Event Id | 132 |
Source | Microsoft-Windows-CertificationAuthority |
Description | The certification authority (CA) was unable to perform a decryption operation. This error can occur when an advanced encryption algorithm such as Advanced Encryption Standard (AES) is used and the CA has not been configured to use a CryptoAPI Next Generation (CNG) key storage provider. If this error occurred during certificate enrollment, check the certificate template to confirm that advanced encryption for key archival is not enabled. |
Event Information | According to Microsoft : Cause This event is logged when the certification authority (CA) was unable to perform a decryption operation. Resolution Enable a decryption operation during certificate request processing To perform this procedure, you must have Manage CA permission, or you must have been delegated the appropriate authority. To identify and resolve an encryption error: 1.Check the event log on the certification authority (CA) for other event log messages related to certificate requests, such as CertificationAuthorityEvent 22. This event log message should contain the ID of the failed certificate request. 2. Click Start, point to Administrative Tools, and click Certification Authority. 3.Double-click Failed Requests. 4 Right-click the failed certificate request identified in the first step, point to All Tasks, and then click View Attributes/Extensions. 5. Click the Extensions tab, and click Certificate Template Information. Note the certificate template name. 6.Click Start, type Certtmpl.msc, and press ENTER. 7. Right-click the certificate template identified in step 5, and then click Properties. 8.Click the Request Handling tab.Under Archive subject's encryption private key, clear the Use advanced symmetric algorithm to send the key to the CA check box if it is selected, and then retry the certificate enrollment.Verify To perform this procedure, you must have permission to request a certificate. To confirm that certificate request processing is working properly: 1.Click Startcertmgr.msc, and then press ENTER. 2. If the 3.In the console tree, double-click Personal, and then click Certificates. 4.On the Action menu, point to All Tasks, and click Request New Certificate to start the Certificate Enrollment wizard. 5.Use the wizard to create and submit a certificate request for any type of certificate that is available. 6.Under Certificate Installation Results, confirm that the enrollment completes successfully and no errors are reported. You can also click Details to view additional information about the certificate. |
Reference Links | Event ID 132 from Source Microsoft-Windows-CertificationAuthority |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.