| Previous | Next |
| CERTSRV_E_TEMPLATE_DENIED | CERTSRV_E_ADMIN_DENIED_REQUEST |
CERTSRV_E_DOWNLEVEL_DC_SSL_OR_UPGRADE
CERTSRV_E_DOWNLEVEL_DC_SSL_OR_UPGRADE The CA contacted a domain controller that cannot meet the signed LDAP requirement used by Certificate Services. AD CS needs a supported domain-controller path or SSL for directory access.
What to check
- Identify the domain controller selected by the CA and verify its operating system, LDAP configuration, and connectivity.
- Check directory replication and DNS so the CA does not select an obsolete or incorrectly configured controller.
- Use a supported upgrade or LDAPS configuration path; do not weaken LDAP-signing security controls as a workaround.
Microsoft: Active Directory Certificate Services overview
Microsoft: Certificate Enrollment Web Service
Microsoft: Audit Certification Services
Looking for a different code? Search another status or error code.