MZ@ !L!This program cannot be run in DOS mode. $Rؕ3}3}3}H̴3}H̱3}Rich3}PEL!  f*@e.rsrcpf@@@0H  0H`x 8 P ` p             0HZ\nzH|n|!##ZH$$%&xJ4qMUIJ9`/`*kbQ MUI en-USCertAdmin ClassCertView Class.CertManageModule Class (policy legacy support)Legacy Policy Module,CertManageModule Class (exit legacy support)Legacy Exit ModulePA Request IDBinary RequestOld CertificatePARequest Attributes Request Type Request FlagsRequest StatusRequest Status CodeRequest DispositionRequest Disposition MessageRequest Submission DateRequest Resolution DateRevocation DateEffective Revocation DateRevocation ReasonRequester NameRequester AddressRequest Distinguished NameRequest Binary NamePARequest Name TypeRequest Country/RegionRequest OrganizationRequest Organization UnitRequest Common Name Request City Request State Request TitleRequest First NameRequest InitialsRequest Last NameRequest Domain ComponentRequest Email AddressRequest Street AddressRequest Unstructured NameRequest Unstructured AddressRequest Device Serial Number Archived KeyKey Recovery Agent HashesSigner PoliciesSigner Application Policies Caller NameOfficerAttestation ChallengeEndorsement Key HashEndorsement Certificate HashIssued Request IDBinary CertificateCertificate HashCertificate Type Serial NumberIssuer Name IDCertificate Effective DateCertificate Expiration DateBinary Public KeyPublic Key AlgorithmPublic Key Algorithm ParametersIssued Distinguished NameIssued Binary NameIssued Name TypeIssued Country/RegionPAIssued OrganizationIssued Organization UnitIssued Common Name Issued City Issued State Issued TitleIssued First NameIssued InitialsIssued Last NameIssued Domain ComponentIssued Email AddressIssued Street AddressIssued Unstructured NameIssued Unstructured AddressIssued Device Serial NumberIssued SMIME CapabilitiesPAIssued Subject Key IdentifierCertificate TemplateTemplate Enrollment FlagsTemplate General FlagsPublic Key LengthUser Principal Name"Publish Expired Certificate in CRLTemplate Private Key FlagsExtension Request IDExtension NameExtension FlagsExtension Raw ValueAttribute Request IDAttribute NameAttribute ValuePA CRL Row ID CRL NumberCRL Minimum Base Number CRL Name ID CRL CountCRL This UpdateCRL Next UpdatePACRL This PublishCRL Next Publish CRL EffectiveCRL Propagation Complete CRL Raw CRLCRL Last PublishedCRL Publish AttemptsCRL Publish FlagsCRL Publish Status CodeCRL Publish Error InformationPAPPXppqqp$ 2Error Warning Information TCertificate Enrollment Policy Server xActive Directory Certificate Enrollment Policy Provider DCertificate Enrollment Server pMicrosoft-Windows-EnrollmentPolicyWebService/Admin dMicrosoft-Windows-EnrollmentWebService/Admin The Certificate Enrollment Policy Web Service has started. A service end point with URI %1 has been configured for this service. The client authentication scheme is %2. Use the Group PolicyManagement Consoleor the Certificates snap-in to configure clients with this Certificate Enrollment Policy Web Service information. A service end point with URI %1 has been configured for this service. The configuration of the client authentication scheme or the binding is not recommended. To fix the issue, open the web.config file and verify the binding and security settings. The only supported binding type for this service is wsHttpBinding. The security mode should be either Transportor TransportWithMessageCredential. When the security mode is Transport, the ClientCredentialType should be either Windows or Certificate. When the security mode is TransportWithMessageCredential, the ClientCredentialType should be UserName. The Certificate Enrollment Policy Web Service failed to initialize. Confirm that the Certificate Enrollment Policy Web Service is properly installed. Try to restart Internet Information Services (IIS) by using iisreset.exe. If the problem persists, enable tracing in the web.config file, restart IIS, attempt to obtain policy information from any client, and then contact Microsoft Customer Service and Support with the trace file information. %1 The Certificate Enrollment Policy Web Service has been stopped. The Active Directory certificate enrollment policy provider has been initialized to target the "%1" domain controller. ,The Active Directory certificate enrollment policy provider has been initialized to target the default domain controller for the current domain. The Active Directory certificate enrollment policy provider failed to initialize. Try to restart Internet Information Services (IIS) by using iisreset.exe. If the problem persists, enable tracing in the web.config file, restart IIS, attempt to obtain policy information from any client, and then contact Microsoft Customer Service and Support with the trace file information. %1 dThe Active Directory certificate enrollment policy provider failed to obtain policy information from Active Directory Domain Services (AD DS). The provider will attempt to read the information again in %1 milliseconds. If the problem persists, enable tracing in the web.config file, enable logging by using "certutil -setreg debug 0xffffffe3", restart IIS by using iisreset.exe, attempt to obtain policy information from any client, and then contact Microsoft Customer Service and Support with the information in the trace files and certenroll.log file. %2 tThere is no enterprise certification authority (CA) configured with the Certificate Enrollment Web Service in the current forest. Confirm that at least one enterprise CA is available in the forest and that at least one server running the Certificate Enrollment Web Service is configured to work with this CA. PNo certificate templates in the forest are configured to be sent as part of the policy response. Confirm that the server hosting the Certificate Enrollment Policy Web Service has Read permission to the required templates in this forest and that at least one server hosting the Certificate Enrollment Web Service is configured to work with the certification authorities (CAs) configured to issue the required templates. The certification authority (CA) "%1" cannot be sent as part of