214 Cannot find the certificate for %1 to build a certificate chain. Do you wish to install this certificate now?
215 Cannot verify certificate chain. Do you wish to ignore the error and continue?
216 An error occurred retrieving the pending certificate\nfrom %1:
217 Get Server CA Name
218 Select CA
230 Save certificate and Keys
231 Retrieve Certificate
232 Finish Suspended Setup
233 The certificate is not a CA certificate.
234 Setup complete
235 Retrieve Pending Certificate
236 Key Index
237 Load Old Certificate
238 Clone Root Certificate
239 Build Request
240 Renew CA -- reuse keys
241 Install CA Certificate
242 Renew CA -- new keys
243 Build CA Certificate
244 Save Chain and Keys
245 If you want to send the request to an offline CA, click Cancel and send the request file at %1 to your parent CA.
246 Create DS CDP object
247 Create DS enrollment services object
248 Create DS Root Trust
249 Publish CA in DS
250 Submit Request
251 An error occurred when creating the new key container "%1". Please make sure the CSP is installed correctly or select another CSP.\n
252 The Certification Authority certificate has a bad length:
253 The new Certification Authority certificate cannot be installed because the CA Version extension is incorrect. The most recently generated request file should be used to obtain the new certificate: %1
254 The root certificate is untrusted. Do you wish to trust the root certificate on this machine and complete the installation?
255 Cannot add the Certification Authority certificate to the certificate store:
256 Cannot create a certificate context using the Certification Authority certificate:
257 Unreferenced INF sections
258 Set Security
259 Cannot create file %1:
260 The existing private key "%1" cannot be deleted. Either reuse this key, or use a different name for the CA.\n
261 Cannot encode key attributes:
262 Cannot encode certificate:
263 The %SystemRoot% environment variable is not set.
264 This key storage device is full and the new key "%1" could not be added. Go back and pick an existing key, or use a different key storage device.\n
265 An error occurred when generating key "%1" for the Active Directory Certificate Services service. Either the CSP configuration is not complete or the key length is not supported. Please make sure the CSP is installed correctly or select another CSP.\n
266 Cannot determine the computer name:
267 An error occurred when setting the security access on the private key "%1", or the CSP selected does not support setting security access on private keys. Please make sure the CSP is installed correctly or select another CSP.\n
268 Cannot decode Certification Authority name information:
269 The parent CA has denied your request because you are not a domain administrator. (%1)\nTo obtain the certificate for your CA, you must request the certificate as a domain administrator. You can install the certificate using the Certification Authority snap-in.
270 The new certificate subject Common Name does not match the active CA name:
271 Generate Keys
272 An error was detected while configuring Active Directory Certificate Services.\nThe Active Directory Certificate Services Setup Wizard will need to be rerun to complete the configuration.\n
273 The parent CA has denied your request for a CA certificate. Please contact the parent CA administrator.\n(%1)
274 An error occurred when the parent CA processed this CA certificate request. Please contact the parent CA administrator.\n(%1)
275 This CA certificate request did not complete. Please contact the parent CA administrator.\n(%1)
276 This CA certificate will be issued administratively. Please contact the parent CA administrator.\n(%1)
277 This CA certificate request is in the pending state. Please contact the parent CA administrator.\n(%1)
278 This CA certificate was revoked by the parent CA. Please contact the parent CA administrator.\n(%1)
279 Cannot set the key provider information for the certificate context:
280 Cannot submit the certificate request to the specified CA. Please ensure that the CA information is correct and that the CA is online. Note: only CAs running the Microsoft Active Directory Certificate Services are supported.\n
281 Cannot submit the certificate request to the specified CA. (%1)\nTo obtain the certificate for your CA, you can install the certificate using the Certification Authority snap-in.
