| Previous | Next |
| CERTSRV_E_SIGNATURE_COUNT | CERTSRV_E_ISSUANCE_POLICY_REQUIRED |
CERTSRV_E_SIGNATURE_REJECTED
CERTSRV_E_SIGNATURE_REJECTED The request contains signatures, but one or more of them do not meet the template’s application-policy or issuance-policy requirements.
What to check
- Inspect the signing certificate’s EKUs and issuance policies, then compare them with the template requirements.
- Verify that the signer is authorized for the exact certificate type and has not used an expired, revoked, or wrong-purpose certificate.
- Correct the enrollment-agent configuration rather than altering the target subject’s request to mask the authorization failure.
Microsoft: Certificate template concepts
Microsoft: Manage certificate templates
Microsoft: Audit Certification Services
Looking for a different code? Search another status or error code.