Certificate template availability

Microsoft.Windows.RemoteAccess.Monitor.DA_OTP_HEURISTIC_CERT_TEMPLATE_GONE (UnitMonitor)

Knowledge Base article:

Summary

1. Certificate template configured for OTP authentication cannot be reached.

2. Certificate template used for OTP authentication is configured incorrectly.

Causes

1. The certificate template was deleted or renamed.

2. The Remote Access server does not have the required permissions to enroll the certificate template.

3. The DirectAccess user does not have the required read permissions for the certificate template.

4. The certificate template is not suitable for issuing OTP certificates. Possible causes:

a. Enhanced key usage is not smart card logon.

b. Key usage is not digital signature.

c. Validity period exceeds four hours.

d. Subject name is not set to be supplied in the request.

5. The certificate template is misconfigured.

Resolutions

1. Ensure that the certificate template exists on the domain controller.

2. Ensure that Remote Access server has read and enrollment permissions for the certificate template.

3. Ensure that DirectAccess users have read permissions for the certificate template

4. Ensure that the certificate template name is configured correctly in the Remote Access Setup Wizard.

Element properties:

TargetMicrosoft.Windows.RemoteAccess.DirectAccessServer.Class
Parent MonitorSystem.Health.AvailabilityState
CategoryCustom
EnabledTrue
Alert GenerateTrue
Alert SeverityError
Alert PriorityNormal
Alert Auto ResolveTrue
Monitor TypeMicrosoft.Windows.RemoteAccess.Monitor.Heuristic.MonitorType
RemotableTrue
AccessibilityPublic
Alert Message
Certificate template unavailable

Error Description - {0}
Error Cause - {1}
Error Resolution - {2}
RunAsDefault