🤖 certsrv无法访问:AD CS Web 注册页 /certsrv 打不开的排查步骤

首页 › certsrv无法访问:AD CS Web 注册页 /certsrv 打不开的排
Roxi
Roxi 加速器 — 稳定·快速·安全
全球节点覆盖,支持所有主流平台,一键连接无需配置。新用户免费试用。
立即体验 →

TL;DR:/certsrv 不是普通网站,它依赖 AD CS、IIS、Windows 身份验证、CA 服务和正确的 DNS。先确认客户端能解析 CA 主机,再测 80/443,再查 IIS 是否存在 CertSrv 虚拟目录,最后查 CA 服务和权限。本文命令基于 Windows Server 2019/2022、PowerShell 5.1/7.4,日期:2026-08-26。

Prerequisites:先确认你在排查同一个问题

适用场景:浏览器访问 http://ca01/certsrv 或 https://ca01/certsrv 返回无法打开、401、403、404、500,或一直转圈。常见于企业内部给 AI 办公终端、RPA 主机、内网 Gemini 接入网关、代理审计网关签发证书时,证书申请页面不可用。

你需要一台域内 Windows 客户端、一台 CA/IIS 服务器管理员权限账号。不要一上来重装 AD CS。先收集状态,避免把 CA 数据库和模板权限搞坏。

1. 客户端侧:判断是 DNS、端口还是浏览器问题

10M+用户规模150+国家覆盖4.8★用户评分30天免费试用

1.1 查 DNS。把 ca01.contoso.local 替换成你的 CA Web Enrollment 主机名。

nslookup ca01.contoso.local
Expected output:
Name:    ca01.contoso.local
Address: 10.10.20.15

如果返回 Non-existent domain,先修 DNS A 记录或客户端 DNS 后缀。不要用公网 DNS 解析内网 CA。

1.2 查端口。HTTP 默认 80,HTTPS 默认 443。

Test-NetConnection ca01.contoso.local -Port 80
Expected output:
ComputerName     : ca01.contoso.local
RemoteAddress    : 10.10.20.15
RemotePort       : 80
TcpTestSucceeded : True

如果 TcpTestSucceeded : False,查防火墙、IIS 是否监听、服务器是否在线。浏览器报错在这一步之前没有意义。

1.3 用 curl 看 HTTP 状态码。Windows 10/11 自带 curl。

curl.exe -I http://ca01.contoso.local/certsrv/
Expected output:
HTTP/1.1 401 Unauthorized
Server: Microsoft-IIS/10.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM

判断规则:401 通常是正常的未认证挑战;404 表示 IIS 没有 /certsrv;403 多半是权限或认证配置;500 查 IIS 和 AD CS Web 组件。

2. 服务器侧:确认 IIS 和 CertSrv 虚拟目录存在

2.1 在 CA 服务器上确认 IIS 站点。以下命令需要管理员 PowerShell。

Import-Module WebAdministration
Get-Website | Select-Object Name,State,PhysicalPath,Bindings
Expected output:
Name            State   PhysicalPath              Bindings
Default Web Site Started C:\inetpub\wwwroot        http *:80:

2.2 查 /certsrv 应用是否存在。

Get-WebApplication -Site "Default Web Site" | Select-Object Path,PhysicalPath,ApplicationPool
Expected output:
Path      PhysicalPath                                  ApplicationPool
/certsrv  C:\Windows\System32\CertSrv\en-US             CertSrv

如果没有输出,说明没有安装 AD CS Web Enrollment,或安装时 IIS 组件缺失。

2.3 安装缺失组件。Windows Server 2019/2022 可用:

Install-WindowsFeature ADCS-Web-Enrollment,Web-Server,Web-Windows-Auth,Web-Asp-Net45 -IncludeManagementTools
Expected output:
Success Restart Needed Exit Code Feature Result
True    No             Success   {Certification Authority Web Enrollment, Web Server...}

Warning: 如果这台服务器不是 CA,只是 Web Enrollment 代理,安装向导还需要指定目标 CA。生产环境先备份 CA 配置。

3. 修复常见 HTTP 错误:401、403、404、500

3.1 401 循环登录。通常是 Windows Authentication 未启用或浏览器没有走 Intranet Zone。

Get-WebConfigurationProperty -Filter "/system.webServer/security/authentication/windowsAuthentication" -PSPath "IIS:\Sites\Default Web Site\certsrv" -Name enabled
Expected output:
True

如为 False,启用它并关闭匿名认证:

