Microsoft-Windows-CertificateServicesClient-AutoEnrollment
23 events across 2 channels
Event ID 1 —
Fields
| Name | Description |
|---|---|
Context | — |
StoreName | — |
LdapStore | — |
ErrorCode | — |
ErrorMsg | — |
Event ID 2 —
Fields
| Name | Description |
|---|---|
Context | — |
Event ID 3 —
Fields
| Name | Description |
|---|---|
Context | — |
Event ID 4 —
Fields
| Name | Description |
|---|---|
Context | — |
Event ID 5 —
Fields
| Name | Description |
|---|---|
Context | — |
Event ID 6 —
Fields
| Name | Description |
|---|---|
Context | — |
ErrorCode | — |
ErrorMsg | — |
Event ID 6 — Automatic certificate enrollment for local system failed (0x8007054b) The specified domain either does not exist or could not be contacted.
Fields
| Name | Description |
|---|---|
Context | — |
ErrorCode | — |
ErrorMsg | — |
Example Event
system:
provider: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
guid: '{F0DB7EF8-B6F3-4005-9937-FEB77B9E1B43}'
event_source_name: AutoEnrollment
event_id: 6
version: 0
level: 2
task: 0
opcode: 0
keywords: 36028797018963968
time_created: '2022-04-07T08:15:12.653840+00:00'
event_record_id: 112
correlation: {}
execution:
process_id: 0
thread_id: 0
channel: Application
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: ''
event_data:
Context: local system
ErrorCode: '0x8007054b'
ErrorMsg: "The specified domain either does not exist or could not be contacted.\r\n"
message: "Automatic certificate enrollment for local system failed (0x8007054b) The
specified domain either does not exist or could not be contacted.\r\n."
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 15 —
Fields
| Name | Description |
|---|---|
Context | — |
ErrorCode | — |
ErrorMsg | — |
Event ID 64 —
Fields
| Name | Description |
|---|---|
Context | — |
ObjId | — |
Event ID 1073741825 — Automatic certificate enrollment for %1 failed to download certificates for %2 store from %3 (%4).
Message
Fields
| Name | Description |
|---|---|
Context | — |
StoreName | — |
LdapStore | — |
ErrorCode | — |
ErrorMsg | — |
Event ID 1073741826 — Automatic certificate enrollment for {Context} started.
Message
Fields
| Name | Description |
|---|---|
Context | — |
Event ID 1073741827 — Automatic certificate enrollment for {Context} completed.
Message
Fields
| Name | Description |
|---|---|
Context | — |
Event ID 1073741828 — Automatic certificate enrollment for {Context} invoked the enrollment API.
Message
Fields
| Name | Description |
|---|---|
Context | — |
Event ID 1073741829 — Automatic certificate enrollment for {Context} returned from the enrollment API.
Message
Fields
| Name | Description |
|---|---|
Context | — |
Event ID 1073741830 — Automatic certificate enrollment for %1 failed (%2) %3.
Message
Fields
| Name | Description |
|---|---|
Context | — |
ErrorCode | — |
ErrorMsg | — |
Event ID 2147483663 — Automatic certificate enrollment for %1 failed to contact the active directory (%2).
Message
Fields
| Name | Description |
|---|---|
Context | — |
ErrorCode | — |
ErrorMsg | — |
Event ID 2147483712 — Certificate for %1 with Thumbprint %2 is about to expire or already expired.
Message
Fields
| Name | Description |
|---|---|
Context | — |
ObjId | — |
Event ID 3221225473 — Automatic certificate enrollment for {Context} failed to download certificates for {StoreName} store from {LdapStore} ({ErrorCode}).
Message
Fields
| Name | Description |
|---|---|
Context | — |
StoreName | — |
LdapStore | — |
ErrorCode | — |
ErrorMsg | — |
Event ID 3221225474 — Automatic certificate enrollment for %1 started.
Message
Fields
| Name | Description |
|---|---|
Context | — |
Event ID 3221225475 — Automatic certificate enrollment for %1 completed.
Message
Fields
| Name | Description |
|---|---|
Context | — |
Event ID 3221225476 — Automatic certificate enrollment for %1 invoked the enrollment API.
Message
Fields
| Name | Description |
|---|---|
Context | — |
Event ID 3221225477 — Automatic certificate enrollment for %1 returned from the enrollment API.
Message
Fields
| Name | Description |
|---|---|
Context | — |
Event ID 3221225478 — Automatic certificate enrollment for {Context} failed ({ErrorCode}) {ErrorMsg}.
Message
Fields
| Name | Description |
|---|---|
Context | — |
ErrorCode | — |
ErrorMsg | — |