| Previous | Next |
| CERTSRV_E_UNKNOWN_CERT_TYPE | CERTSRV_E_TOO_MANY_SIGNATURES |
CERTSRV_E_CERT_TYPE_OVERLAP
CERTSRV_E_CERT_TYPE_OVERLAP should be read at the template renewal and validity geometry boundary. The template renewal period extends beyond its validity period, leaving no coherent interval in which normal renewal behavior can be scheduled. Compare the validity and renewal periods on the exact certificate-template version published by the CA; the two intervals must leave a valid renewal window.
What the code establishes
The certification authority is evaluating the request against a published certificate template. Capture the template OID, display name, major and minor version, CA template publication state, key and subject settings, validity and renewal periods, and any authorized-signature requirements.
Facts to preserve before changing state
| Record | Why it matters for this code |
|---|---|
| Template OID and version actually referenced by the request | Links the status to the exact template or CA transaction. |
| CA configuration, published-template set, and directory replication view | Preserves directory, request, and policy data evaluated by the CA. |
| Encoded request attributes, public-key properties, renewal state, and signer count | Avoids treating a new enrollment as proof that the original request was fixed. |
Code-specific checks:
- Read the effective validity and renewal periods in consistent units.
- Check whether the issuing CA certificate lifetime imposes a shorter practical validity.
- Change template timing deliberately and allow replication before retesting enrollment.
Build a timeline before changing state
CA decisions depend on directory and transaction state at a particular moment. Correlate template modification and publication, Active Directory replication, request submission, request ID assignment, policy-module evaluation, disposition changes, and any client continuation. This is especially important when a retry reaches a different domain controller or creates a new CA database row in a template renewal and validity geometry investigation.
- exported request and relevant attributes, template OID/version, CA configuration, and original request ID.
- CA operational events and request disposition history from the same transaction.
- Directory evidence showing the template and requester attributes as visible to the CA at evaluation time.
Isolation procedure
Submit a nonproduction request built directly from the same template with one known compliant key and identity. Then change only the policy dimension named by the status in this condition investigation. This avoids confusing template lookup, request construction, and CA issuance policy.
- Use one known-good control that changes only the suspected part of this path.
- Record where behavior first diverges in this path instead of judging only by the final application message.
Common wrong turns
This is a template design error rather than an individual request defect. Issuing from another template can make enrollment succeed while producing a certificate with different EKUs, key policy, subject rules, or lifetime. Treat it as a comparison, not the repair.
Proving the intended path works
The CA must accept a request that still uses the intended template and security policy, and the resulting certificate must contain the expected identity, usages, key, and lifetime in this condition investigation.
Technical references
These sources define the HRESULT and the relevant interface, protocol, or data format.
Looking for a different code? Search another status or error code.
