Details of the event with ID 22 of the source Microsoft-Windows-CertificationAuthority

Event Source:Microsoft-Windows-CertificationAuthority
Event ID:22 (0x16)
Event log:Application
Event type:Error
Symbolic Name:MSG_E_PROCESS_REQUEST_FAILED_WITH_INFO
Event text (English):Active Directory Certificate Services could not process request %1 due to an error: %2. The request was for %3. Additional information: %4
Event text (German):The request %1 could not be executed due to an error: %2. The request was for %3. More information: %4
Continue reading „Details zum Ereignis mit ID 22 der Quelle Microsoft-Windows-CertificationAuthority“

Details of the event with ID 23 of the source Microsoft-Windows-CertificationAuthority

Event Source:Microsoft-Windows-CertificationAuthority
Event ID:23 (0x17)
Event log:Application
Event type:Error
Symbolic Name:MSG_E_BADCERTLENGTHFIELD
Event text (English):Active Directory Certificate Services could not process request %1 due to an error: %2. The request was for %3. The certificate would contain an encoded length that is potentially incompatible with older enrollment software. Submit a new request using different length input data for the following field: %4
Event text (German):The request %1 could not be executed due to an error: %2. The request referred to %3. The certificate would contain an encoded length that may not be compatible with older versions of the enrollment software. Submit a new request with a different length in the following field: %4
Continue reading „Details zum Ereignis mit ID 23 der Quelle Microsoft-Windows-CertificationAuthority“

Details of the event with ID 10 of the source Microsoft-Windows-CertificationAuthority

Event Source:Microsoft-Windows-CertificationAuthority
Event ID:10 (0xA)
Event log:Application
Event type:Error
Symbolic Name:MSG_E_CANNOT_BUILD_CERT_OR_CHAIN
Event text (English):Active Directory Certificate Services were unable to build a new certificate or certificate chain: %1.
Event text (German):Failed to create a new certificate or certificate chain: %1.
Continue reading „Details zum Ereignis mit ID 10 der Quelle Microsoft-Windows-CertificationAuthority“

Details of the event with ID 15 of the source Microsoft-Windows-CertificationAuthority

Event Source:Microsoft-Windows-CertificationAuthority
Event ID:15 (0xF)
Event log:Application
Event type:Error
Event text (English):Active Directory Certificate Services did not start: Version does not match certif.dll.
Event text (German):The Active Directory certificate services have not been started: The version does not match "certif.dll".
Continue reading „Details zum Ereignis mit ID 15 der Quelle Microsoft-Windows-CertificationAuthority“

Details of the event with ID 16 of the source Microsoft-Windows-CertificationAuthority

Event Source:Microsoft-Windows-CertificationAuthority
Event ID:16 (0x10)
Event log:Application
Event type:Error
Event text (English):Active Directory Certificate Services did not start: Unable to initialize OLE: %1.
Event text (German):Active Directory certificate services failed to start: OLE could not be initialized: %1.
Continue reading „Details zum Ereignis mit ID 16 der Quelle Microsoft-Windows-CertificationAuthority“

Details of the event with ID 6 of the source Microsoft-Windows-CertificationAuthority

Event Source:Microsoft-Windows-CertificationAuthority
Event ID:6 (0x6)
Event log:Application
Event type:Information
Event text (English):Active Directory Certificate Services issued a certificate for request %1 for %2.
Event text (German):A certificate was issued for the request %1 for %2.
Continue reading „Details zum Ereignis mit ID 6 der Quelle Microsoft-Windows-CertificationAuthority“

Details of the event with ID 7 of the source Microsoft-Windows-CertificationAuthority

Event Source:Microsoft-Windows-CertificationAuthority
Event ID:7 (0x7)
Event log:Application
Event type:Warning
Symbolic Name:MSG_DN_CERT_DENIED
Event text (English):Active Directory Certificate Services denied request %1 because %2. The request was for %3.
Event text (German):The request %1 was rejected because %2. The request was for %3.
Continue reading „Details zum Ereignis mit ID 7 der Quelle Microsoft-Windows-CertificationAuthority“

Details of the event with ID 8 of the source Microsoft-Windows-CertificationAuthority

Event Source:Microsoft-Windows-CertificationAuthority
Event ID:8 (0x8)
Event log:Application
Event type:Information
Event text (English):Active Directory Certificate Services left request %1 pending in the queue for %2.
Event text (German):The %1 request from %2 has been queued.
Continue reading „Details zum Ereignis mit ID 8 der Quelle Microsoft-Windows-CertificationAuthority“

Details of the event with ID 9 of the source Microsoft-Windows-CertificationAuthority

Event Source:Microsoft-Windows-CertificationAuthority
Event ID:9 (0x9)
Event log:Application
Event type:Error
Symbolic Name:MSG_NO_POLICY
Event text (English):The Active Directory Certificate Services did not start: Unable to load an external policy module.
Event text (German):Active Directory Certificate Services failed to start: No external policy module could be loaded.
Continue reading „Details zum Ereignis mit ID 9 der Quelle Microsoft-Windows-CertificationAuthority“

Details of the event with ID 5 of the source Microsoft-Windows-CertificationAuthority

Event Source:Microsoft-Windows-CertificationAuthority
Event ID:5 (0x5)
Event log:Application
Event type:Error
Symbolic Name:MSG_BAD_REGISTRY
Event text (English):Active Directory Certificate Services could not find required registry information. The Active Directory Certificate Services may need to be reinstalled.
Event text (German):The required registry information could not be found. The Active Directory certificate services may need to be reinstalled.
Continue reading „Details zum Ereignis mit ID 5 der Quelle Microsoft-Windows-CertificationAuthority“

Change the signing algorithm of a certification authority hierarchy without issuing new certification authority certificates

Sometimes it may be necessary to change the Signature algorithm to subsequently change an already installed certification authority hierarchy.

This is often the case because one has installed them with PKCS#1 version 2.1 and unfortunately finds out afterwards that not all applications are compatible with the resulting certificates, and thus cannot use the hierarchy.

While it is relatively easy to change the signature algorithm for certificates issued by a certification authority, it is more difficult to do so for certification authority certificates.

Continue reading „Den Signaturalgorithmus einer Zertifizierungsstellen-Hierarchie ändern, ohne neue Zertifizierungsstellen-Zertifikate auszustellen“

The certification authority service does not start and throws the error message "The parameter is incorrect. 0x80070057 (WIN32: 87 ERROR_INVALID_PARAMETER)".

Assume the following scenario:

  • A certification authority is implemented in the network.
  • The certification authority service does not start.
  • When trying to start the Certification Authority service, you get the following error message:
The parameter is incorrect. 0x57 (WIN32: 87 ERROR_INVALID_PARAMETER)
Continue reading „Der Zertifizierungsstellen-Dienst startet nicht und wirft die Fehlermeldung „The parameter is incorrect. 0x80070057 (WIN32: 87 ERROR_INVALID_PARAMETER)““

Deploy PKCS#1 version 2.1 for a root CA (owned and issued certificates)

Before the Installation of a standalone root certification authority (Standalone Root CA) the question arises as to which cryptographic algorithms should be used.

Continue reading „PKCS#1 Version 2.1 für eine Stammzertifizierungsstelle (Root CA) einsetzen (eigenes und ausgestellte Zertifikate)“

Basics: key algorithms, signature algorithms and signature hash algorithms

When planning a public key infrastructure, the question arises as to which cryptographic algorithms it should use.

The main principles are explained below.

Continue reading „Grundlagen: Schlüsselalgorithmen, Signaturalgorithmen und Signaturhashalgorithmen“
en_USEnglish