Consider the following scenario:
Additionally, notice that the following CA certificate signature was used in the first installation:Note <Object_ID> is the object identifier of the algorithm that was used for the original certificate for the sha1RSA element.
However, in this scenario, this signature has been changed to the following:This algorithm implies an error.
- You reinstall the Active Directory Certificate Services (ADCS) role.
- During the reinstallation process, the use existing keys option is selected.
Additionally, notice that the following CA certificate signature was used in the first installation:
Signature Algorithm:
Algorithm ObjectId: <Object_ID>Algorithm Parameters:...
However, in this scenario, this signature has been changed to the following:
Signature Algorithm:
Algorithm ObjectId: 1.2.840.113549.1.1.5 sha1RSA
Algorithm Parameters:
05 00