Autoenrollment error 6

From: Thorsten Hindermann (hindermath_at_msn.com)
Date: 10/05/05


Date: Wed, 5 Oct 2005 09:06:16 +0200

Hi folks!

We have in our DCs in the eventlog the autoenrollment error 6 with the
following description:
"Automatic certificate enrollment for local system could not find a valid
certificate template to match DomainController as specified in the group
policy automatic enrollment object. Enrollment will not be performed."

Source: AutoEnrollment
Type: Error
EventID: 6

We don't know why this issue occurs because the AD integrated Windows Sub-CA
runs normaly. We have create our own certifikate templates based/inherit
from the Microsoft templates and give them other names to match our
namingconvention. Is the other name the problem. And where could I see and
the "group policy automatic enrollment object"? With the GPEdit.msc or GPMC
I see only the normal PKI settings objects in den group policies. BTW the
autoenrollment function runs normaly because all DCs in the forest get a
valid certificate via autoenrollment.

Anybody who have an idea?

Thanx for information!

Thorsten Hindermann



Relevant Pages

  • Autoenrollment error number 6
    ... We have in our DCs in the eventlog the autoenrollment error 6 with the ... "Automatic certificate enrollment for local system could not find a valid ... the "group policy automatic enrollment object"? ...
    (microsoft.public.windows.server.security)
  • Re: Error enrolling machine certs
    ... Make sure that you have enable autoenrollment via Group Policy for computer ... For autoenrollment you either need to use a version 2 certificate template ... Automatic certificate enrollment for local system failed to ...
    (microsoft.public.windows.server.security)
  • Re: LDAP over SSL
    ... Somehow I missed errors in the Application log for AutoEnrollment like the ... Automatic certificate enrollment for local system failed to ... install the appropriate certificate' ...
    (microsoft.public.windows.server.active_directory)
  • Re: Wireless WPA on SBS not authenticating
    ... Automatic certificate enrollment for local system failed to contact the ... Enrollment will not be performed. ... certificate then tested on wireless. ... client PC or the router. ...
    (microsoft.public.windows.server.sbs)
  • Re: Web Certificate Enrollment security problem
    ... Enrollment works only with the NetBIOS Name and not with the FQDN. ... Svyatoslav Pidgorny, MS MVP - Security, MCSE ... access auditing and logging "issue and manage certificate requests" on ... Have seen that there is a component "Certsrv Request" when launching ...
    (microsoft.public.security)