Original URL: | https://blogs.technet.microsoft.com/pki/2008/07/31/you-cannot-add-v2-or-v3-templates-after-an-inplace-upgrade-was-performed-on-a-windows-server-2008-enterprise-ca/ |
Post name: | You cannot add V2 or V3 templates after an inplace upgrade was performed on a Windows Server 2008 enterprise CA |
Original author: | MS2065 [MSFT] |
Posting date: | 2008-07-31T11:41:44+00:00 |
Technically, it is possible to install an enterprise CA on a Windows Server Standard edition. With this configuration, enterprise features of the certification authority are intentionally not available.
To enable the CA enterprise features, it is required to upgrade a Windows Server from Standard to Enterprise edition. To keep the existing enterprise CA configuration, it is recommended to just perform a Windows inplace upgrade. If you do this on a Windows Server 2008 you will recognize that only V1 certificate templates are available for assigning after the upgrade was performed.
To fix the problem, close the Certificate Services MMC snap-in and run the following commands with administrator permissions at a command-line on the CA computer:
certutil -setreg ca\setupstatus +512
net stop certsvc
net start certsvc
When you re-open the Certificate Services MMC snap-in, you are able to assign V1, V2 and V3 certificate templates to the certification authority.
[February 3, 2009 update] An official Microsoft Knowledgebase article is published under http://support.microsoft.com/kb/967332.
Comments: