Меню

Certificate services client ошибка

Если событие с кодом 86: CertificateServicesClient-CertEnroll продолжает вас беспокоить, этот пост может вам помочь. Когда появляется эта ошибка, ваше устройство может выключиться или зависнуть с синим экраном DPC_WATCHDOG_VIOLATION. Вместе с сообщением об ошибке также появится уведомление с указанием имени журнала, источника, идентификатора события и т. д. К счастью, вы можете выполнить несколько простых шагов, чтобы устранить эту ошибку.

Идентификатор события 86, CertificateServicesClient-CertEnroll

Что вызывает событие с идентификатором 86?

Событие с кодом 86 часто появляется, когда службы сертификации Active Directory не могут использовать поставщика, указанного в реестре, для ключей шифрования. Обычно это связано с TPM, BIOS или поврежденными обновлениями или драйверами Windows.

Если ошибка Event ID 86: CertificateServicesClient-CertEnroll продолжает беспокоить вас на вашем компьютере с Windows, следуйте этим советам, чтобы решить проблему:

  1. Запустить или откатить Центр обновления/обновления Windows
  2. Обновите драйверы устройств
  3. Обновить БИОС/прошивку
  4. Проверьте файлы минидампа
  5. Восстановление системы до состояния, предшествующего возникновению проблемы
  6. Восстановление ОС Windows с помощью установочного носителя

Теперь давайте посмотрим на них подробно.

1]Запустить или откатить Центр обновления/обновления Windows

Удалить обновления

Сначала обновите Windows вручную и посмотрите, поможет ли это. Однако рассмотрите возможность удаления обновления, если проблема возникает после обновлений Windows. Чтобы удалить обновление, выполните следующие действия:

  1. Нажмите клавишу Windows + R, чтобы открыть диалоговое окно «Выполнить».
  2. Тип appwiz.cpl и нажмите Enter.
  3. На странице «Удалить или просмотреть программу» нажмите «Просмотр установленных обновлений».
  4. Щелкните правой кнопкой мыши недавно установленное обновление и выберите «Удалить».

2]Обновить драйверы устройств

Обновить драйверы

Также известно, что устаревшие или поврежденные драйверы устройств вызывают событие с идентификатором 86 в Windows. Обновите драйверы вашего устройства и проверьте, устранена ли проблема.

Воспользуйтесь одним из приведенных ниже способов, чтобы обновить драйверы устройства:

  1. Вы можете проверить наличие драйверов и дополнительных обновлений через Центр обновления Windows, чтобы обновить драйверы.
  2. Вы можете посетить сайт производителя для загрузки драйверов.
  3. Используйте бесплатное программное обеспечение для обновления драйверов
  4. Если у вас уже есть файл драйвера INF на вашем компьютере, то:
    • Откройте Диспетчер устройств.
    • Щелкните категорию драйвера, чтобы развернуть меню.
    • Затем выберите соответствующий драйвер и щелкните его правой кнопкой мыши.
    • Выберите Обновить драйвер.
    • Следуйте указаниям мастера на экране, чтобы завершить обновление драйверов.

3]Обновить BIOS/прошивку

обновить биос виндовс 10

Обновление BIOS может исправить ошибки, связанные с конкретным оборудованием, или добавить совместимость с новыми устройствами. BIOS должен заставить ваш компьютер работать; его обновление сопряжено с огромным риском. Если что-то пойдет не так, это может привести к тому, что ваша материнская плата перестанет работать и ваш компьютер не запустится должным образом. Всегда следуйте инструкциям производителя по обновлению BIOS, если вам необходимо обновить BIOS. Вот как вы можете обновить BIOS вашего устройства.

4]Проверьте файлы минидампа

Файлы минидампа содержат наиболее важные области памяти аварийных процессов. При сбое процесса или появлении BSoD файл минидампа записывается на диск пользователя и позже загружается в Sentry. Минидамп обычно включает в себя стек времени выполнения каждого активного потока во время сбоя. Возможно, вы захотите проверить эти файлы журналов, чтобы выяснить причины.

5]Восстановление системы до точки, предшествующей возникновению проблемы

Восстановите систему с помощью System Restore

В случае сбоя установки или повреждения данных выполнение восстановления системы может вернуть ваше устройство в рабочее состояние без переустановки операционной системы. Это восстановит среду Windows, установив файлы и настройки, сохраненные в точке восстановления. Вот как вы можете выполнить восстановление системы. Обратите внимание, что это можно сделать, только если вы ранее создали точку восстановления системы.

6]Восстановите ОС Windows с помощью установочного носителя

Если ни один из этих способов вам не помог, восстановите ОС Windows с помощью установочного носителя. Вот как это сделать:

  1. Загрузите Windows ISO и создайте загрузочный USB-накопитель или DVD-диск.
  2. Загрузитесь с носителя и выберите Восстановить компьютер.
  3. В разделе «Расширенное устранение неполадок» выберите «Дополнительные параметры» > «Устранение неполадок».
  4. Теперь нажмите «Восстановление при загрузке» и следуйте инструкциям на экране.

Если идентификатор события не вызывает никаких проблем, таких как BSOD, а просто регистрируется в журналах, вы можете игнорировать его.

Исправлено: идентификатор события 1108, служба регистрации событий обнаружила ошибку.

Что такое инициализация регистрации сертификата SCEP?

Простой протокол регистрации сертификатов или SCEP позволяет пользователям безопасно выдавать сертификаты различным сетевым устройствам, используя метод автоматической регистрации. Этот процесс выдачи сертификатов является более безопасным и масштабируемым. Он также может автоматизировать задачу выдачи сертификатов.

My Windows 10 is 1809. Recently I saw the warning in the Event Viewer.

Event 64, CertificateServicesClient-AutoEnrollment

Certificate for local system with Thumbprint be f9 b4 cd 1xxxxxxxx f4 df 51 is about to expire or already expired.

I did the search and find the way to solve this problem.

