Machine Certificate Expired

RiverWild 96 Reputation points
2020-09-09T19:30:15.04+00:00

I inherited a Windows Server 2016 Standard which appears to have the Certificate Authority installed but the role is not installed. I think it may have to do with RSAT tools. Anyway, there is an expired certificate that is showing up in the Application logs.

Certificate for local system with Thumbprint f6 8c d1 f3 09 f0 ea 64 35 8b 36 38 d1 74 e5 b2 e8 e1 2f 99 is about to expire or already expired.

When I try to request a certificate with new key, I get the message that an enrollment policy server cannot be located.

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,774 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Fan Fan 15,321 Reputation points Microsoft Vendor
    2020-09-10T00:49:42.073+00:00

    Hi,
    To know the issue more clearly, would you please tell more about the environment for the server?
    Is it a stand alone server or a domain joined server member.

    1,To make sure if it is a CA server:

    Based on my experience, on a windows server, if we installed the CA role, we can see the role as following screenshot showing without instals the RSAT tools manually.
    Or you can run PKIVIEW.msc from the Search or Run menus on the server, if it is a CA, you can see the following :
    23661-9102.png
    23662-9103.png
    If you can't find it, the role mas be uninstalled or the server was not the CA server.
    23622-9104.jpg
    Then if it need to renew a certificate , it need to find the ca server.
    2,To make which CA issued the certificate, you can check all the issuer for certificates by the following steps :
    Run MMC. from the Search or Run menus
    23671-9105.png
    23642-9106.png
    23652-9107.png
    3,When make sure the issuer for the expired certificates , we can determine how to renew it.

    Following case for your reference:
    https://social.technet.microsoft.com/Forums/windowsserver/en-US/405545fe-1272-4a4a-a8ca-7e0b918cef37/how-to-generate-cert-request-from-my-cert-in-mmc?forum=winserversecurity

    0 comments No comments

  2. Thameur-BOURBITA 32,621 Reputation points
    2020-09-10T21:54:15.507+00:00

    Hi,

    If you are using a entreprise PKI, you have to check if the user or computer has the enrollment right on the template.
    072114_1141_PublicKeyIn11.png

    certificate-autoenrollment-in-windows-server-2016-part-3.aspx

    Please don't forget to mark this reply as answer if it help you to fix your issue

    0 comments No comments