282 The new certificate subject name does not exactly match the active CA name.\nRenew with a new key to allow minor subject name changes:
283 The new certificate public key does not match the current outstanding request.\nThe wrong request may have been used to generate the new certificate:
284 Find certificate for %1
285 Cannot write the Certification Authority certificate to file "%1":
286 Cannot write to file %1:
287 INF file error
288 Set Key Security
289 Parent CA =
290 Request ID =
291 Microsoft Active Directory Certificate Services
292 Set Directory Security
299 An error occurred when creating the new key container "%1". You do not have write access permission to the key container. Please use a different CA name.\n
320 Certificate Server Hierarchy Configuration
321 Process Certificate Request File
322 Windows NT 4.0 Option Pack\Microsoft Certificate Server (Common)
323 Generate New Certificate Revocation List
330 Key length must be a number.
331 Key length is out of the range %1.
332 Key length cannot be negative number.
333 Select a cryptographic service provider (CSP), hash algorithm, and settings for the key pair.
334 Public and Private Key Pair
335 The following folders will be created:\n%1\nDo you want to continue?
336 The parent CA name must be no more than 64 characters.
337 Select a parent CA name.
338 Request the certificate for this CA by sending the request directly to a parent CA or saving the request to a file and sending this file to the CA
339 CA Certificate Request
340 The most trusted CA in an enterprise. Should be installed before any other CA.
341 A standard CA that can issue certificates to users and computers in the enterprise. Must obtain a CA certificate from another CA in the enterprise.
342 The most trusted CA in a CA hierarchy.
343 A standard CA that can issue certificates to users and computers. Must obtain a CA certificate from another CA.
344 Select the type of CA you want to set up.
345 CA Type
346 Creates, manages, and removes X.509 certificates for applications such as S/MIME and SSL. If this service is stopped, certificates will not be created. If this service is disabled, any services that explicitly depend on it will fail to start.
347 Active Directory Certificate Services
348 Active Directory Certificate Services configuration
349 Windows did not find a CA on this computer. Change the computer name, or click Browse to select a CA.
350 Enter a computer name that has a running CA.
351 You can use the Active Directory Certificate Services Client software to host the certificate enrollment Web pages on a separate Web server.
352 Active Directory Certificate Services Client Configuration
354 The computer name must be no longer than 64 characters.
355 Enter the name of the computer that is running the parent CA.
356 Select a CA for this client
357 Select Certification Authority
358 An error occurred when creating the service log in the registry:
359 Setup was unable to retrieve the required information about the CA from the existing certificate:
360 Active Directory Certificate Services Setup failed in building CA certificate.
361 Cannot build certificate request:
362 Active Directory Certificate Services Installation failed.
363 Active Directory Certificate Services setup failed with the following error:
364 An error occurred when creating the server configuration files in folder "%1":
365 An error occurred when creating program link "%1":
366 Cannot Change Active Directory Certificate Services configuration.
367 Cannot delete Active Directory Certificate Services "%1":
368 An error occurred when registering or unregistering Active Directory Certificate Services related dll "%1":
369 The certification authority name contains characters that are not valid.\nSpecify a different certification authority name.
370 Enter the name of a PFX file.
371 An error occurred when generating keys for Active Directory Certificate Services:
372 An error occurred when importing the PFX file:
373 The selected hash algorithm "%1" failed the signature test. Return to the Advanced options and select a different hash algorithm.
374 Could not load the Active Directory Certificate Services configuration interface:
375 Could not determine Networking role:
377 You must be a member of the Administrators group.
378 The selected hash algorithm is not supported by Active Directory Certificate Services. Select another algorithm.
379 An error occurred during the creation of the configuration files. Make sure the shared folder exists and has the necessary permissions.
380 A certification authority with the same name was found in the Active Directory. Do you want to overwrite the existing CA name?