Before to do the following, I would like to make an announcement. It is just a warning. It will not affect your Windows System.

Right Click Start > Run > type mmc > press ENTER
On the File Menu > Click Add/Remove Snap-in > Click Certificates > Click Add
Click Computer Account > click Next
Click Finish > Click OK
In the console tree, Expand Certificates > Personal > Certificates
You should see the XBL Client IPsec Issuing CA
Right Click on it > All tasks > Export
Follow the Export Wizard > Export it as a x509 (.cer) > Give it a name (example: xbl-client-ipsec.cer)
Right Click on it > Delete > Confirm Delete
Close the mmc > Say NO when asked if you want to save Console

Now, the certificate is removed. This warning should not appear in the Event Viewer.

RRS feed

  • Remove From My Forums
  • Question

  • Hello,

    In event viewer I keep seeing an error Certificate enrollment for Local system failed to enroll for a DomainController certificate with request ID N/A from mail1.my.domainmail1 (The RPC server is unavailable. 0x800706ba (WIN32: 1722 RPC_S_SERVER_UNAVAILABLE)).

    The only thing is, I no longer have this server. This was out old exchange server that we migrated away from. Does anyone know how I would stop this? Thanks.

All replies

  • Hi KAG,

    Looks like you have an auto-enrollment policy on. First, check the following and give a detailed report on what you find:

    — Your Certificate Services Client — Auto-Enrollment GPO.

    — The Certificate Authority Listing in your Active Directory Services Node -> Public Key Services -> <CA Name>.

    — Any Domain Controller certificates issued by this CA already in the certificate store for the domain controller.

    Next you need to determine if you still have a need for Domain Controller certificates, be it from a different CA, or if you have no need altogether. Tell us about your needs too.

    Kind Regards,

  • Hi,

    Thanks for your question.

    Please try the following steps.

    1 Please check the object mail1.my.domainmail1 if it exists
    in the AD database. If it is no use, we could remove the object and its corresponding in AD to see if it could resolved the issue.

    2 We could try remove authenticated users and everyone
    permissions from DC certificate template so that other users like mail1 cannot auto-enroll and enroll this DC certificate.

    Hope above information can help you.

    Highly appreciate your effort and time. If you have any question and concern, please feel free to let me know.

    Best regards,

    Michael


    Please remember to mark the replies as an answers if they help.
    If you have feedback for TechNet Subscriber Support, contact
    tnmff@microsoft.com

  • Hi,

    Thanks for your question.

    Please try the following steps.

    1 Please check the object mail1.my.domainmail1 if it exists
    in the AD database. If it is no use, we could remove the object and its corresponding in AD to see if it could resolved the issue.

    2 We could try remove authenticated users and everyone
    permissions from DC certificate template so that other users like mail1 cannot auto-enroll and enroll this DC certificate.

    Hope above information can help you.

    Highly appreciate your effort and time. If you have any question and concern, please feel free to let me know.

    Best regards,

    Michael


    Please remember to mark the replies as an answers if they help.
    If you have feedback for TechNet Subscriber Support, contact
    tnmff@microsoft.com

    I just removed mail1 from Active Directory Users and Computers. Is that what you mean?

  • Hi,

    Thanks for your update.

    Yes! This is said at the point 1. Could it be of help?

    And the point 2 I suggested is removing the authenticated users from DC certificate template from its security permission.

    Hope this helps. I look forward hearing your good news.

    Best regards,

    Michael


    Please remember to mark the replies as an answers if they help.
    If you have feedback for TechNet Subscriber Support, contact
    tnmff@microsoft.com

  • Hi KGA,

    Some explanation, since this is getting a bit off track.

    On finding the auto-enrollment GPO set (which doesn’t specify a template), the DC will look for a suitable template. On finding it, it will look in Active Directory Services Node for a CA that is eligible for this template. It will then contact this CA and
    request enrollment. Since in this case mail1.my.domainmail1 no longer exists as a machine (but both the GPO and the listing in Services still exist, it will try and fail to contact the CA. Removing the listing and deactivating the GPO should do the trick.

    Kind Regards,

    • Marked as answer by

      Wednesday, June 20, 2018 12:50 PM

    • Unmarked as answer by
      KAG PMW
      Wednesday, June 20, 2018 1:41 PM

  • I just recently turned oof the auto enrollment on the server that this was originally on, but am still getting the same error. Auto enrollment was not yet configured on the new server that I just moved CA to.

  • Hi KAG,

    Are we talking about the same thing? Auto-enrollment obligation is normally pushed through Group Policy Objects. You can turn it off on the machine, but if the Domain/OU it’s in has the GPO set, it will be pushed right back onto the machine.

    In addition, a certificate template has an auto-enroll permission. The latter can cause interesting situations as well, where a GPO forces an auto-enrollment
    obligation, but there are no suitable templates at all with the right permission.

    Could you show us a GPResult on the machine of the auto-enrollment GPO? See https://docs.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-server-certificate-autoenrollment where to find it.

    And could you also show us screenshots of the Public Key Services tree in Active Directory?

    Kind Regards,

  • Hi KAG,

    How are things going on? 

    Now we’d better remove Authenticated Users or other users except DCs from the DC certificate template for to see if it could fix this error. The method needn’t to gpupdate.

    Hope this helps. If you have any question and concern, please feel free to let me know.

    Best regards,

    Michael


    Please remember to mark the replies as an answers if they help.
    If you have feedback for TechNet Subscriber Support, contact
    tnmff@microsoft.com

  • I seriously doubt that will do the trick. To be sure, the DC will need Read, Enroll and Autoenroll permissions in order to use the template. But the moment it gets all three permissions through any combination of group memberships, all partial actions are
    useless. Even if it does, it will probably provoke a different error (no templates could be found). It also gets in the way of any future plans to reinstate auto-enrollment using a different CA.

    The problem is twofold. First, that the DC gets instructions to auto-enroll for a Certificate for which no CAs are present to accommodate. Second, that it gets information from the Active Directory configuration partition about the presence of a CA which
    no longer exists.