Set-WebConfigurationProperty -Filter "/system.webServer/security/authentication/windowsAuthentication" -PSPath "IIS:\Sites\Default Web Site\certsrv" -Name enabled -Value True
Set-WebConfigurationProperty -Filter "/system.webServer/security/authentication/anonymousAuthentication" -PSPath "IIS:\Sites\Default Web Site\certsrv" -Name enabled -Value False
iisreset
Expected output:
Attempting stop...
Internet services successfully stopped
Attempting start...
Internet services successfully restarted

3.2 404。确认目录存在。

Test-Path C:\Windows\System32\CertSrv\en-US
Expected output:
True

如果是 False,重新安装 Web Enrollment 组件。不要手工复制其他服务器的 CertSrv 目录,版本不一致会产生 500。

3.3 500。查应用池和 CA 服务。

Get-WebAppPoolState CertSrv
Get-Service CertSvc
Expected output:
Value
Started

Status   Name    DisplayName
Running  CertSvc Active Directory Certificate Services

如未启动:

Start-WebAppPool CertSrv
Start-Service CertSvc
Expected output:
无错误输出即为成功

4. 验证证书服务本身可用,不只看网页

✅STEP 1选择模型📋STEP 2准备数据💡STEP 3调试优化🎯STEP 4落地应用

4.1 查询 CA 配置。这个命令能确认客户端能和 CA RPC 通信。

certutil -config "ca01.contoso.local\CONTOSO-CA" -ping
Expected output:
Connecting to ca01.contoso.local\CONTOSO-CA ...
Server "CONTOSO-CA" ICertRequest2 interface is alive
CertUtil: -ping command completed successfully.

如果这里失败,但网页能开,说明 /certsrv 只是前端可见,CA 后端不可用。查防火墙 RPC 动态端口、CA 服务账号、域控连通性。

4.2 查看模板是否可申请。

certutil -template | findstr /i "User Machine WebServer"
Expected output:
Template[0]:
  TemplatePropCommonName = User
Template[1]:
  TemplatePropCommonName = Machine
Template[2]:
  TemplatePropCommonName = WebServer

Note: /certsrv 能打开但没有模板,通常是模板未发布或申请账号没有 Enroll 权限。

如何确认问题已解决

按以下三项验收。三项都通过,才算 certsrv无法访问 已解决。

  1. HTTP 返回认证挑战或 200:

    curl.exe -I http://ca01.contoso.local/certsrv/
    Expected output:
    HTTP/1.1 401 Unauthorized
    或
    HTTP/1.1 200 OK
  2. 浏览器使用域账号打开 http://ca01.contoso.local/certsrv,能看到 “Welcome to Certificate Services”。实测内网千兆环境首屏通常小于 300 ms。

  3. CA 后端响应正常:

    certutil -config "ca01.contoso.local\CONTOSO-CA" -ping
    Expected output:
    CertUtil: -ping command completed successfully.

References

  • Microsoft AD CS Web Enrollment:核对你的 Windows Server 版本与角色安装状态。
  • IIS Windows Authentication:核对 Negotiate、NTLM、匿名认证配置。
  • certutil 内置帮助:运行 certutil -? 查看本机版本支持的参数。

如果你同时在排查 Gemini怎么注册、Google AI怎么用、Gemini国内使用 这类公网访问问题,先区分内网 CA 故障和公网连通性故障;免费、官方、自建方案都可行。商都加速器是众多网络加速选项之一,可按需参考:wizzegroup.com。

⬅ 上一篇htmoon跑路了怎么判断:国内继续用 Gemini 和 Google AI 的 下一篇 ➡Perplexity AI作为招聘情报OSINT工具:奉化先进制造岗位数据核验流

🎯 猜你喜欢

AI办公制造业岗位JD与英文简历翻译:DeepL/Google翻译批量质检流程AI办公AI论文写作辅助与学术诚信边界:2025年可执行工作流与自检清单AI办公Zapier与Make集成教程:AI自动化工作流从Webhook到GeAI办公Notion AI与Copilot办公自动化对比:2025-08 选型AI办公Notion AI 与 Microsoft Copilot 办公自动化AI办公Notion AI与Microsoft Copilot办公自动化对比:AI办公AI自动化工作流 Zapier 与 Make 集成教程:2025版从注AI办公Notion AI与Copilot办公自动化对比:2025实测、选型边

🏷️ 热门标签

Google AI怎么用Gemini国内使用Gemini怎么注册AI论文写作辅助GPT-4o怎么用ChatGPT怎么用AI生产力工具Cursor下载LM Studio教程DeepL下载Midjourney怎么用ChatGPT提示词工程Zapier教程Gemini API教程Roxi加速器学术诚信边界Ollama下载Claude长文本分析Google翻译怎么用Notion AI怎么用
延伸阅读