question

bizcntradmin-7120 avatar image
0 Votes"
bizcntradmin-7120 asked DaisyZhou-MSFT commented

Certificate template not showing

Hi Guys,

I have migrated my 2 tier PKI from Windows Server 2012 r2 to Windows Server 2019. Evrything is good except certificate templates are missing. When i check the container in AD sites and services the list of certificate templates is still there, is there a way to make it appear in certificate authority.

windows-active-directory
· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hello @bizcntradmin-7120
How are things going on your end? Please keep me posted on this issue.
If you have any further questions or concerns about this question, please let us know.
I appreciate your time and efforts.

Best Regards,
Daisy Zhou

============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 Votes 0 ·

Hello @bizcntradmin-7120
Would you please tell me how things are going on your side. If you have any questions or concerns about the information I provided, please don't hesitate to let us know.
Again thanks for your time and have a nice day!

Best Regards,
Daisy Zhou

============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 Votes 0 ·
Thameur-BOURBITA avatar image
0 Votes"
Thameur-BOURBITA answered

Hi,

The certificate template created through enterprise PKI is saved on configuration partition in the forest level and , it replicated on all domain controllers in the forest. There is no certificate template in AD site level.
There is no sense to talk about move certificate template from AD site to PKI.

Please don't forget to mark this reply as answer if it help your to fix your issue

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

DaisyZhou-MSFT avatar image
0 Votes"
DaisyZhou-MSFT answered DaisyZhou-MSFT edited

Hello @bizcntradmin-7120,

Thank you for posting here.

Based on the description, do you mean all the certificate templates are missing or only custom certificate templates are missing when issue certificate templates?

If all the certificate templates are missing, we can open certificate ttemplate console and check the certificate templates are stored on which DC (if you have one than one DC in the domain).

For example,

Here is stored on DC named 2012R2.

25307-dc.png

If we connected to another DC, we can see all the certificate templates, maybe there is issue about AD replication.
25386-dc1.png

We can whether check AD replication is working fine. On one DC and run repadmin /replsum and **repadmin /showrepl /csv >C:\showrepl.csv* to check the there is any issue about AD replication (if there is no any error message, then AD replication is working fine).


If we mean only custom certificate templates are missing when issue certificate templates. We can check if the "flags" below is 10 or not.

ADSI\Configuration\Services\Public Key Services\Enrollment Services\right sub CA name->Properties->flags.

25364-dc2.png


Hope the information above is helpful. If anything is unclear, please feel free to let us know.




Best Regards,
Daisy Zhou


============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.



dc.png (23.1 KiB)
dc1.png (13.9 KiB)
dc2.png (70.2 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.