    The following document provides some background on auto-enrollment troubleshooting, though it’s written to get it to work while we’re trying to turn it off.

    https://blogs.technet.microsoft.com/xdot509/2012/10/18/troubleshooting-autoenrollment/

    Kind Regards,

  • Hi ,

    Just want to confirm the current situations.

    Please feel free to let us know if you need further assistance.

    Best regards,

    Michael


    Please remember to mark the replies as an answers if they help.
    If you have feedback for TechNet Subscriber Support, contact
    tnmff@microsoft.com

  • Hi ,

    Just want to confirm the current situations.

    Please feel free to let us know if you need further assistance.

    Best regards,

    Michael


    Please remember to mark the replies as an answers if they help.
    If you have feedback for TechNet Subscriber Support, contact
    tnmff@microsoft.com

    I removed Authenticated Users from the template and this did not resolve the issue.

  • I seriously doubt that will do the trick. To be sure, the DC will need Read, Enroll and Autoenroll permissions in order to use the template. But the moment it gets all three permissions through any combination of group memberships, all partial actions are
    useless. Even if it does, it will probably provoke a different error (no templates could be found). It also gets in the way of any future plans to reinstate auto-enrollment using a different CA.

    The problem is twofold. First, that the DC gets instructions to auto-enroll for a Certificate for which no CAs are present to accommodate. Second, that it gets information from the Active Directory configuration partition about the presence of a CA which
    no longer exists.

    The following document provides some background on auto-enrollment troubleshooting, though it’s written to get it to work while we’re trying to turn it off.

    https://blogs.technet.microsoft.com/xdot509/2012/10/18/troubleshooting-autoenrollment/

    Kind Regards,

    The Certificate Services Auto Enrollment Policy is showing as not configured.

  • Hi KAG,

    Interesting. I’d almost expect the lookup in the policy to be on the wrong layer (which is something that you can check using rsop.msc).

    Anyway, that brings us to the old CA registrations. For this, you need to perform the steps in https://support.microsoft.com/en-us/help/889250/how-to-decommission-a-windows-enterprise-certification-authority-and-r, step 6. If you find more than one CA in
    public key services, be careful that you only remove the entries specifically referring to the mail1.my.domain machine / mail1 CA and not to any other CA. This will clear the message as you mentioned, but
    may replace it with another one to the effect that no CA at all can be found.

    Kind Regards,

  • Hi KAG,

    Interesting. I’d almost expect the lookup in the policy to be on the wrong layer (which is something that you can check using rsop.msc).

    Anyway, that brings us to the old CA registrations. For this, you need to perform the steps in https://support.microsoft.com/en-us/help/889250/how-to-decommission-a-windows-enterprise-certification-authority-and-r, step 6. If you find more than one CA in
    public key services, be careful that you only remove the entries specifically referring to the mail1.my.domain machine / mail1 CA and not to any other CA. This will clear the message as you mentioned, but
    may replace it with another one to the effect that no CA at all can be found.

    Kind Regards,

    I revoked the certificates for this server, and for whatever reason I’m still getting the error.

  • Hi KAG,

    You may be helped better by hiring a consultant in this case, since he can observe and solve the problem in real time. Sorry.

    Kind Regards,

Содержание

  1. Client behavior
  2. Pended request processing
  3. Certificate update and enrollment
  4. Epilogue
  5. Windows Server 2016 – CertificateServicesClient-AutoEnrollment Event >

После установки службы CEP у вас появляется адрес HTTP, который указывает на сервер CEP и этот адрес имеет вид:

где auth_protocol указывает на протокол аутентификации клиента на сервере CEP. Это может быть Kerberos (только для доменных клиентов), Password или Certificate. Вот этот адрес нужно добавить в настройки групповой политики. Для этого откройте редактор групповой политики (gpmc.msc или gpedit.msc для недоменных машин) и в секции: Computer ConfigurtionWindows SettingsSecurity SettingsPublic Key Policies настроить параметр Certificate Services Client — Certificate Enrollment Policy. В свойствах следует включить эту политику и вы увидите окно Certificate Enrollment Policy list и в котором уже одна политика будет определена. Предопределённую политику следует удалить совсем и кнопкой Add добавить новую. В открывшемся окне вставить эту ссылку, указать нужный тип аутентификации и нажать Validate. В результате вы должны получить нечто вроде такого:

fig.1

Если вам это удалось сделать, значит клиент смог успешно пообщаться с сервером XCEP и CES. Причём, вы увидите, что клиент по этой ссылке смог найти название данной политики и вставить её в окошко:

И таким образом вы можете добавлять несколько различных адресов политик, которые могут относиться к различным организациям. Причём, организация может развернуть несколько серверов XCEP для обеспечения высокой доступности, тогда вы можете добавлять несколько адресов серверов CEP и они будут линковаться к одной политике.

Следует чётко понимать, что на предыдущей картинке вы видите коллекцию серверов CEP (Policy collection). Каждое имя уникально идентифицирует политику, которая может поддерживаться несколькими серверами CEP. Чтобы посмотреть сколько серверов CEP обслуживают ту или иную политику, выделите нужную политику и нажмите Properties. В результате вы увидите нечто похожее на это:

Уникальность политики определяется по её GUID’у. В этом окне может формироваться список всех серверов CEP, которые обслуживают одну и ту же политику (с одинаковым GUID’ом). По умолчанию для всех политик включается разрешение автоэнроллмента.

Примечание: галочка Enable for automatic enrollment and renewal не является самодостаточной и зависит от классической политики автоэнроллмента. Если автоэнроллмент отключен, то соответственно, автоматическая подача заявок на сертификаты производиться не будет.

