Assume the following scenario:
- A network device enrollment service (NDES) is implemented in the network.
- The NDES server uses a domain account or a Group Managed Service Account (gMSA) for the identity of the SCEP IIS application pool.
- Requesting certificates via NDES fails with HTTP error code 503 (Server Unavailable).
- Calling the mscep and mscep_admin pages also fails with HTTP error code 500.
- Even after an iisreset or restart of the NDES server, no event appears after calling the mscep or mscsp_admin page that the NDES service has started or that there were errors.
The Network Device Enrollment Service (NDES) provides a way for devices that do not have an identifier in Active Directory (for example, network devices such as routers, switches, printers, thin clients, or smartphones and tablets) to request certificates from a certification authority. For a more detailed description, see the article "Network Device Enrollment Service (NDES) Basics„.
Possible causes:
Do you know TameMyCerts? TameMyCerts is an add-on for the Microsoft certification authority (Active Directory Certificate Services). It extends the function of the certification authority and enables the Application of regulationsto realize the secure automation of certificate issuance. TameMyCerts is unique in the Microsoft ecosystem, has already proven itself in countless companies around the world and is available under a free license. It can downloaded via GitHub and can be used free of charge. Professional maintenance is also offered.
This error occurs, among others, if the service account under which the SCEP application pool is running does not have the following rights:
- Log on as a Batch Job (SeBatchLogonRight), if it is a domain account or...
- Log on as a Service (SeServiceLogonRight), if it is a Group Managed Service Account (gMSA) acts.
This may be the case, among others, when hardening guidelines have been applied, such as the official Microsoft Security Baselines. See article "Required Windows security permissions for the Network Device Enrollment Service (NDES)„.