| Previous | Next |
| CERTSRV_E_NO_POLICY_SERVER | CERTSRV_E_KEY_ATTESTATION_NOT_SUPPORTED |
CERTSRV_E_WEAK_SIGNATURE_OR_KEY
CERTSRV_E_WEAK_SIGNATURE_OR_KEY The requested signature algorithm or public-key length is below the minimum security requirements enforced by the client, template, CA, or operating system.
What to check
- Compare the request key algorithm, key length, and signature hash with the template Cryptography settings and current organizational crypto policy.
- Use a supported modern key provider and algorithm instead of lowering the minimum requirement to accept weak keys.
- When renewing legacy certificates, plan a controlled key rollover because a previous key may no longer meet the template requirements.
Microsoft: Certificate template concepts
Microsoft: Manage certificate templates
Microsoft: Active Directory Certificate Services overview
Looking for a different code? Search another status or error code.