Как обычно, триггер автоэнроллмента устанавливается в групповых политиках. Для его установки необходимо в редакторе групповой политики выключить следующие опции:

  • создать новый объект групповой политики или отредактировать существующую политику по адресу:
    Computer Configuration –> Windows Settings –> Security Settings –> Public Key Policies –> Certificate Services Client — Autoenrollment
    данный элемент политики следует установить в состояние Enabled, поставить галочку Update certificates that use certificate templates и при необходимости выбрать автоматическое обновление просроченных сертификатов и удалении отозванных сертификатов из хранилища.
  • Те же параметры настраиваются и в секции User Configuration, чтобы обеспечить автоматическое распространение пользовательских сертификатов. Это могут быть сертификаты EFS, подписи электронной почты или сертификаты для аутентификации пользователей:
    User Configuration –> Windows Settings –> Security Settings –> Public Key Policies –> Certificate Services Client — Autoenrollment
  • прилинкуйте созданную или отредактированную политику к нужному OU (чаще всего её применяют для всего домена).

Примечание: для успешного энроллмента сертификатов на основе новых шаблонов (для которых у клиента ещё нет ни одного сертификата) галочка Update certificates that use certificate templates обязательна!

В общем смысле, новый автоэнроллмент работает примерно так:

fig.4

Client behavior

Примечание: по причине громоздкости текста, я не буду приводить содержание ответа сервера XCEP. Но его cтруктуру можно увидеть в §4.1.1.2 (GetPoliciesResponse Response) документа [MS-XCEP]. Поэтому я буду подразумевать, что вы ознакомились с его примерным содержанием.

Когда срабатывает триггер автоэнроллмента, клиент считывает параметры из реестра:

Данные разделы реестра содержат настройки автоэнроллмента для конфигурации компьютера и пользователя, соответственно (более подробней о содержимом этих разделов реестра читайте во второй части). А так же будет считывать следующие ключи реестра:

Данные ключи будут содержать подключи политик. Каждому подключу политики присваивается уникальный GUID и внутри него будет содержаться необходимая информация о каждой политике, как URI, метод аутентификации, «стоимость» политики и флаги автоэнроллмента. После этого происходит сортировка политик по следующим правилам:

  • сортируются по «стоимости» политики. Политика с меньшей стоимостью будет более приоритетной и политика с большей стоимостью будет менее приоритетной, соответственно. Если 2 и более политик имеют одинаковую стоимость, то идёт второй уровень сортировок по методу аутентификации (в порядке приоритета):
  • используется аутентификация Kerberos;
  • используется анонимная аутентификация;
  • остальные политики используются в том порядке, в каком они записаны в реестре.

Когда политики отсортированы, клиент подключается к серверу XCEP из каждой политики по HTTPS. Если по какой-то ссылке не удаётся подключиться или сервер возвращает ошибку (SOAP), клиент переходит к следующей ссылке. Если в ответ получены политики, клиент извлекает следующие параметры:

  • адрес или адреса серверов CES;
  • список серверов CA, на работу с которыми настроен сервер CES. Один сервер CES должен быть настроен на работу с неболее, чем одним сервером CA;
  • список шаблонов и их параметры.

Pended request processing

Как и в случае с ACR, клиент после всех подготовительных процедур пытается получить сертификаты в ответ на запросы. Как мы уже знаем, запросы хранятся в контейнере Certificate Enrollment Requests. Сперва клиент удаляет все запросы, которые старше 60 дней, а затем посылает запрос на CES для выяснения статуса каждого запроса. Если в ответ на запрос был получен сертификат, то он помещается в список ToBeAdded. Если статус запроса Denied, то запрос удаляется. Если статус неизвестен, клиент переходит к следующему запросу.

Certificate update and enrollment

После обработки всех ожидающих запросов, клиент проверяет статус каждого существующего сертификата. Если сертификат отозван или его срок истёк, он помещается в список ToBeDeleted.

Примечание: просроченные сертификаты будут помещены в этот список только если в групповой политике выставлен флаг Renew expired certificates, update pending certificates, and remove revoked certificates и сертификат не используется для шифрования.

Если срок действия сертификата преодолел отметку 80% и шаблон этого сертификата находится в списке доступных шаблонов (который был получен после нескольких уровней фильтрации в предыдущих шагах), клиент отправляет запрос на обновление сертификата. При этом запрос подписывается текущим сертификатом. Если в реестре для текущего сертификата указан PolicyID, клиент будет пытаться найти тот же ID в списке политик CEP и запрос на обновление сертификата отправлять на сервер CES, который указан в политике. Если PolicyID для текущего сертификата не указан, то запрос будет отправляться на тот сервер CES, политика которого является по умолчанию (см fig.2). Если в ответ на запрос был получен сертификат, клиент помещает его в список ToBeAdded и записывает PolicyID, который использовался при энроллменте. Этот ID будет использоваться при обновлении сертификата.

Примечание: здесь и далее. Если по каким-либо причинам запрос подписать невозможно, клиент вместо обновления сертификата выполняет стандартную процедуру запроса сертификата с генерацией новой ключевой пары.

Примечание: здесь и далее. Если необходимый шаблон находится в выдаче более одного CA, клиент по очереди посылает запрос на каждый сервер CES в соответствии с их сортировкой.

Если версия шаблона (Major Version), который использовался при предыдущем энроллменте отличается от текущего Major Version шаблона, клиент посылает запрос на обновление сертификата. При этом запрос подписывается текущим сертификатом. Если в ответ на запрос был получен сертификат, клиент помещает его в список ToBeAdded.

Примечание: при каждом редактировании шаблона (кроме вкладки Security) изменяется только Minor Version. И держатели сертификатов этого шаблона не увидят, что шаблон изменён, поскольку они проверяют только Major Version. В случае, если после внесения изменений в шаблон необходимо переиздать все сертификаты этого шаблона, администратор должен изменить Major Version. Для этого администратор в оснастке certtmpl.msc должен выбарть нужный шаблон, нажать правой кнопкой и выбарть Reenroll All Certificate Holders. Этот шаг изменит Major Version шаблона и все клиенты, которые уже имеют сертификат данного шаблона его обновят, получив новый сертификат с новыми изменениями.

Если шаблон, который использовался при предыдущем энроллменте был заменён более новым (вкладка Superseded Templates нового шаблона содержит устаревший шаблон), клиент отправляет запрос на обновление сертификата. При этом запрос подписывается текущим сертификатом. Если в реестре для текущего сертификата указан PolicyID, клиент будет пытаться найти тот же ID в списке политик CEP и запрос на обновление сертификата отправлять на сервер CES, который указан в политике. Если PolicyID для текущего сертификата не указан, запрос будет отправляться на тот сервер CES, политика которого является по умолчанию (см fig.2). Если в ответ на запрос был получен сертификат, клиент помещает его в список ToBeAdded и записывает PolicyID, который использовался при энроллменте. Этот ID будет использоваться при обновлении сертификата.

Для необработанных шаблонов клиент отправляет запросы на получение сертификатов на основе этих шаблонов.Если в ответ на запрос был получен сертификат, клиент помещает его в список ToBeAdded и записывает PolicyID, который использовался при энроллменте. Этот ID будет использоваться при обновлении сертификата.

Когда все запросы, сертификаты и шаблоны были обработаны, триггер автоэнроллмента очищает список ToBeDeleted и все сертификаты из списка ToBeAdded копирует в контейнер Personal.

Epilogue

Вот, вроде и всё. На этом я завершаю цикл статей, посвящённых Certificate Autoenrollment во всех его вариациях и с рассказом о новых возможностях Windows 7 и Windows Server 2008 R2. Рассказал как умел и, мне кажется, материал получился достаточно исчерпывающим и у читателя должно появиться понимание принципа работы всех внутренних механизмов. Если что-то осталось непонятным или появились вопросы — комментарии внизу 🙂

Windows Server 2016 – CertificateServicesClient-AutoEnrollment Event >

I got some warnings regarding Event ID 64 CertificateServicesClient-AutoEnrollment

SOLUTION :

Open PowerShell and use command

If PowerShell can’t find it use the GUI

Open mmc and add the Certificates snap-in.

And search for the HASH Key in all stores.

Certificate seems to be expired.

Since this certificate relates to Azure AD Connect, which was uninstalled on this server, I can delete it…

Lately I am getting these warnings in the event log and today my RWW stopped working for a while .
It came back but I have no idea why . This is the only thing I am seeing repeating in the event log .
This is the only server and functions as a the WSUS and file server and the RWW service.
Is there anything I need to do to get rid of this ?
Can you point me in the direction of a resolution ?
Thanks in advance

Log Name: Application
Source: Microsoft-Windows-Certific ateService sClient-Au toEnrollme nt
Date: 6/4/2015 1:04:38 PM
Event ID: 64
Task Category: None
Level: Warning
Keywords: Classic
User: N/A
Computer:company .mls.local
Description:
Certificate for local system with Thumbprint 36 a2 4d af e3 ff 3e f4 81 9d 7a c1 84 49 14 87 3a 3b ee c0 is about to expire or already expired.
Event Xml:

rtificateS ervicesCli ent-AutoEn rollment» Gu >9937-FEB77 B9E1B43>» EventSourceName=»AutoEnrol lment» />
64&l t;/EventID >
0 on>
3 t;
0
0 >
0x80000000 000000 /Keywords& gt;
04:38.000Z » />
34456 5 tRecordID& gt;

Application el>
MLS-MAIN.m ls.local&l t;/Compute r>

local system
36 a2 4d af e3 ff 3e f4 81 9d 7a c1 84 49 14 87 3a 3b ee c0

Premium Content
Premium Content
  • Facebook
  • Twitter
  • LinkedIn
  • https://www.experts-exchange.com/questions/28685828/Microsoft-Windows-CertificateServicesClient-AutoEnrollment-error-ID-64-on-SBS-2008-server.html copy

This indicates that you are using a self-signed certificate for some services (probably Exchange and/or RWW), and that the certificate has or is about to expire. The easiest way to renew this certificate is from the Setup the Internet wizard, unless you are ALSO using a separate certificate that is not self-signed.

To check whether you are using only the self-signed certificate for Exchange (if you don’t already know), you can run the following command from the Exchange management shell:

This will display a list of the certificates that are being used for Exchange and what services (IMAP, POP, SMTP, SSL) they are assigned to. Then, compare the thumbprint shown in the event log message against the thumbprints displayed on this list to see which certificate has or is about to expire.

Thanks for you quick reply and help .

Below is what I found that matches the thumbprint

It says self-signed is false . Does that mean that I cannot renew it with the method you stated ?
Could this be the reason why the RWW suddenly was not working ?
What do I do ?

AccessRules :
.Security.AccessControl.Cr yptoKeyAcc essRule, System.Securi
ty.AccessControl.CryptoKey AccessRule >
CertificateDomains :
om, MCC-MOON.mcc.local>
HasPrivateKey : True
IsSelfSigned : False
Issuer : CN=mls-MCC-MOON-CA
NotAfter : 9/28/2013 1:39:23 PM
NotBefore : 9/29/2011 1:39:23 PM
PublicKeySize : 2048
RootCAType : Unknown
SerialNumber : 610FF47B00000000001B
Services : IMAP, POP, SMTP
Status : Invalid
Subject : CN=remote.thecompany.com
Thumbprint : 36A24DAFF3FF3EF4819D7AD184 4914873A3B FEC0

Sorry for the delayed reply; I was away for a few days.

The issuing server is listed as: CN=mls-MCC-MOON-CA. This looks like a self-signed certificate to me, so I’m not sure why it says it’s not. It also looks like it expired some time ago. But the thumbprint is not the same as the one in the event log entry:

Event log entry: 36a24dafe3ff3ef4819d7ac184 4914873a3b eec0
Your post: 36A24DAFF3FF3EF4819D7AD184 4914873A3B FEC0

The differences are small but they are there. Can you post the complete list of certificates?

Windows 10: CertificateServicesClient-AutoEnrollment Warning Event ID 64

Discus and support CertificateServicesClient-AutoEnrollment Warning Event ID 64 in Windows 10 Performance & Maintenance to solve the problem; Hi, this is a new Warning in my laptop, never seen it before with previous versions of Windows 10. During the first 3 days after upgrading to Fall…
Discussion in ‘Windows 10 Performance & Maintenance’ started by bo elam, Oct 21, 2017.

  1. CertificateServicesClient-AutoEnrollment Warning Event ID 64

    Hi, this is a new Warning in my laptop, never seen it before with previous versions of Windows 10. During the first 3 days after upgrading to Fall Creators Update, I didn’t get any. But yesterday, for the first time, an CertificateServicesClient-AutoEnrollment Warning Event ID 64 was logged in Events viewer. Today, I got another one after starting the laptop.

    I searched Google and found that the Warning has something to do with an expired certificate. I know nothing about certificates or how to properly handle something like this, I found this link below, it suggest to use Troubleshooting/System Maintenance. The instructions are easy to follow and carry on.
    Expired Certificate — Microsoft Community

    But my questions are, Is this something new with FCU? Are other people getting this Warning 64? Should Microsoft fix this on its own or should I run System maintenance? Is this a benign Warning event that can be ignored?

    My W10 is running perfect, I cant find nothing wrong with it. I even find less Warning and Errors being logged in Events viewer with this version than before but I never seen this one and it seems its gonna show up every day unless it gets taken care of.

    Appreciate your help

    Bo

    🙂

  2. Win10-certification problem

    Certificate for local system with Thumbprint 54 58 b5 9e 86 da fc 61 dc bc 55 75 53 14 09 3d 6e 1f b1 d3 is about to expire or already expired.

    Log name — Application

    Event Id — 64 , Source -CertificateServicesClient-AutoEnrollment

    Please help me solve the problem for ever.

  3. Expired Certificate

    Hello everyone. I received a call today from an HP Rep. He informed me that HP was receiving notifications, that I had a certificate that was approaching expiration or had already expired. Our discussion ended when he requested to have remote access to
    my computer for a one time fee of $99.00. He assured me that all would be well. I researched the event id online and there are many who are receiving this error. I did track down the certificate and it did expire in February.

    Would you please help with steps to correct the error? THANKS!

    Log Name: Application

    Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment

    Date: 5/28/2017 4:02:28 AM

    Event ID: 64

    Task Category: None

    Level: Warning

    Keywords: Classic

    User: N/A

    Computer: RFE-TAMPA

    Description:

    Certificate for local system with Thumbprint 18 c8 d5 12 74 b1 3e f6 d1 98 59 a0 a2 01 3d 32 5b 3a 10 9a is about to expire or already expired.

    Event Xml:

    <Event xmlns=»http://schemas.microsoft.com/win/2004/08/events/event»>

    <System>

    <Provider Name=»Microsoft-Windows-CertificateServicesClient-AutoEnrollment» Guid=»{F0DB7EF8-B6F3-4005-9937-FEB77B9E1B43}» EventSourceName=»AutoEnrollment» />

    <EventID Qualifiers=»32768″>64</EventID>

    <Version>0</Version>

    <Level>3</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x80000000000000</Keywords>

    <TimeCreated SystemTime=»2017-05-28T08:02:28.136379300Z» />

    <EventRecordID>6927</EventRecordID>

    <Correlation />

    <Execution ProcessID=»0″ ThreadID=»0″ />

    <Channel>Application</Channel>

    <Computer>RFE-TAMPA</Computer>

    <Security />

    </System>

    <EventData>

    <Data Name=»Context»>local system</Data>

    <Data Name=»ObjId»>18 c8 d5 12 74 b1 3e f6 d1 98 59 a0 a2 01 3d 32 5b 3a 10 9a</Data>

    </EventData>

    </Event>

  4. CertificateServicesClient-AutoEnrollment Warning Event ID 64

    I ran System Maintenance, it found nothing. So, I still dont know what to do to solve the message. The Warning doesn’t seem to have any effect in the laptop but I wonder if a certificate that’s about to expire or has already expired can create problems later.

    Bo

  5. Hey bo elam,
    1. It should be safe to ignore the warning.
    2. I haven’t see that warning on either of my pcs with FCU
    3. I do see the warning in my Insider Preview (FCU) and I think it has to do with Xbox Live looking at it (XBL Client IPsec Issuing CA) and it appears it expired 10-15-2017

    Note: I don’t use the Xbox Live stuff (actually uninstalled all of it), this might be why I don’t see the warning or have the certificate.

    Note: I’m not recommending this, but if you want to get rid of the error … ie: get rid of the certificate *Smile

    Right Click Start > Run > type mmc > press ENTER
    On the File Menu > Click Add/Remove Snap-in > Click Certificates > Click Add
    Click Computer Account > click Next
    Click Finish > Click OK
    In the console tree, Expand Certificates > Personal > Certificates
    You should see the XBL Client IPsec Issuing CA
    Right Click on it > All tasks > Export
    Follow the Export Wizard > Export it as a x509 (.cer) > Give it a name (example: xbl-client-ipsec.cer)
    Right Click on it > Delete > Confirm Delete
    Close the mmc > Say NO when asked if you want to save Console

  6. hi guys, im also getting the same event id 64 on a fresh install of fall creators update 1709. i did some digging around on mmc, the certificate belongs to xbox live app as mentioned above (xbl ipsec) . the problem is that the certificate is only renewing for 1 day at a time. i know a few people on different forums that are experiencing the same thing. i tried to manually renew the certificate as a new and also as same but no luck! i also deleted the certificate but when i restarted the computer it only renewed for 1 day lol i remember seeing this issue a few months ago with the previous creators update. i also removed the xbox app through powershell and reinstalled the app through the store with no luck! why is this app only renewing for 1 day at a time? maybe a xbox app update from microsoft will fix it

  7. Thanks, Eagle51. I ll ignore the warning, thats what I ll do. I dont use Xbox Live or anything like it either. I uninstalled all Store apps that an uninstaller is provided but preferred to leave the rest alone and just ignore them. I update them manually but don’t do nothing with them.