the policy response. Confirm that this CA is running and that at least one Certificate Enrollment Web Service is configured to use this CA . %2 The certificate template "%1" cannot be sent as part of the policy response. Use the Certificate Templates snap-in to confirm that this is a valid certificate template. Also confirm that at least one running certification authority (CA) has this template enabled and that at least one Certificate Enrollment Web Service is configured to use this CA. %2 The certification authority (CA) "%1" associated with the template "%2" cannot be sent as part of the policy response. Confirm that the CA is running and that at least one Certificate Enrollment Web Service is configured to use this CA. %3 The URI %2 used by the Certificate Enrollment Web Service for certification authority (CA) "%1" is invalid. Use Server Manager to configure the Certificate Enrollment Web Service to use a valid CA. %3 A certificate template %1 has been loaded. For additional information, please refer to the EventData section of the Details pane. A certification authority %1 has been loaded. For additional information, please refer to the EventData section of the Details pane. For a list of the OIDs which are loaded please refer to the "Details" pane. The Certificate Enrollment Policy Web Service cannot operate because Windows authentication is not compatible with key based renewal. To resolve this issue, remove the Certificate Enrollment Policy Web Service. Reconfigure the Setup options to disable key based renewal, or select either user name and password authentication or client certificate authentication, and then run Setup again. A service end point with URI %1 has been configured for this service. The client authentication scheme is %2. Only policies that contain certificate templates that are enabled for key based renewal will be returned to the client. Use the Group PolicyManagement Consoleor the Certificates snap-in to configure clients with this Certificate Enrollment Policy Web Service information. A service end point with URI %1 has been configured for this service. The client authentication scheme is %2. Only policies that contain certificate templates that are enabled for key based renewal will be returned to the client. Client certificates without subject information in the Active Directory database can be used to retrieve certificate templates. Use the Group PolicyManagement Consoleor the Certificates snap-in to configure clients with this Certificate Enrollment Policy Web Service information. pThe Certificate Enrollment Web Service has started. dThe Certificate Enrollment Web Service failed to start. Confirm that the Certificate Enrollment Web Service is properly installed, and restart Internet Information Services (IIS) by using iisreset.exe. If the problem persists, enable tracing in the web.config file, restart IIS, attempt to enroll for a certificate again from any client, and then contact Microsoft Customer Service and Support with the trace file information. %1 The Certificate Enrollment Web Service failed to start. The certification authority (CA) "%1" is not an enterprise CA. The Certificate Enrollment Web Service failed to start. A valid certification authority (CA) configuration is not specified in the web.config file. Please specify a CA configuration in the web.config file. |The Certificate Enrollment Web Service has been stopped. The Certificate Enrollment Web Service is in renewal-only mode. New enrollment requests cannot be processed when the Certificate Enrollment Web Service is in renewal-only mode. If you want to enable new enrollment requests, configure both the CA and the Certificate Enrollment Web Service for new enrollment requests. HThe Certificate Enrollment Web Service is attempting to use renewal-only mode, but certification authority (CA) "%1" does not support this mode. To use renewal-only mode, configure the Certificate Enrollment Web Service to use a CA that is installed on a computer that is running at least Windows Server 2008 R2. Then, configure the CA by running the following command on the CA: certutil -setreg policy\editflags +EDITF_ENABLERENEWONBEHALFOF. Otherwise, disable renewal-only mode. If no action is taken, subsequent requests will be rejected. The Certificate Enrollment Web Service cannot read the version or the configuration flags from certification authority (CA) "%1." On the Security tab of the CA property sheet, grant Read permission to the account used by the Certificate Enrollment Web Service application pool. If no action is taken, subsequent requests will be rejected. The Certificate Enrollment Web Service is attempting to use renewal-only mode, but certification authority (CA) "%1" does not support this mode. To use renewal-only mode, configure the CA by running the following command on the CA: certutil -setreg policy\editflags +EDITF_ENABLERENEWONBEHALFOF. Otherwise, disable renewal-only mode. If no action is taken, subsequent requests will be rejected. PThe Certificate Enrollment Web Service cannot operate because an incompatible configuration was selected. To resolve this issue, remove the Certificate Enrollment Web Service. If you want to use key based renewal, enable both client certificate authentication and renewal-only mode. If you want to use user name and password authentication or Windows authentication, disable key based renewal, and then run Setup again. The Certificate Enrollment Web Service is enabled for key based renewal. Client certificates without subject information in the Active Directory database can be used to renew certificates. 4VS_VERSION_INFO@%@%?*StringFileInfo040904B0LCompanyNameMicrosoft Corporation7FileDescriptionMicrosoft Active Directory Certificate Services Adminr)FileVersion6.3.9600.16384 (winblue_rtm.130821-1623)0InternalNameCertAdm.LegalCopyright Microsoft Corporation. All rights reserved.8OriginalFilenameCertAdmj%ProductNameMicrosoft Windows Operating SystemBProductVersion6.3.9600.16384DVarFileInfo$Translation PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING