certificate renewals in IIS.
    2. Check the Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational logs to see if anything was written there, since the KV VM extension generates Certificate Lifecycle Notifications when a certificate with a matching SAN is installed.
    3. If the above steps don't work, can you see if renewing a machine cert manually via MMC helps to populate the correct event id? For more info - Event ID1001 CertificateServicesClient-Lifecycle-System/Operational.
      • Enable Event Viewer\Applications and Services Logs\Microsoft\Windows\CertificateServicesClient-LifeCycle-System log. 75715-enabled.png
      • Renew a machine cert manually via MMC. 76055-renew222.png
      • After the cert has been renewed successfully, you should be able to see the event ID 1001. 75658-renew2.png
      Additional Links:

    I hope this helps!

    If you have any other questions, please let me know. Thank you for your time and patience throughout this issue.


    If the information helped address your question, please Accept the answer. This will help us and also improve searchability for others in the community who might be researching similar information.