Microsoft-Windows-CertificateServicesClient-CertEnroll
97 events across 2 channels
Event ID 15 — Certificate enrollment for Local system failed to retrieve certificate template information from the Policy Server.
#Fields #
| Name | Description |
|---|---|
Context | — |
ErrorCode | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificateServicesClient-CertEnroll",
"guid": "{54164045-7C50-4905-963F-E5BC1EEF0CCA}",
"event_source_name": "CertEnroll",
"event_id": 15,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2022-04-07T08:15:12.606960+00:00",
"event_record_id": 111,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "Application",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Context": "Local system",
"ErrorCode": "The specified domain either does not exist or could not be contacted. 0x8007054b (WIN32: 1355 ERROR_NO_SUCH_DOMAIN)"
},
"message": "Certificate enrollment for Local system failed to retrieve certificate template information from the Policy Server. Enrollment was not performed."
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 67 — Certificate enrollment for Local system failed to load policy from policy servers with ID The specified domain either does not exist or could not b...
#Fields #
| Name | Description |
|---|---|
Context | — |
ServerID | — |
ErrorCode | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificateServicesClient-CertEnroll",
"guid": "{54164045-7C50-4905-963F-E5BC1EEF0CCA}",
"event_source_name": "CertEnroll",
"event_id": 67,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2022-04-07T08:15:12.606960+00:00",
"event_record_id": 110,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "Application",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Context": "Local system",
"ServerID": "The specified domain either does not exist or could not be contacted. 0x8007054b (WIN32: 1355 ERROR_NO_SUCH_DOMAIN)",
"ErrorCode": ""
},
"message": "Certificate enrollment for Local system failed to load policy from policy servers with ID The specified domain either does not exist or could not be contacted. 0x8007054b (WIN32: 1355 ERROR_NO_SUCH_DOMAIN) ()"
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 68 — Certificate enrollment for Local system failed in authentication to policy servers with ID {67576419-F9FE-45FF-B3DA-10013334C041}.
#Fields #
| Name | Description |
|---|---|
Context | — |
ServerID | — |
ErrorCode | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificateServicesClient-CertEnroll",
"guid": "{54164045-7C50-4905-963F-E5BC1EEF0CCA}",
"event_source_name": "CertEnroll",
"event_id": 68,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2022-04-07T08:15:12.606960+00:00",
"event_record_id": 109,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "Application",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Context": "Local system",
"ServerID": "{67576419-F9FE-45FF-B3DA-10013334C041}",
"ErrorCode": "The specified domain either does not exist or could not be contacted. 0x8007054b (WIN32: 1355 ERROR_NO_SUCH_DOMAIN)"
},
"message": "Certificate enrollment for Local system failed in authentication to policy servers with ID {67576419-F9FE-45FF-B3DA-10013334C041} (The specified domain either does not exist or could not be contacted. 0x8007054b (WIN32: 1355 ERROR_NO_SUCH_DOMAIN))"
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 70 — Certificate enrollment for Local system failed because no valid policy can be obtained from policy servers with ID {67576419-F9FE-45FF-B3DA-1001333...
#Fields #
| Name | Description |
|---|---|
Context | — |
ServerURL | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CertificateServicesClient-CertEnroll",
"guid": "{54164045-7C50-4905-963F-E5BC1EEF0CCA}",
"event_source_name": "CertEnroll",
"event_id": 70,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2022-04-07T08:15:12.606960+00:00",
"event_record_id": 108,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "Application",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Context": "Local system",
"ServerURL": "{67576419-F9FE-45FF-B3DA-10013334C041}"
},
"message": "Certificate enrollment for Local system failed because no valid policy can be obtained from policy servers with ID {67576419-F9FE-45FF-B3DA-10013334C041}"
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 39452686 — Certificate enrollment for Context received a TemplateName certificate with request ID RequestId from CA when retrieving pending requests.
Event ID 39452693 — Certificate enrollment for Context attempted to enroll for a TemplateName certificate with request ID RequestId from certification authority CA.
Description
Certificate enrollment for Context attempted to enroll for a TemplateName certificate with request ID RequestId from certification authority CA. The request is pending.
Message #
Fields #
| Name | Description |
|---|---|
Context UnicodeString | — |
TemplateName UnicodeString | — |
CA UnicodeString | — |
RequestId UnicodeString | — |
Event ID 39452694 — Certificate enrollment for Context attempted to renew a TemplateName certificate with request ID RequestId from certification authority CA.
