| Previous | Next |
| STATUS_REVOCATION_OFFLINE_KDC | STATUS_KDC_CERT_EXPIRED |
STATUS_ISSUING_CA_UNTRUSTED_KDC
The domain controller certificate issuer is not trusted
This status is the KDC-side counterpart of certificate issuer trust problems. During smart-card or PKINIT authentication, the client and Windows logon path must be able to trust the domain controller certificate chain used by the KDC.
It often appears after CA migration, domain-controller certificate template changes, stale root distribution, or incomplete third-party CA deployment. Replacing the user card will not help if the KDC certificate chain is the rejected object.
What to inspect
- Validate root and intermediate CA distribution to clients and domain controllers.
- Check the domain controller certificate template, EKU and chain.
- Review certificate enrollment and auto-enrollment after CA changes.
References
- Microsoft Open Specifications: MS-PKCA PKINIT in Kerberos
- RFC 4556: PKINIT
- Microsoft: Smart card certificate requirements
- Microsoft Open Specifications: NTSTATUS values
- Microsoft: Enabling smart card logon with third-party CAs
Looking for a different code? Search another status or error code.