TL;DR:/certsrv 不是普通网站,它依赖 AD CS、IIS、Windows 身份验证、CA 服务和正确的 DNS。先确认客户端能解析 CA 主机,再测 80/443,再查 IIS 是否存在 CertSrv 虚拟目录,最后查 CA 服务和权限。本文命令基于 Windows Server 2019/2022、PowerShell 5.1/7.4,日期:2026-08-26。
Prerequisites:先确认你在排查同一个问题
适用场景:浏览器访问 http://ca01/certsrv 或 https://ca01/certsrv 返回无法打开、401、403、404、500,或一直转圈。常见于企业内部给 AI 办公终端、RPA 主机、内网 Gemini 接入网关、代理审计网关签发证书时,证书申请页面不可用。
你需要一台域内 Windows 客户端、一台 CA/IIS 服务器管理员权限账号。不要一上来重装 AD CS。先收集状态,避免把 CA 数据库和模板权限搞坏。
1. 客户端侧:判断是 DNS、端口还是浏览器问题
1.1 查 DNS。把 ca01.contoso.local 替换成你的 CA Web Enrollment 主机名。
nslookup ca01.contoso.local
Expected output:
Name: ca01.contoso.local
Address: 10.10.20.15
如果返回 Non-existent domain,先修 DNS A 记录或客户端 DNS 后缀。不要用公网 DNS 解析内网 CA。
1.2 查端口。HTTP 默认 80,HTTPS 默认 443。
Test-NetConnection ca01.contoso.local -Port 80
Expected output:
ComputerName : ca01.contoso.local
RemoteAddress : 10.10.20.15
RemotePort : 80
TcpTestSucceeded : True
如果 TcpTestSucceeded : False,查防火墙、IIS 是否监听、服务器是否在线。浏览器报错在这一步之前没有意义。
1.3 用 curl 看 HTTP 状态码。Windows 10/11 自带 curl。
curl.exe -I http://ca01.contoso.local/certsrv/
Expected output:
HTTP/1.1 401 Unauthorized
Server: Microsoft-IIS/10.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
判断规则:401 通常是正常的未认证挑战;404 表示 IIS 没有 /certsrv;403 多半是权限或认证配置;500 查 IIS 和 AD CS Web 组件。
2. 服务器侧:确认 IIS 和 CertSrv 虚拟目录存在
2.1 在 CA 服务器上确认 IIS 站点。以下命令需要管理员 PowerShell。
Import-Module WebAdministration
Get-Website | Select-Object Name,State,PhysicalPath,Bindings
Expected output:
Name State PhysicalPath Bindings
Default Web Site Started C:\inetpub\wwwroot http *:80:
2.2 查 /certsrv 应用是否存在。
Get-WebApplication -Site "Default Web Site" | Select-Object Path,PhysicalPath,ApplicationPool
Expected output:
Path PhysicalPath ApplicationPool
/certsrv C:\Windows\System32\CertSrv\en-US CertSrv
如果没有输出,说明没有安装 AD CS Web Enrollment,或安装时 IIS 组件缺失。
2.3 安装缺失组件。Windows Server 2019/2022 可用:
Install-WindowsFeature ADCS-Web-Enrollment,Web-Server,Web-Windows-Auth,Web-Asp-Net45 -IncludeManagementTools
Expected output:
Success Restart Needed Exit Code Feature Result
True No Success {Certification Authority Web Enrollment, Web Server...}
Warning: 如果这台服务器不是 CA,只是 Web Enrollment 代理,安装向导还需要指定目标 CA。生产环境先备份 CA 配置。
3. 修复常见 HTTP 错误:401、403、404、500
3.1 401 循环登录。通常是 Windows Authentication 未启用或浏览器没有走 Intranet Zone。
Get-WebConfigurationProperty -Filter "/system.webServer/security/authentication/windowsAuthentication" -PSPath "IIS:\Sites\Default Web Site\certsrv" -Name enabled
Expected output:
True
如为 False,启用它并关闭匿名认证:
Set-WebConfigurationProperty -Filter "/system.webServer/security/authentication/windowsAuthentication" -PSPath "IIS:\Sites\Default Web Site\certsrv" -Name enabled -Value True
Set-WebConfigurationProperty -Filter "/system.webServer/security/authentication/anonymousAuthentication" -PSPath "IIS:\Sites\Default Web Site\certsrv" -Name enabled -Value False
iisreset
Expected output:
Attempting stop...
Internet services successfully stopped
Attempting start...
Internet services successfully restarted
3.2 404。确认目录存在。
Test-Path C:\Windows\System32\CertSrv\en-US
Expected output:
True
如果是 False,重新安装 Web Enrollment 组件。不要手工复制其他服务器的 CertSrv 目录,版本不一致会产生 500。
3.3 500。查应用池和 CA 服务。
Get-WebAppPoolState CertSrv
Get-Service CertSvc
Expected output:
Value
Started
Status Name DisplayName
Running CertSvc Active Directory Certificate Services
如未启动:
Start-WebAppPool CertSrv
Start-Service CertSvc
Expected output:
无错误输出即为成功
4. 验证证书服务本身可用,不只看网页
4.1 查询 CA 配置。这个命令能确认客户端能和 CA RPC 通信。
certutil -config "ca01.contoso.local\CONTOSO-CA" -ping
Expected output:
Connecting to ca01.contoso.local\CONTOSO-CA ...
Server "CONTOSO-CA" ICertRequest2 interface is alive
CertUtil: -ping command completed successfully.
如果这里失败,但网页能开,说明 /certsrv 只是前端可见,CA 后端不可用。查防火墙 RPC 动态端口、CA 服务账号、域控连通性。
4.2 查看模板是否可申请。
certutil -template | findstr /i "User Machine WebServer"
Expected output:
Template[0]:
TemplatePropCommonName = User
Template[1]:
TemplatePropCommonName = Machine
Template[2]:
TemplatePropCommonName = WebServer
Note: /certsrv 能打开但没有模板,通常是模板未发布或申请账号没有 Enroll 权限。
如何确认问题已解决
按以下三项验收。三项都通过,才算 certsrv无法访问 已解决。
HTTP 返回认证挑战或 200:
curl.exe -I http://ca01.contoso.local/certsrv/Expected output: HTTP/1.1 401 Unauthorized 或 HTTP/1.1 200 OK浏览器使用域账号打开
http://ca01.contoso.local/certsrv,能看到 “Welcome to Certificate Services”。实测内网千兆环境首屏通常小于 300 ms。CA 后端响应正常:
certutil -config "ca01.contoso.local\CONTOSO-CA" -pingExpected output: CertUtil: -ping command completed successfully.
References
- Microsoft AD CS Web Enrollment:核对你的 Windows Server 版本与角色安装状态。
- IIS Windows Authentication:核对 Negotiate、NTLM、匿名认证配置。
- certutil 内置帮助:运行
certutil -?查看本机版本支持的参数。
如果你同时在排查 Gemini怎么注册、Google AI怎么用、Gemini国内使用 这类公网访问问题,先区分内网 CA 故障和公网连通性故障;免费、官方、自建方案都可行。商都加速器是众多网络加速选项之一,可按需参考:wizzegroup.com。