Jon Pennycook
Jon Pennycook 31.03.2021 19:34 (GMT+3) Export and import certificate templates with PowerShell

Never mind - I see "Existing OID reuse is not supported" in the Description of the Import- script.

Vadims Podāns
Vadims Podāns 31.03.2021 18:43 (GMT+3) Export and import certificate templates with PowerShell

> The OIDs of the certificate templates were different between the two forests - is this expected?

I would say that yes. IX509CertificateTemplateADWritable COM interface re-generates template OIDs.

Jon Pennycook
Jon Pennycook 31.03.2021 18:31 (GMT+3) Export and import certificate templates with PowerShell

Hi!

I tried to export the certificate templates from one forest and import them in another.  The OIDs of the certificate templates were different between the two forests - is this expected?

Jon

adrian sabas
adrian sabas 24.03.2021 22:34 (GMT+3) Add multiple Certificate Enrollment Service instances

hi got an issue using this it says

PS C:\Windows\system32> Install-AdcsEnrollmentWebService -applicationpoolidentity -CAConfig "<removed ca name>" -AuthenticationType username
Install-AdcsEnrollmentWebService : You cannot set this property because the application pool "WSEnrollmentServer"
already exists. The group or resource is not in the correct state to perform the requested operation. 0x8007139f
(WIN32: 5023 ERROR_INVALID_STATE)
At line:1 char:1
+ Install-AdcsEnrollmentWebService -applicationpoolidentity -CAConfig " ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : InvalidArgument: (:) [Install-AdcsEnrollmentWebService], EnrollmentServiceSetupException
    + FullyQualifiedErrorId : SetCESProperties,Microsoft.CertificateServices.Deployment.Commands.CES.InstallAdcsEnroll
   mentWebService

Vadims Podāns
Vadims Podāns 24.03.2021 20:36 (GMT+3) Add multiple Certificate Enrollment Service instances

On Windows Server 2019 you can use built-in Install-AdcsEnrollmentWebService command from AdcsDeployment module.