Requesting Certificates with ML-DSA-Based Keys Through the Network Device Enrollment Service (NDES)

With the May 2026 security update, Microsoft has added support for the ML-DSA algorithm in Active Directory Certificate Services.

In her documentary They do say that NDES is not compatible with ML-DSA,:

You can enroll ML-DSA certificates using the Certificates Microsoft Management Console (MMC) snap-in and certreq.exe. Enrollment through the Network Device Enrollment Service (NDES) is not currently available.

But that's not entirely true…

Continue reading „Beantragen von Zertifikaten mit auf ML-DSA basierenden Schlüsseln über den Registrierungsdienst für Netzwerkgeräte (NDES)“

Configuring an SSL certificate binding for Microsoft Internet Information Server (IIS) fails with an error message when using ML-DSA-based keys

Assume the following scenario:

  • A web server certificate was generated using an ML-DSA-based key pair.
  • We would like to integrate this with Internet Information Services (IIS).
  • The configuration fails with the following error message:
There was an error while performing this operation.

Details:

A specified logon session does not exist. It may already have been terminated. (Exception from HRESULT: 0x80070520)
Continue reading „Das Konfigurieren einer SSL-Zertifikatbindung für Microsoft Internet Information Server (IIS) schlägt fehl mit Fehlermeldung, wenn auf ML-DSA basierenden Schlüssel verwendet werden“

Requests for certificates using ML-DSA-based keys fail with the error message „The parameter is incorrect. 0x80070057 (WIN32: 87 ERROR_INVALID_PARAMETER)“

Assume the following scenario:

  • People are trying to apply for certificates using the ML-DSA algorithm.
  • The request fails with the following error message:
The parameter is incorrect. 0x80070057 (WIN32: 87 ERROR_INVALID_PARAMETER)
Continue reading „Die Beantragung von Zertifikaten mit auf ML-DSA basierenden Schlüsseln schlägt fehl mit Fehlermeldung „The parameter is incorrect. 0x80070057 (WIN32: 87 ERROR_INVALID_PARAMETER)““

How many Subject Alternative Names (SAN) do the Active Directory Certificate Services support?

Like any software Microsoft Active Directory Certificate Services are also subject to certain limitsimposed by their design.

What is not so obvious is the question of how many Subject Alternative Name (SAN) can be issued with the Microsoft certification authority.

The IETF RFC 5280 describes the structure for Subject Alternative Names as follows:

SubjectAltName ::= GeneralNames
Continue reading „Wie viele Alternative Antragstellernamen (engl. Subject Alternative Name, SAN) unterstützen die Active Directory Certificate Services?“

Details of the event with ID 33 of the source Microsoft-Windows-OnlineResponder

Event Source:Microsoft-Windows-OnlineResponder
Event ID:33 (0x21)
Event log:Application
Event type:Error
Symbolic Name:MSG_E_CACONFIG_CREATE_ENROLLMENT_REQUEST_FAILED
Event text (English):The Online Responder Service failed to create an enrollment request for the signing certificate template %2 for configuration %1.(%3).
Event text (German):The online responder service could not create registration requests for the signature certificate template "%2" for the configuration %1.(%3)
Continue reading „Details zum Ereignis mit ID 33 der Quelle Microsoft-Windows-OnlineResponder“
en_USEnglish