Autoenrollment error 6

From: Thorsten Hindermann (
Date: 10/05/05

Date: Wed, 5 Oct 2005 09:06:16 +0200

Hi folks!

We have in our DCs in the eventlog the autoenrollment error 6 with the
following description:
"Automatic certificate enrollment for local system could not find a valid
certificate template to match DomainController as specified in the group
policy automatic enrollment object. Enrollment will not be performed."

Source: AutoEnrollment
Type: Error
EventID: 6

We don't know why this issue occurs because the AD integrated Windows Sub-CA
runs normaly. We have create our own certifikate templates based/inherit
from the Microsoft templates and give them other names to match our
namingconvention. Is the other name the problem. And where could I see and
the "group policy automatic enrollment object"? With the GPEdit.msc or GPMC
I see only the normal PKI settings objects in den group policies. BTW the
autoenrollment function runs normaly because all DCs in the forest get a
valid certificate via autoenrollment.

Anybody who have an idea?

Thanx for information!

Thorsten Hindermann