Event ID 39452700 — Certificate enrollment for {Context} successfully installed a {TemplateName} certificate when retrieving pending requests.
Event ID 39452701 — Certificate enrollment for {Context} reused the private key when requesting a {TemplateName} certificate.
Event ID 39452721 — Certificate enrollment for {Context} successfully received a {TemplateName} certificate.
Event ID 1113194500 — Certificate enrollment for Context could not access local resources or retrieve TemplateName certificate template information (CA).
Description
Certificate enrollment for Context could not access local resources or retrieve TemplateName certificate template information (CA). Enrollment was not performed.
Message #
Fields #
| Name | Description |
|---|---|
Context UnicodeString | Certificate enrollment for |
TemplateName UnicodeString | could not access local resources or retrieve |
CA UnicodeString | certificate template information ( |
Event ID 1113194501 — Certificate enrollment for Context could not find any valid certificate templates.
Event ID 1113194504 — Certificate enrollment for {Context} removed pending certificate requests that have expired or are obsolete.
Event ID 1113194506 — Certificate enrollment for Context archived or deleted, from the Personal certificate store, certificates that have expired, or been revoked or superseded.
Event ID 1113194515 — Certificate enrollment for Context successfully received a TemplateName certificate with request ID RequestId from certification authority CA.
Event ID 1113194516 — Certificate enrollment for Context successfully renewed a TemplateName certificate with request ID RequestId from certification authority CA.
Event ID 1113194521 — Certificate enrollment for Context failed to update the TemplateName certificate in the Personal certificate store due to one of the following.
Event ID 1113194523 — Certificate enrollment for Context was cancelled by the user.
Event ID 1113194526 — Certificate enrollment for Context was cancelled by the user when requesting a TemplateName certificate.
Event ID 1113194528 — Certificate enrollment for Context attempted to retrieve a TemplateName certificate from CA.
Event ID 1113194529 — Certificate enrollment for Context deleted certificates that have expired, or have been revoked or superseded from the user object in Active Directory.
Event ID 1113194537 — To prevent simultaneous renewal or enrollment from another computer, certificate enrollment for Context to renew or enroll for a TemplateName certificate has been...
Event ID 1113194552 — Certificate enrollment for Context for the template TemplateName was not performed because this template has been superseded.
Event ID 1113194584 — SCEP Certificate enrollment for Method via Stage succeeded.
Event ID 1113194587 — Successfully found Logon Certificate Template for Template.
Event ID 1113194589 — Logon Certificate Request creation for Request_thumbprint succeeded for the Process template for key Context.
Event ID 1113194591 — Successfully installed Logon Certificate for Request_thumbprint.
Event ID 2186936331 — Certificate enrollment for Context could not find a certification authority in the enterprise.
Event ID 2186936332 — Certificate enrollment for {Context} encountered errors while retrieving information about the certification authority from Active Directory.
Event ID 2186936335 — Certificate enrollment for Context failed to retrieve certificate template information from the Policy Server.
Event ID 2186936337 — Certificate enrollment for Context failed to enroll for a TemplateName certificate from certification authority CA (ErrorCode).
Description
Certificate enrollment for Context failed to enroll for a TemplateName certificate from certification authority CA (ErrorCode). Another certification authority will be contacted.
Message #
Fields #
| Name | Description |
|---|---|
Context UnicodeString | — |
TemplateName UnicodeString | — |
CA UnicodeString | — |
ErrorCode UnicodeString | — |
Event ID 2186936338 — Certificate enrollment for Context failed to renew a TemplateName certificate from certification authority CA (ErrorCode).
Description
Certificate enrollment for Context failed to renew a TemplateName certificate from certification authority CA (ErrorCode). Another certification authority will be contacted.
Message #
Fields #
| Name | Description |
|---|---|
Context UnicodeString | — |
TemplateName UnicodeString | — |
CA UnicodeString | — |
ErrorCode UnicodeString | — |
Event ID 2186936354 — Certificate enrollment for {Context} cannot enroll or renew {TemplateName} certificate because the certificate template is used for smart cards and...
Event ID 2186936357 — Certificate enrollment for {Context} cannot enroll or renew {TemplateName} certificate because strong private key protection is required on the new...
Event ID 2186936358 — Certificate enrollment for Context cannot enroll or renew TemplateName certificate because user interaction is required on the TemplateName template in Active Directory.
Event ID 2186936359 — Certificate enrollment for {Context} cannot enroll or renew {TemplateName} certificate because a password is required to access the associated priv...
