top of page

Search


AD CS Says “Certificate Template Not Supported”
Windows certificate enrollment can fail with Event IDs 6, 13 and 53 and error 0x80094800 CERTSRV_E_UNSUPPORTED_CERT_TYPE, even when the certificate template appears to exist and be published correctly. On the CA, Event ID 77 may provide the more useful clue: the certificate template could not be loaded with 0x80070490 ERROR_NOT_FOUND.
Sep 53 min read


Signed WDAC: What Changes to Secure Boot, UEFI and Recovery?
An enforced WDAC policy is already a strong security control. Signing the policy takes it further because it protects the WDAC policy itself and links that protection into the UEFI and Secure Boot environment.
That turned out to be rather more significant than simply putting a digital signature on a .cip file.
In my home lab, systems that had previously booted happily from deployment USB media stopped doing so after the WDAC policy was signed. Hyper-V VMs showed similar
Sep 25 min read


When NTLM Hardening Breaks SID Lookup: Diagnosing RPC Endpoint Mapper and LSA Failures
NTLM restrictions and RPC hardening can interact in unexpected ways. This article walks through a real Windows lab failure where AD groups stopped resolving, SID translation failed and Windows misleadingly reported a broken domain trust.
The trust relationship between this workstation and the primary domain failed.
The account cannot be translated to a security identifier.
The specified domain either does not exist or could not be contacted.
Aug 306 min read
bottom of page