    Bo

  8. CertificateServicesClient-AutoEnrollment Warning Event ID 64

    Thanks for your reply, hbordon727. Very helpful as well. Perhaps you are right and a future Xbox live update takes care of the certificate.

    I never saw this Warning before with previous versions of W10. Started seeing it 3 days after installing FCU. But you say you did. Did the Warning eventually went away on its own when you were getting it in Creators Update?

    Bo

  9. I have this same Event ID 64 in the Event Viewer. It is indeed an expired X-Box Live certificate.

    CertificateServicesClient-AutoEnrollment Warning Event ID 64 [​IMG]

  10. I haven’t gotten the expired Certificate Event today, perhaps MS has silently fixed it. I was getting a Warning after starting or rebooting the laptop, and then one more about 8 hours later. I am going to turn off the laptop in a little while and restart it later, that probably will tell the story (really fixed or not).

    Bo

  11. I didn’t get the Warning yesterday at all, but I am getting it again today. So, I guess this is not fixed. The certificate is now showing today’s date. *Smile

    Bo

  12. Still not fixed. It really annoys me since there are several records of this event per day.
    Does anyone know some kind of trick to disable this particular event from logging?

  13. CertificateServicesClient-AutoEnrollment Warning Event ID 64

Thema:

CertificateServicesClient-AutoEnrollment Warning Event ID 64

  1. CertificateServicesClient-AutoEnrollment Warning Event ID 64 — Similar Threads — CertificateServicesClient AutoEnrollment Warning

  2. how to fix CertificateServicesClient-CertEnroll event ID 86

    in Windows 10 Gaming

    how to fix CertificateServicesClient-CertEnroll event ID 86: Usually when I shut down a heavy program like MW 2022, or when I’m just surfing the web, my pc will either freeze and stay frozen, blue screen and reboot and/or just restart out of the blue. CertificateServicesClient-CertEnroll Enent ID 86 SCEP Certificate enrollment…
  3. how to fix CertificateServicesClient-CertEnroll event ID 86

    in Windows 10 Software and Apps

    how to fix CertificateServicesClient-CertEnroll event ID 86: Usually when I shut down a heavy program like MW 2022, or when I’m just surfing the web, my pc will either freeze and stay frozen, blue screen and reboot and/or just restart out of the blue. CertificateServicesClient-CertEnroll Enent ID 86 SCEP Certificate enrollment…
  4. Event ID:86 AMD CertificateServicesClient-CertEnroll failure

    in Windows 10 Gaming

    Event ID:86 AMD CertificateServicesClient-CertEnroll failure: Before I had a amd CPU R9 5900x and an NVIDIA GPU that I recently replaced with an RX 6900XT. Did a clean reinstall of win 11 with all the latest updates for BIOS, MB, CPU, GPU. Any time I play a game I crash and my pc becomes unresponsive and I have to switch power off the…
  5. Event ID:86 AMD CertificateServicesClient-CertEnroll failure

    in Windows 10 Software and Apps

    Event ID:86 AMD CertificateServicesClient-CertEnroll failure: Before I had a amd CPU R9 5900x and an NVIDIA GPU that I recently replaced with an RX 6900XT. Did a clean reinstall of win 11 with all the latest updates for BIOS, MB, CPU, GPU. Any time I play a game I crash and my pc becomes unresponsive and I have to switch power off the…
  6. CertificateServicesClient Event ID 64

    in Windows 10 Performance & Maintenance

    CertificateServicesClient Event ID 64: Since fall creators update have this in event viewer no other problems.

    Warning 20/10/2017 15:42:19 CertificateServicesClient-AutoEnrollment 64 None
    Certificate for local system with Thumbprint bc 12 3b b8 35 dc 72 9b 43 95 af 52 cc 5f 05 28 8d e3 28 af is about to expire…

  7. Event ID 1 warning & Event ID 2 error

    in Windows 10 Performance & Maintenance

    Event ID 1 warning & Event ID 2 error: Hello,
    After Fall Creators update I’m seeing 1 error and 1 warning in the Event Viewer which I’m not able to resolve.

    Event ID 1
    The backing-file for the real-time session «DefenderApiLogger» has reached its maximum size. As a result, new events will not be logged to…

  8. Event ID 64?

    in Windows 10 Support

    Event ID 64?: I just started getting this error everytime I reboot and during random use, it says Certificate for local system with Thumbprint ae 22 de 20 00 9d 5e 94 81 7a 12 38 0d 90 fe 9f 40 9d 62 17 is about to expire or already expired. Is this something I should be concerned about?…
  9. Event Warning 64

    in Windows 10 Support

    Event Warning 64: Have a certificate expired or soon to expire and it belongs to google portablewares; I can bring it up in the mmc but when I try to get new key it says enrollment error. Do I need this certificate or just ignore the warning. Is it possible that when it does actually expire…
  10. Warning Event ID 4101

    in Windows 10 Support

    Warning Event ID 4101: Hi TenForumers.
    Few days ago I found some strange warnings concerning the display driver (event ID 4101):
    «Display driver amdkmdap stopped responding and has successfully recovered».
    After trying this and that with no avail, I noticed these warning were raised when I was…

Users found this page by searching for:

  1. Warning 2/21/2019 8:48:36 PM CertificateServicesClient-AutoEnrollment 64 None

    ,

  2. Certificate for local system with Thumbprint c8

    ,

  3. ertificateServicesClient-AutoEnrollment expired

    ,

  4. ertificateServicesClient-AutoEnrollment 64,
  5. event ID 64 certificateservicesclient-autoenrollment,
  6. event id 64 warning certificate for local system with thumbprint is about to expire,
  7. event 64 certificateservicesclient autoenrollment,
  8. CertificateServicesClient-AutoEnrollment event idea 4,
  9. event id 14 Microsoft-Windows-CertificateServicesClient-CertEnroll,
  10. event 64 cert thumbprint,
  11. certificateservicesclient-autoenrollment thumbprint,
  12. windows 10 event viewer id for auto-enrollment,
  13. HTL-RDG01 64 Warning Microsoft-Windows-CertificateServicesClient-AutoEnrollment Application 13/06/2019 03:29:38,
  14. which certicficate CertificateServicesClient-AutoEnrollment(64-none),
  15. event id 64 source certificate services client autoenrollment


Windows 10 Forums

  • Remove From My Forums
  • Question

  • Certificate Services Client UserTask fails on every attempt.  Log details below.  Admin user on Win7 Ultimate x64.  Not a domain computer, but occasionally connect via VPN to domain computer.  Any assistace appreciated.

