Certificate enrollment policy server URI format

If you’re trying to request a certificate from a non-domain joined computer using Certificates console (CertMgr.msc or CertLM.msc) then you need to install on the server that hosts your Certificate Authority the following components:

(maybe you need just one of them but I’ve installed both)

and then enter its URI in the following format:

https://dc.example.local/ADPolicyProvider_CEP_Kerberos/service.svc/CEP

That’s it, folks!

This entry was posted in Infrastructure and tagged , . Bookmark the permalink.

2 Responses to Certificate enrollment policy server URI format

  1. Also the following for username/password authentication:

    https://<FQDN>/ADPolicyProvider_CEP_UsernamePassword/service.svc/CEP

  2. Pingback: Windows Enterprise CA - Certificate Services - xandi's blog

Leave a reply to Chris Parsons Cancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.