381 The description must be no longer than 1024 characters in length.
382 The country/region code must be two characters.
383 Determined by parent CA
384 The email address must be no longer than 128 characters in length.
385 The country/region field must be alphabetic characters.
386 The country/region field must be two characters in length.
387 The validity duration must be between 1 day and 1000 years.
388 The city name must be no longer than 128 characters.
389 The CA name must be no longer than 64 characters.
390 Enter the CA name.
391 The organization name must be no longer than 64 characters.
392 The organization unit must be no longer than 64 characters.
393 The state or province name must be no longer than 128 characters.
394 Enter information to identify this CA.
395 CA Identifying Information
396 Enter a validity period.
397 Import Personal Information Exchange
398 The Active Directory Certificate Services installation is incomplete. To complete the installation, use the request file "%1" to obtain a certificate from the parent CA. Then, use the Certification Authority snap-in to install the certificate. To complete this procedure, right-click the node with the name of the CA, and then click Install CA Certificate.
399 Generating cryptographic key...
400 Securing cryptographic key...
401 Active Directory Certificate Services is generating the cryptographic key and setting key protection.
402 Validating key set and hash algorithm...
403 Cryptographic Key Generation
404 The key "%1" is either corrupted or cannot be used for signing. Select another key.
405 Setup needs to create the file "%1" that is derived from the CA name. The file path exceeds the maximum length. Use a shorter CA name.
406 Personal Information Exchange (*.p12, *.pfx)|*.p12;*.pfx|All Files (*.*)|*.*||
407 The file "%1" does not exist.
408 The password is not valid.
409 The key and certificate from the import file already exist on this computer. Do you want to overwrite them?
410 The file path "%1" is invalid.
411 The name of the request file must be less than 64 characters in length.
412 Enter a name for the request file.
413 To complete the installation, Active Directory Certificate Services must temporarily stop the Internet Information Services. Do you want to stop the service now?
414 The immediate parent folder of the lowest subfolder must exist.
415 The directory path %ws exceeds the maximum length of %u characters.
416 "%1" does not exist. Enter an existing UNC path.
417 Enter locations for the certificate database, database log, and configuration information.
418 Certificate Database Settings
419 Active Directory Certificate Services
420 Days
421 Months
422 Weeks
423 Years
425 Cannot access the database file "%1" because it is being used by another process. You must specify a different folder.
426 The private key "%1" already exists. Do you want to overwrite this key with a new one?
427 Enter a complete path to the certificate database folder. "%1" is not a full path.
428 Setup needs to overwrite existing database files in the "%1" folder. It is recommended that you shutdown the applications that are using files in this folder. Do you want to continue?
429 Enter a complete path to the certificate database log folder. "%1" is not a full path.
430 Enter a complete path to the shared folder. "%1" is not a full path.
431 The CA information contains characters that require extended name encoding in the certificate. Certificates containing this name encoding conform to accepted standards, but may be incompatible with non-compliant applications. Do you want to use these fields?
433 Begin
434 End
435 Was Enabled
436 Is Enabled
437 Install State
438 Create Request
439 Create Certificate
440 Start Service
441 Create Web Include Files
442 Install Client
443 Install Server
444 Upgrade Type
445 Upgrade Cert Store
446 Upgrade Key Security
447 Upgrade Server
448 Upgrade Client
449 Service Stopped
450 Service Started
451 Created Client Registry
452 Created Server Registry
453 Upgraded Server Registry
454 Unregistered DLLs
455 Registered DLLs
456 Created Program Groups
457 Create certsvc
458 Install Cancelled
459 Dispatch Function
460 Unattended Attribute
461 loaded Client Unattended Attributes
462 loaded Server Unattended Attributes
463 Operation Flags
464 Adding to ToDoList
465 Post-Base
466 Unattended
467 Registry State
468 Selection State
469 Active Directory Certificate Services Installation Wizard
470 Active Directory Certificate Services Installation Wizard
471 Import PFX
473 Failed to create the directory %1.
474 You must uninstall Active Directory Certificate Services first and then reinstall Active Directory Certificate Services Web Enrollment Support.
475 You must uninstall the current Active Directory Certificate Services Web Enrollment Support and then reinstall Active Directory Certificate Services.
476 The imported certificate does not match the chosen CA type and will not be used. However, the imported key can still be used.
477 %1 must specify a file name in an existing directory.
478 The key length defined in the answer file is ignored because a key is re-used
479 Cannot create request file. A directory named "%1" already exists.
480 The PFX file name or password is too long.
481 Upgrade is only supported from Windows 2000 Active Directory Certificate Services.
482 Active Directory Certificate Services cannot be installed on this version of the operating system.
483 Validity period must be no longer than 4 characters
484 The distinguished name syntax is invalid.
485 The distinguished name syntax is invalid. %1
486 Property cannot be modified in current state of object. An Existing private key is being used.
487 Property cannot be modified in current state of object. An Existing certificate is being used.
488 Property cannot be modified in current state of object. Current CA Type does not allow this property to be modified.
489 Shared Folder property should not be set as Active Directory can be used to discover certification authority.
490 For new certification authority, database cannot be preserved.
491 Property cannot be modified in current state of object. Existing database is being preserved.
492 Cannot perform the operation as object was initialized for only CA Web Enrollment support
510 <%' CODEPAGE=65001 'UTF-8%>\n<%' certdat.inc - (CERT)srv web - global (DAT)a\n ' Copyright (C) Microsoft Corporation, 1998 - 1999 %>\n<%\n ' default values for the certificate request\n sDefaultCompany="%0"\n sDefaultOrgUnit="%1"\n sDefaultLocality="%2"\n sDefaultState="%3"\n sDefaultCountry="%4"\n \n ' global state\n sServerType="%7" 'vs %8\n sServerConfig="%5\%6"\n sServerDisplayName="%9"\n nPendingTimeoutDays=10\n\n%>\n
511 <%\nResponse.ContentType = "application/x-netscape-revocation"\nserialnumber = Request.QueryString\nset Admin = Server.CreateObject("CertificateAuthority.Admin")\n\nstat = Admin.IsValidCertificate("%1", serialnumber)\n\nif stat = 3 then Response.Write("0") else Response.Write("1") end if\n%>\n
512 Could not delete CA certificates from ROOT or CA store.
900 User
901 Authenticated Session
902 Smartcard Logon
903 Basic EFS
904 Administrator
905 EFS Recovery Agent
906 Code Signing
907 Trust List Signing
908 Computer
909 Domain Controller
910 Web Server
911 KDC
912 Root Certification Authority
913 Subordinate Certification Authority
914 Enrollment Agent
915 Smartcard User
917 User Signature Only
919 The value for the following key is incorrect in the INF file. It should be a non-zero numeric value.
923 IPSec
924 The value for RenewalValidityPeriodUnits is incorrect in CAPolicy.inf. It should be a non-zero numeric value.
925 IPSec (Offline request)
926 The value for RenewalValidityPeriod is incorrect in CAPolicy.inf. It should be one of the following: Years, Months, Weeks or Days (in English).
932 Please make sure there is a running CA on the computer.
933 There is no matched CA on the computer. This might be caused by the computer being offline. Please contact the system adminstrator or select a different CA.
934 Cannot ping the selected CA. Please make sure the CA is running.
935 Exchange Enrollment Agent (Offline request)
936 Exchange User
937 Exchange Signature Only
938 There are no published CAs available. Please contact the system adminstrator or select a CA by name.
939 Enrollment Agent (Computer)
940 Save Request File
941 CEP Encryption
942 Built Policy
943 Policy Element
944 Policy Statement Extension
945 Policy inf missing section or key
946 Opened Policy inf
947 Cannot open Policy inf
948 Begin
949 End
950 Manage CA
951 Issue and Manage Certificates
952 Manage Audit Logs
953 Backup and Restore
954 Read
955 Request Certificates
964 Closed Policy inf
965 Message Box
966 The value for RenewalValidityPeriod is incorrect in unattended answer file. It should be one of the following: Years, Months, Weeks or Days (in English).
967 Key Recovery Agent
968 CA Exchange
969
970 Cross Certification Authority
971 Domain Controller Authentication
972 Directory Email Replication
974 \nYou have configured this Web client to forward requests to an enterprise CA. If the CA is using the enterprise default policy module, this computer must have delegation enabled and use Kerberos authentication. To enable delegation, see 'Allow computer accounts to be trusted for delegation' help topic.
976 The Web client cannot be configured to forward requests to the selected CA.
977 The value for the following key is incorrect in the INF file. It should be a boolean value (Yes/No/True/False/0/1).
978 Workstation Authentication
979 RAS and IAS Server
980 Low Assurance
981 Medium Assurance
982 High Assurance
983 OCSP Response Signing
984 Kerberos Authentication
1000 Key recovery agent
1001 Directory e-mail replication
1002 Cross-certified certification authority
1003 Certification authority (CA)
1004 Computer
1005 User
1006 Unknown
1007 Active Directory KRA
1008 Active Directory AIA
1782 CA Name
1783 Organization
1784 Organizational Unit
1785 Locality
1786 State or Province
1787 EMail
1788 Country/region
1789 Description
1790 Shared Folder
1791 Database directory
1792 Database log directory
1793 Computer name
1794 Request file
1795 Validity period
1796 CA Type
1797 Key Name
1798 The server DNS name contains characters that cannot be encoded into Certificate Extensions. Please change the computer name or the server DNS name to eliminate special characters.
1799 The path "%1" cannot be used for database files. The path might have special characters or be read-only. Please change the path.
1800 After installing Active Directory Certificate Services, the machine name and domain membership may not be changed due to the binding of the machine name to CA information stored in the Active Directory. Changing the machine name or domain membership would invalidate the certificates issued from the CA. Please ensure the proper machine name and domain membership are configured before installing Active Directory Certificate Services. Do you want to continue?
1801 Setup needs to create a key container name "%1" that is derived from the CA name. The maximum length allowed by the CSP "%2" is %3 characters. The name exceeds the maximum length. Please shorten the CA name.
1802 Query Change Selection State
1803 Setup needs to create the file "%1". The file path exceeds the maximum length. Use a shorter path.
1804 Unknown CA Type
1805 Bad or missing CA Name
1806 The value for ValidityPeriod is incorrect. It should be one of the following: Years, Months, Weeks or Days (in English).
1807 CA Machine name required
1808 CA name required
1809 Failed in pinging parent CA
1810 Empty unattended attribute
1811 Failed in building CA file path
1812 Enterprise CA requires DS availability
1813 Country/region code must be either empty or two characters long
1814 Matching CA certificate not found
1815 Reuse certificate requires reuse key
1816 Preserve DB requires reuse certificate
1817 The value for ValidityPeriodUnits is out of range. It should be a small non-zero numeric value.
1818 Request file name too long
1819 CA Name too long for key container name
1820 Path too long; shorten CA Name
1821 Country/region code must be in 'A'-'Z' or 'a'-'z'
1822 Cannot find a key from the list
1823 Disable the wizard page because of a fatal error
1824 Wizard Page Error
1825 Upgrade unsupported
1826 Upgrade from Windows2000
1827 Upgrade from build to build
1828 12
1829 Verdana
1831 Sanitized CA Name
1832 Key Container Name
1833 Setup could not add the Certification Authority s computer account to the Cert Publishers security group. This Certification Authority will not be able to publish certificates in Active Directory. To fix this, an administrator must manually add the Certification Authority s computer account to the Cert Publishers security group in Active Directory.
1834 Setup could not add the Certification Authority s computer account to the Pre-Windows 2000 Compatible Access security group. Certificate Managers Restrictions feature will not work correctly on this Certification Authority. To fix this, an administrator must manually add the Certification Authority s computer account to the Pre-Windows 2000 Compatible Access security group in Active Directory.