Event ID 2186936360 — Certificate enrollment for {Context} cannot enroll or renew {TemplateName} certificate because a password is required to access the associated priv...
Event ID 2186936362 — Certificate enrollment for Context for the TemplateName template must be performed by using the machine context.
Event ID 2186936363 — Certificate enrollment for Context failed to find a smart card reader for the TemplateName template.
Event ID 2186936364 — Certificate enrollment for Context failed to open the user interface (ErrorCode).
Event ID 2186936366 — Certificate enrollment for Context could not enroll for a TemplateName certificate.
Event ID 2186936367 — Certificate enrollment for Context could not enroll for a TemplateName certificate.
Event ID 2186936368 — Certificate enrollment for Context could not enroll for a TemplateName certificate.
Event ID 2186936370 — Certificate enrollment for Context failed to install the certificate response for a TemplateName certificate with request ID RequestId (ErrorCode).
Event ID 2186936371 — Certificate enrollment for Context for the TemplateName certificate must be performed under the user context.
Event ID 2186936372 — The CA certificate for CAName is not trusted.
Event ID 2186936373 — Certificate enrollment for Context failed to retrieve a TemplateName certificate from certification authority CA with request ID RequestId, and the error returned from t...
Event ID 2186936374 — Certificate enrollment for Context failed to retrieve a pending TemplateName certificate with request ID RequestId from certification authority CA (ErrorCode).
Description
Certificate enrollment for Context failed to retrieve a pending TemplateName certificate with request ID RequestId from certification authority CA (ErrorCode). The enrollment process will be attempted again later.
Message #
Fields #
| Name | Description |
|---|---|
Context UnicodeString | — |
TemplateName UnicodeString | — |
CA UnicodeString | — |
RequestId UnicodeString | — |
ErrorCode UnicodeString | — |
Event ID 2186936375 — Certificate enrollment for Context for the TemplateName template could not find specified CSPs on the local machine.
Event ID 2186936377 — The "Provider" provider was not loaded because initialization failed.
Event ID 2186936378 — The "Algorithm" algorithm for the "Provider" provider was not loaded because initialization failed.
Event ID 2186936379 — Could not determine the signature algorithm for PublicKeyAlgorithm to sign an enrollment request.
Description
Could not determine the signature algorithm for PublicKeyAlgorithm to sign an enrollment request.
Message #
Fields #
| Name | Description |
|---|---|
HashAlgorithm UnicodeString | — |
PublicKeyAlgorithm UnicodeString | — |
HashLookupAlgorithm UnicodeString | — |
PublicKeyLookupAlgorithm UnicodeString | — |
SignatureAlgorithm UnicodeString | — |
SignatureAlgorithmPreferred UnicodeString | — |
Pkcs7Signature UnicodeString | — |
AlternateSignatureAlgorithm UnicodeString | — |
NullSignature UnicodeString | — |
ErrorCode UnicodeString | — |
Event ID 2186936380 — Could not find a registered public key algorithm OID for PublicKeyAlgorithm for an enrollment request.
Description
Could not find a registered public key algorithm OID for PublicKeyAlgorithm for an enrollment request.
Message #
Fields #
| Name | Description |
|---|---|
HashAlgorithm UnicodeString | — |
PublicKeyAlgorithm UnicodeString | — |
HashLookupAlgorithm UnicodeString | — |
PublicKeyLookupAlgorithm UnicodeString | — |
SignatureAlgorithm UnicodeString | — |
SignatureAlgorithmPreferred UnicodeString | — |
Pkcs7Signature UnicodeString | — |
AlternateSignatureAlgorithm UnicodeString | — |
NullSignature UnicodeString | — |
ErrorCode UnicodeString | — |
Event ID 2186936381 — Could not find a registered signature algorithm OID for HashAlgorithm and PublicKeyAlgorithm to sign an enrollment request.
Description
Could not find a registered signature algorithm OID for HashAlgorithm and PublicKeyAlgorithm to sign an enrollment request.
Message #
Fields #
| Name | Description |
|---|---|
HashAlgorithm UnicodeString | — |
PublicKeyAlgorithm UnicodeString | — |
HashLookupAlgorithm UnicodeString | — |
PublicKeyLookupAlgorithm UnicodeString | — |
SignatureAlgorithm UnicodeString | — |
SignatureAlgorithmPreferred UnicodeString | — |
Pkcs7Signature UnicodeString | — |
AlternateSignatureAlgorithm UnicodeString | — |
NullSignature UnicodeString | — |
ErrorCode UnicodeString | — |
Event ID 2186936382 — Could not encode signature parameters for a PublicKeyAlgorithm signature for an enrollment request.