    *********

    Log Name:      Microsoft-Windows-TaskScheduler/Operational
    Source:        Microsoft-Windows-TaskScheduler
    Date:          12/9/2011 2:27:35 PM
    Event ID:      202
    Task Category: Action failed
    Level:         Error
    Keywords:     
    User:          SYSTEM
    Computer:      Server_2
    Description:
    Task Scheduler failed to complete task «Certificate Services Client Task Handler» , instance «{6e071813-093e-485e-9809-a61cb5a2e1e5}» , action «MicrosoftWindowsCertificateServicesClientUserTask» . Additional Data: Error Value: 2147549183.
    Event Xml:
    <Event xmlns=»http://schemas.microsoft.com/win/2004/08/events/event»>
      <System>
        <Provider Name=»Microsoft-Windows-TaskScheduler» Guid=»{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}» />
        <EventID>202</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>202</Task>
        <Opcode>102</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime=»2011-12-09T20:27:35.809358600Z» />
        <EventRecordID>69830</EventRecordID>
        <Correlation ActivityID=»{6E071813-093E-485E-9809-A61CB5A2E1E5}» />
        <Execution ProcessID=»940″ ThreadID=»6808″ />
        <Channel>Microsoft-Windows-TaskScheduler/Operational</Channel>
        <Computer>Server_2</Computer>
        <Security UserID=»S-1-5-18″ />
      </System>
      <EventData Name=»ActionFailure»>
        <Data Name=»TaskName»>Certificate Services Client Task Handler</Data>
        <Data Name=»TaskInstanceId»>{6E071813-093E-485E-9809-A61CB5A2E1E5}</Data>
        <Data Name=»ActionName»>MicrosoftWindowsCertificateServicesClientUserTask</Data>
        <Data Name=»ResultCode»>2147549183</Data>
      </EventData>
    </Event>

Answers

  • Hi,

    I would like to verify what VPN client is used. When will the error occur?

    I suggest updating or reinstalling the VPN client. Also test the issue in
    clean boot.

    Best Regards,

    Niki


    Niki Han

    TechNet Community Support

    • Marked as answer by

      Wednesday, December 21, 2011 9:19 AM

  • Remove From My Forums
  • Question

  • Certificate Services Client UserTask fails on every attempt.  Log details below.  Admin user on Win7 Ultimate x64.  Not a domain computer, but occasionally connect via VPN to domain computer.  Any assistace appreciated.

    *********

    Log Name:      Microsoft-Windows-TaskScheduler/Operational
    Source:        Microsoft-Windows-TaskScheduler
    Date:          12/9/2011 2:27:35 PM
    Event ID:      202
    Task Category: Action failed
    Level:         Error
    Keywords:     
    User:          SYSTEM
    Computer:      Server_2
    Description:
    Task Scheduler failed to complete task «Certificate Services Client Task Handler» , instance «{6e071813-093e-485e-9809-a61cb5a2e1e5}» , action «MicrosoftWindowsCertificateServicesClientUserTask» . Additional Data: Error Value: 2147549183.
    Event Xml:
    <Event xmlns=»http://schemas.microsoft.com/win/2004/08/events/event»>
      <System>
        <Provider Name=»Microsoft-Windows-TaskScheduler» Guid=»{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}» />
        <EventID>202</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>202</Task>
        <Opcode>102</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime=»2011-12-09T20:27:35.809358600Z» />
        <EventRecordID>69830</EventRecordID>
        <Correlation ActivityID=»{6E071813-093E-485E-9809-A61CB5A2E1E5}» />
        <Execution ProcessID=»940″ ThreadID=»6808″ />
        <Channel>Microsoft-Windows-TaskScheduler/Operational</Channel>
        <Computer>Server_2</Computer>
        <Security UserID=»S-1-5-18″ />
      </System>
      <EventData Name=»ActionFailure»>
        <Data Name=»TaskName»>Certificate Services Client Task Handler</Data>
        <Data Name=»TaskInstanceId»>{6E071813-093E-485E-9809-A61CB5A2E1E5}</Data>
        <Data Name=»ActionName»>MicrosoftWindowsCertificateServicesClientUserTask</Data>
        <Data Name=»ResultCode»>2147549183</Data>
      </EventData>
    </Event>

Answers

  • Hi,

    I would like to verify what VPN client is used. When will the error occur?

    I suggest updating or reinstalling the VPN client. Also test the issue in
    clean boot.

    Best Regards,

    Niki


    Niki Han

    TechNet Community Support

    • Marked as answer by

      Wednesday, December 21, 2011 9:19 AM

0 0 голоса
Рейтинг статьи
Подписаться
Уведомить о
guest

0 комментариев
Старые
Новые Популярные
Межтекстовые Отзывы
Посмотреть все комментарии

А вот еще интересные материалы:

  • Яшка сломя голову остановился исправьте ошибки
  • Ясность цели позволяет целеустремленно добиваться намеченного исправьте ошибки
  • Ясность цели позволяет целеустремленно добиваться намеченного где ошибка
  • Cep 8 ошибка старлайн
  • Century age of ashes ошибка unreal engine