1835 Active Server Pages (ASPs) must be enabled in Internet Information Services (IIS) in order to allow Active Directory Certificate Services to provide web enrollment services. Enabling ASPs is a potential security risk and must be carefully evaluated. You can enable ASPs later if you choose not to do it now. IIS must be manually reconfigured later to enable this functionality.\nDo you want to enable Active Server Pages now?
1836 Internet Information Services (IIS) is not installed on this computer. Active Directory Certificate Services Web Enrollment Support will be unavailable until IIS is installed.
1837 Active Directory Certificate Services Setup has detected a domain controller running Windows 2000 without Service Pack 3 or later. An enterprise certification authority (CA) cannot be installed when a domain controller is running this version of the operating system. The options to install an enterprise CA are unavailable.\n\nYou can install a stand-alone CA now, or you can resolve the problem and install an enterprise CA. To resolve the problem, ensure that all Windows 2000 domain controllers \nare running Service Pack 3 or later, or configure your domain controllers to allow SSL connections from the CA. For information on how to configure your domain controllers, search Help and Support Center.
1840 Setup created a shared folder for configuration information, but this shared folder could not be verified because there is no available network connection.
1841 Share disposition
1842 Virtual root disposition
1843 http://%ws/certsrv/mscep_admin/
1844 http://%ws/certsrv/mscep/mscep.dll
1845 You have to be the local machine administrator in order to run this setup.
1846 Can not delete RA certificates. Please close all programs or increase the available virtual memory.
1847 Failed to update the registry.
1848 Failed to add the web virtual directory.
1849 Setup can not obtain security identity for the account.
1850 Failed to add the following certificate templates to the enterprise Active Directory Certificate Services or update security settings on those templates:\n EnrollmentAgentOffline\n CEPEncryption\n IPSEC (Offline request)\n
1851 No more memory. Please close all programs or increase the available virtual memory.
1852 Failed to enroll RA certificates.
1853 Failed to update the Active Directory Certificate Services.
1854 The account name is incorrectly formatted. Examples of correct account names include do main\account or account@domain.
1855 Setup is unable to obtain security information for the account.
1856 Setup can not find the domain or machine that the account belongs to.
1857 Setup is unable to check the membership of the account.
1858 Setup is unable to find the account.
1859 The account is not a member of the local machine's IIS_IUSRS group.
1860 Fail to retrieve the DNS name of the computer.
1861 The account should be a domain account. Local account is not allowed.
1862 Setup can not find the IPSEC (Offline request) certificate template in the Active Directory.
1863 Setup can not find the security information for the IPSEC (Offline request) certificate template in the Active Directory.
1864 Setup can not detect if the account can read information about the IPSEC (Offline request) certificate template in the Active Directory.
1865 The account can not read information about the IPSEC (Offline request) certificate template in the Active Directory. Please make sure this is a domain account.
1866 The certification authority has been uninstalled from this computer. However, Windows was not able to remove objects related to this CA from the NTAuthCertificates, Certification Authorities, and Enrollment Services containers in Active Directory. Use the Enterprise PKI snap-in to manually remove CA objects from these containers. For more information, see Enterprise PKI Help.
1867 Network Service account cannot send authenticated certificate request to a local Enterprise CA. Specify a user account.
1868 The certification authority is already installed on this computer. Microsoft Simple Certificate Enrollment Protocol can send authenticated certificate request to this certification authority only.
1869 The Network Device Enrollment Service cannot be configured with a remote standalone certification authority (CA). Select an enterprise CA or install this service on a computer that hosts a standalone CA.
1870 The Network Device Enrollment Service failed because the setup could not obtain the type of CA from "%1". Make sure that the Active Directory Certificate Services service is running. The error is:
4050 Select Certification Authority
4051 Select a Certification Authority to send the request.