Description
Could not encode signature parameters for a PublicKeyAlgorithm signature for an enrollment request.
Message #
Fields #
| Name | Description |
|---|---|
HashAlgorithm UnicodeString | — |
PublicKeyAlgorithm UnicodeString | — |
HashLookupAlgorithm UnicodeString | — |
PublicKeyLookupAlgorithm UnicodeString | — |
SignatureAlgorithm UnicodeString | — |
SignatureAlgorithmPreferred UnicodeString | — |
Pkcs7Signature UnicodeString | — |
AlternateSignatureAlgorithm UnicodeString | — |
NullSignature UnicodeString | — |
ErrorCode UnicodeString | — |
Event ID 2186936383 — Enrollment Policy Server ServerURL returned an error when retrieving templates for Context: FaultString.
Event ID 2186936384 — Certificate enrollment for Context successfully load policy from policy server ServerID.
Event ID 2186936385 — Certificate enrollment for Policy_Id is successfully authenticated by policy server Context using authentication mechanism Credential (Credential: ServerID).
Description
Certificate enrollment for Policy_Id is successfully authenticated by policy server Context using authentication mechanism Credential (Credential: ServerID). Policy Id: ServerURL.
Message #
Fields #
| Name | Description |
|---|---|
Policy_Id | — |
Context UnicodeString | — |
ServerURL UnicodeString | — |
ServerID UnicodeString | — |
Credential UnicodeString | — |
AuthType UnicodeString | — |
Event ID 2186936386 — Certificate enrollment for Policy_Id is successfully authenticated by enrollment server Context using authentication mechanism Credential (Credential: ServerID).
Description
Certificate enrollment for Policy_Id is successfully authenticated by enrollment server Context using authentication mechanism Credential (Credential: ServerID). Policy Id: ServerURL.
Message #
Fields #
| Name | Description |
|---|---|
Policy_Id | — |
Context UnicodeString | — |
ServerURL UnicodeString | — |
ServerID UnicodeString | — |
Credential UnicodeString | — |
AuthType UnicodeString | — |
Event ID 2186936387 — Certificate enrollment for Context failed to load policy from policy servers with ID ServerID (ErrorCode).
Event ID 2186936388 — Certificate enrollment for Context failed in authentication to policy servers with ID ServerID (ErrorCode).
Event ID 2186936390 — Certificate enrollment for Context failed because no valid policy can be obtained from policy servers with ID ServerURL.
Event ID 2186936391 — Certificate enrollment for Context failed in adding credential to Vault for ServerURL (ErrorCode).
Event ID 2186936392 — Certificate enrollment for Context failed because the loaded policy from the policy server ServerURL is invalid (ErrorCode).
Event ID 2186936393 — Certificate auto enrollment for Context cannot be done because the policy server ServerURL turns it off.
Event ID 2186936394 — Certificate enrollment for Context failed to load policy from policy server ServerURL with ID ServerID (ErrorCode).
Event ID 2186936395 — Certificate enrollment for Context failed in authentication to policy server ServerURL with ID ServerID (ErrorCode).
Description
Certificate enrollment for Context failed in authentication to policy server ServerURL with ID ServerID (ErrorCode). Authentication mechanism was AuthType (Credential: Credential).
Message #
Fields #
| Name | Description |
|---|---|
Context UnicodeString | — |
ServerURL UnicodeString | — |
ServerID UnicodeString | — |
Credential UnicodeString | — |
AuthType UnicodeString | — |
ErrorCode UnicodeString | — |
Event ID 2186936396 — Certificate enrollment for Context failed in authentication to enrollment server ServerURL (ErrorCode).
Description
Certificate enrollment for Context failed in authentication to enrollment server ServerURL (ErrorCode). Policy Id: ServerID. Authentication mechanism was AuthType (Credential: Credential).
Message #
Fields #
| Name | Description |
|---|---|
Context UnicodeString | — |
ServerURL UnicodeString | — |
ServerID UnicodeString | — |
Credential UnicodeString | — |
AuthType UnicodeString | — |
ErrorCode UnicodeString | — |
Event ID 2186936397 — Certificate enrollment for Context cannot enroll from user configured enrollment policy server since it is disabled by group policy.
