Event ID 125 — AD CS Certification Authority Upgrade

Applies To: Windows Server 2008

Upgrading a certification authority (CA) that was installed on an earlier version of Windows to a computer running Windows Server 2008 can affect configuration options or components that need to be reconfigured after the upgrade. In some cases, you may also have to fix configuration problems before the upgrade can be completed.

Event Details

Product: Windows Operating System
ID: 125
Source: Microsoft-Windows-CertificationAuthority
Version: 6.0
Message: Active Directory Certificate Services upgrade failed. Active Directory Certificate Services settings have not been upgraded. %1


Resolve issues preventing a certification authority upgrade

Essential permissions, information about the version of Windows Server that the computer the certification authority is installed on, and the version of Windows Server that the domain controller that it obtains information from and publishes information to, are needed to complete a CA upgrade.

Possible resolutions include:

  • Confirm that the user performing the upgrade is a member of the local Administrators group. If existing certificate templates need to be upgraded or new certificate templates need to be installed, the upgrade must be performed by a member of the Enterprise Admins group.
  • Confirm that the CA you are attempting to upgrade is installed on a computer running Windows Server 2003 or Windows Server 2008. You cannot upgrade a CA from a computer running Windows 2000 directly to a computer running Windows Server 2008.
  • Restart the computer and try the upgrade again.
  • If the problem persists after a restart, contact Microsoft Customer Service and Support. For more information, see http://go.microsoft.com/fwlink/?LinkId=89446.


To perform this procedure, you must have permissions to request and enroll for a certificate.

To confirm that the upgrade has completed successfully, perform a test enrollment for a user or computer certificate:

  1. Log on to a domain computer running Windows Vista as a domain user with Enroll permissions on at least one template.
  2. Click Start, type mmc, and then press ENTER.
  3. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Continue.
  4. On the File menu, click Add/Remove Snap-in, click Certificates, and then click Add.
  5. Click User account, and click Next.
  6. Click Finish, and then click OK.
  7. In the console tree, double-click Certificates - Current User, and click Personal.
  8. On the Action menu, point to All Tasks, and click Request New Certificate to start the Certificate Enrollment wizard.
  9. Use the wizard to create and submit the certificate request.
  10. Under Certificate Installation Results, confirm that the enrollment completes successfully and no errors are reported. You can also click Details to view additional information about the certificate. 

AD CS Certification Authority Upgrade

Active Directory Certificate Services