Windows 2012 R2 EOS, ADCS/PKI and You. Are You Ready or Risking?

Is your ADCS/PKI running on Windows 2012 R2? Microsoft is ending its support of Windows Server 2012 R2 on October 10, 2023. This will officially spell the end of extended end-of-support (EOS). Released in October 2012, Windows Server 2012 passed the original EOS date over three years ago, on October 9, 2018. Microsoft will stop […]

Offline CA Maintenance – What Do You Really Need to Do?

In a previous post, I discussed the configuration and isolation of true offline Certificate Authorities. There I made reference to the fact that an offline CA is one that never sees the light of day, figuratively that is. The CA should be air-gaped from the network, which requires physical access to the CA to manage […]

Windows ADCS Migration and Modernization

Below are the key highlights, Q&A from our PKI Solutions “Office Hours”: The Migration Edition While our focus was on Windows Server 2012 R2 ADCS migration “common gotchas”, questions and concerns about this topic, and specifically how to align key, certificate infrastructure strategy with the cloud first approach, developer productivity and strategic business initiatives were all touched […]

You cannot download CA certificate from web enrollment pages

As part of joining PKI Solutions, several blog posts from my old site are re-posted here for visibility and thoroughness. When you try to download CA certificate from web enrollment pages you get a prompt message with unreadable proposed file name: Do you want to save certnew_cer?ReqID=CACert&Renewal=1&Enc=bin (1,09 KB) from And when you press ‘Save’ […]

Securing Public Key Infrastructure Whitepaper is Released!

Here’s a great new PKI whitepaper from Microsoft I contributed to prior to my departure. It hasn’t been widely publicized or distributed yet, but you can get it direct from Microsoft. Entitled “Securing Public Key Infrastructure” it is the most up to date set of best practices from Microsoft in years! Topics include: Planning a […]

OCSP Magic Number

The magic number is a value that states when CRLs will be processed over OCSP, specifically it is when the total number of cached OCSP responses from a single OCSP responder URL on behalf of a single certificate authority will stop performing OCSP and start processing CRLs. This will occur if the number of cached […]

Securing Active Directory Certificate Services: Protecting Your Digital Assets

Active Directory Certificate Services (ADCS) plays a crucial role in securing digital assets within organizations. However,even a single device can introduce vulnerabilities in the PKI (Public Key Infrastructure) environment. Understanding, implementing, and securing ADCS can be challenging, requiring organizations to proactively address potential risks. In this blog post, we will explore the risks associated with […]

The Requested Template is not Supported by this CA (Error 0x80094800)

Today I was working with a customer and they mentioned they had just been contacted about an enrollment problem on one of their CAs. They had recently added a template to one of their Windows Server 2012 R2 CAs. The template had been in use for a long time and is present on their other […]