Event ID 2186936398 — Certificate enrollment for Context sent a request for template TemplateName to a ROBO certificate enrollment server CA.
Event ID 2186936399 — Certificate enrollment for Context sent a request for template TemplateName to a ANONYMOUS certificate enrollment server CA.
Event ID 2186936400 — Certificate enrollment for Context cannot enroll for a TemplateName certificate because the certificate enrollment server CA is ROBO and only renewal is supported.
Event ID 2186936401 — Certificate enrollment for Context cannot enroll for a TemplateName certificate because the certificate enrollment server CA is ANONYMOUS and only renewal is supp...
Event ID 2186936402 — Certificate enrollment for Context failed in authentication to all urls for enrollment server associated with policy id: ServerID (ErrorCode).
Description
Certificate enrollment for Context failed in authentication to all urls for enrollment server associated with policy id: ServerID (ErrorCode). Failed to enroll for template: TemplateName.
Message #
Fields #
| Name | Description |
|---|---|
Context UnicodeString | — |
ServerID UnicodeString | — |
TemplateName UnicodeString | — |
ErrorCode UnicodeString | — |
Event ID 2186936403 — Certificate enrollment for Context cannot find a credential that meets the selection criteria for url ServerURL with id ServerID (ErrorCode).
Event ID 2186936404 — The credential for URL ServerURL has been updated from certificate (OldCertificate) to certificate (NewCertificate) in context Context.
Description
The credential for URL ServerURL has been updated from certificate (OldCertificate) to certificate (NewCertificate) in context Context.
Message #
Fields #
| Name | Description |
|---|---|
Context UnicodeString | — |
ServerURL UnicodeString | — |
NewCertificate UnicodeString | — |
OldCertificate UnicodeString | — |
ErrorCode UnicodeString | — |
Event ID 2186936405 — Certificate enrollment for Request_Id for the Context template could not perform attestation due to an error with the cryptographic hardware using the provider:...
Description
Certificate enrollment for Request_Id for the Context template could not perform attestation due to an error with the cryptographic hardware using the provider: TemplateName. Request Id: TpmError.KspName.
Message #
Fields #
| Name | Description |
|---|---|
Request_Id | — |
Context UnicodeString | — |
TemplateName UnicodeString | — |
TpmError UnicodeString | — |
KspName UnicodeString | — |
RequestId UnicodeString | — |
Event ID 2186936417 — Successfully removed Logon Certificate request for Request_thumbprint.
Event ID 3260678150 — Certificate enrollment for Context could not find a valid certificate template to match TemplateName.
Event ID 3260678153 — Certificate enrollment for Context was denied by RequestId when retrieving the pending request for a TemplateName certificate with request ID CA.
Event ID 3260678157 — Certificate enrollment for Context failed to enroll for a TemplateName certificate with request ID RequestId from CA (ErrorCode).
Event ID 3260678160 — Certificate enrollment for Context failed to renew a TemplateName certificate with request ID RequestId from CA (ErrorCode).
Description
Certificate enrollment for Context failed to renew a TemplateName certificate with request ID RequestId from CA (ErrorCode). The certificate which failed to renew is CertificateThumbprint.
Message #
Fields #
| Name | Description |
|---|---|
Context UnicodeString | — |
TemplateName UnicodeString | — |
CA UnicodeString | — |
RequestId UnicodeString | — |
CertificateThumbprint UnicodeString | — |
ErrorCode UnicodeString | — |
Event ID 3260678167 — Certificate enrollment for {Context} failed to renew a {TemplateName} certificate because it cannot find a certification authority to issue the cer...
Event ID 3260678168 — Certificate enrollment for {Context} failed to enroll for a {TemplateName} certificate because it cannot find a certification authority to issue th...
Event ID 3260678170 — Certificate enrollment for {Context} failed to show the user notification balloon ({ErrorCode}).
Event ID 3260678175 — Certificate enrollment for {Context} failed to install a {TemplateName} certificate when retrieving pending requests ({ErrorCode}).
Event ID 3260678179 — Certificate enrollment for Context detected that the DNS name in the TemplateName certificate does not match the DNS name of the local computer.
Description
Certificate enrollment for Context detected that the DNS name in the TemplateName certificate does not match the DNS name of the local computer. A new enrollment for a TemplateName certificate will be attempted in HourNumber hours.
Message #
Fields #
| Name | Description |
|---|---|
Context UnicodeString | — |
TemplateName UnicodeString | — |
HourNumber UnicodeString | — |