Requesting Certificates with ML-DSA-Based Keys Through the Network Device Enrollment Service (NDES)

With the May 2026 security update, Microsoft has added support for the ML-DSA algorithm in Active Directory Certificate Services.

In her documentary They do say that NDES is not compatible with ML-DSA,:

You can enroll ML-DSA certificates using the Certificates Microsoft Management Console (MMC) snap-in and certreq.exe. Enrollment through the Network Device Enrollment Service (NDES) is not currently available.

But that's not entirely true…

Continue reading „Beantragen von Zertifikaten mit auf ML-DSA basierenden Schlüsseln über den Registrierungsdienst für Netzwerkgeräte (NDES)“

Configuring an SSL certificate binding for Microsoft Internet Information Server (IIS) fails with an error message when using ML-DSA-based keys

Assume the following scenario:

  • A web server certificate was generated using an ML-DSA-based key pair.
  • We would like to integrate this with Internet Information Services (IIS).
  • The configuration fails with the following error message:
There was an error while performing this operation.

Details:

A specified logon session does not exist. It may already have been terminated. (Exception from HRESULT: 0x80070520)
Continue reading „Das Konfigurieren einer SSL-Zertifikatbindung für Microsoft Internet Information Server (IIS) schlägt fehl mit Fehlermeldung, wenn auf ML-DSA basierenden Schlüssel verwendet werden“

Requests for certificates using ML-DSA-based keys fail with the error message „The parameter is incorrect. 0x80070057 (WIN32: 87 ERROR_INVALID_PARAMETER)“

Assume the following scenario:

  • People are trying to apply for certificates using the ML-DSA algorithm.
  • The request fails with the following error message:
The parameter is incorrect. 0x80070057 (WIN32: 87 ERROR_INVALID_PARAMETER)
Continue reading „Die Beantragung von Zertifikaten mit auf ML-DSA basierenden Schlüsseln schlägt fehl mit Fehlermeldung „The parameter is incorrect. 0x80070057 (WIN32: 87 ERROR_INVALID_PARAMETER)““

Cryptographic Hardening of SCEP Transactions for the Network Device Enrollment Service (NDES)

The Simple Certificate Enrollment Protocol (SCEP) is an ancient protocol from the early 2000s. It does not use Transport Layer Security (TLS). Therefore, the protocol messages are encrypted at the transport layer.

When sending the certificate request to the NDES server, the client will sign the certificate request with the NDES server's CEP encryption certificate (which was previously communicated to it via the GetCACert message).

Upon receiving the issued certificate, the NDES server will encrypt the response using a self-signed certificate temporarily generated by the SCEP client.

In both cases, a symmetric encryption algorithm is used.

Continue reading „Kryptographische Härtung der SCEP-Transaktionen für den Registrierungsdienst für Netzwerkgeräte (Network Device Enrollment Service, NDES)“

Automatic Publication of Certificate Revocation Lists Following a Certificate Revocation

I often hear that PKI operators would like to see a new certificate revocation list issued immediately for revoked certificates.

Below, I would like to share some thoughts on why this approach is not ideal and propose a more elegant solution.

Continue reading „Automatische Veröffentlichung von Zertifikatsperrlisten nach einem Zertifikat-Widerruf“

What is the difference between „requesting“ and „renewing“ a certificate in the Windows ecosystem?

If you want to request or renew certificates on a Windows client using the Microsoft Management Console (MMC), you have several options—all of which achieve the same result but behave differently. Below, we’ll discuss the differences.

Continue reading „Was ist der Unterschied zwischen „Beantragen“ und „Erneuern“ eines Zertifikates im Windows-Ökosystem“
en_USEnglish