Enterprise Mobility : In the land of NDES – Where one eye is King and you need to watch your CRL Delta files

I was doing a EMS POC and deployment of certificates on mobile devices was a requirement. So I needed to setup an NDES server with a separate Subordinate CA for MDM , NDES Server and SCCM Certificate Registration Point (CRP). Big deal I thought as I did it a already multiple times. At my customer we worked close with the server team and setup the infrastructure which was working fine at first sight. After a reboot of the NDES server I was struggling to get the Network Device Enrollment Service (NDES) up and running again as it would throw me an error 500. The event log of the NDES Server told me the following: The Network Device Enrollment Service cannot retrieve one of its required certificates (0x80070057). The parameter is incorrect. The Network Device Enrollment Service cannot be started (0x80070057). The parameter is incorrect. When the service starts, it searches for two certificates that are used by the service : 1. The service searches in the...
Read More