Fix it now
0x80094800 is CERTSRV_E_UNSUPPORTED_CERT_TYPE: the requested certificate template is not supported by this CA. Usually the template exists in Active Directory and was never published to this CA, which takes two minutes. The other cases are a template the CA cannot read, or one built for a newer CA than you are running.
certutil -CATemplates
certutil -SetCATemplates +WebServerV2
certutil -CATemplates
- Read the first
certutil -CATemplatesoutput. If the template is not listed, this CA is not configured to issue it and that is your answer. - Publish it from the console if you prefer: in the Certification Authority console, right-click Certificate Templates, choose New, then Certificate Template to Issue, and select it.
- From the command line use
certutil -SetCATemplates +<TemplateName>with the template’s internal name, not its display name. - If the template does not appear in the list of templates you can add, open its Compatibility settings and compare the Certification Authority level with the CA you are running.
- Retry the request, then check the CA’s Failed Requests view if it still does not go through.
There is a third possibility that catches people out: if Authenticated Users has been removed from the template’s ACL, the CA itself can no longer read the template in Active Directory, and clients see exactly this code.
If the template now appears in the CA’s list and the request succeeds, stop here. The next section covers the two cases where publishing does not help.
Why it happens
An enterprise CA issues only the templates it has been configured to issue. The template object lives in Active Directory and is visible forest-wide, so a client can see and request a template that this particular CA has never been told about. What comes back is CERTSRV_E_UNSUPPORTED_CERT_TYPE, and on the CA the policy module records a denied request.
The second cause is a permissions problem wearing the wrong error message. Microsoft documents that removing the Authenticated Users group from a template’s access control list stops the enterprise CA reading that template in Active Directory – the CA object is itself covered by that group – and requests against the template then fail. The published fix is that every CA’s computer account must be added to the template ACL with Read. On the CA you also see a warning at service start saying the template could not be loaded.
The third cause is version. A template carries compatibility settings for the certification authority and for the certificate recipient, and a template built for a newer CA than you are running cannot be issued by it – the template will not even appear in the list of templates you can add. That is a capability boundary rather than a configuration one.
The template was never published to this CA
You have this one if certutil -CATemplates does not list it, and other templates issue normally.
- Publish it:
certutil -SetCATemplates +<TemplateName>, or add it in the console under Certificate Templates, New, Certificate Template to Issue. - Re-run
certutil -CATemplatesand confirm it appears. - In a multi-CA environment, publish it on every CA that clients might reach, not just the one you tested.
The CA cannot read the template
You have this one if The template is published, and at service start the CA logs a warning that the template could not be loaded. Requests fail with this code.
- Open the template’s Security tab and check whether Authenticated Users is present.
- If it has been removed, add every CA’s computer account with Read – that is the published remedy.
- Restart Certificate Services and confirm the load warning has gone.
This is the cause that survives every attempt to re-publish the template, because publishing is not the thing that is broken.
The template is a newer version than the CA supports
You have this one if The template does not appear in the list of templates available to add, and its compatibility settings name a newer CA version.
- Open the template’s Compatibility tab and read the Certification Authority setting.
- Either lower the compatibility level – which loses the features that required it – or issue from a CA that supports it.
- Check the Certificate recipient setting at the same time, since a level higher than your clients support causes its own problems.
Replication has not caught up
You have this one if The template issues from one CA and not another, or from one site and not another, and nothing else differs.
- Confirm the template object exists on the domain controller that CA is using.
- Give replication time, or force it, before making changes that will need undoing.
- 0x80094813, CERTSRV_E_UNKNOWN_CERT_TYPE, is the code for templates to be enabled that could not be found at all – that one points at replication or a renamed template rather than publishing.
Full reference
The codes in this family
| Code | Constant | Published meaning |
|---|---|---|
0x80094800 |
CERTSRV_E_UNSUPPORTED_CERT_TYPE | The requested certificate template is not supported by this CA |
0x80094813 |
CERTSRV_E_UNKNOWN_CERT_TYPE | One or more certificate templates to be enabled on this certification authority could not be found |
0x80094801 |
CERTSRV_E_NO_CERT_TYPE | The request contains no certificate template information |
0x80094811 |
CERTSRV_E_KEY_LENGTH | The public key does not meet the minimum size required by the specified certificate template |
What the CA logs while the client sees the error
| Event ID | Source | What it records |
|---|---|---|
| 53 | CertificationAuthority | Active Directory Certificate Services denied the request, naming the request ID, the template and the error code behind the denial |
| 77 | CertificationAuthority | The policy module warning that a named certificate template could not be loaded, logged when Certificate Services starts |
Those two events split the diagnosis cleanly. A 53 with this code and no 77 means the template exists and is readable but is not published on this CA. A 77 at service start means the CA could not load the template at all, which is the Authenticated Users case.
Display name and internal name
certutil -SetCATemplates takes the template’s internal name, which is frequently not what the console shows. A template displayed as “Contoso Web Server (2019)” may have an internal name with no spaces at all. Read it from certutil -template output or from the template’s properties before scripting anything, because a mistyped name silently publishes nothing.
Requests that arrive with no template at all
0x80094801 says the request contains no certificate template information. That is normal for a request generated outside Windows – an appliance, an OpenSSL command line, a load balancer – which has no idea that templates exist. The supported route is to submit it against a named template with certreq -submit -attrib "CertificateTemplate:<name>", rather than to make the CA guess.
Key length refusals
0x80094811 is a different refusal that often follows a template change: the public key in the request does not meet the minimum size the template requires. Devices that generate keys in hardware are the usual source, because their key size is fixed by the firmware. Raise the request’s key size if you can, and if you cannot, the decision is whether that device belongs in your PKI at all rather than whether to lower the template’s floor.
When a licence is the actual fix
Publishing a template, fixing an ACL and correcting a compatibility level are all free, and they close most of these cases. There is one that they do not. If the template needs a certification authority version newer than the one you are running – and the giveaway is that the template never appears in the list of templates you can add – then the CA itself is the limit, and a template’s compatibility level cannot be lowered without giving up the features that required it. Where the CA is running on a Windows Server build that is out of support, that is the moment to move it rather than work around it, and Arco supplies Windows Server 2025 Standard with the client access licences that go with it. Check first: if the template simply is not published, publish it and spend nothing.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x80094800 |
CERTSRV_E_UNSUPPORTED_CERT_TYPE: the requested certificate template is not supported by this CA | Microsoft Learn |
0x80094813 |
CERTSRV_E_UNKNOWN_CERT_TYPE: one or more certificate templates to be enabled on this certification authority could not be found | Microsoft Learn |
0x80094801 |
CERTSRV_E_NO_CERT_TYPE: the request contains no certificate template information | Microsoft Learn |
0x80094811 |
CERTSRV_E_KEY_LENGTH: the public key does not meet the minimum size required by the specified certificate template | Microsoft Learn |
Confirm the fix worked
certutil -CATemplateson the CA lists the template by its internal name.- A test request against that template issues rather than being denied.
- No new Event ID 53 for that template in the CA’s log.
- No Event ID 77 at Certificate Services start-up naming the template.
- In a multi-CA environment, the template is published on every CA clients can reach.
Questions people ask about this
I published the template and it still fails.
Check whether Authenticated Users is still on the template’s ACL. If it has been removed, the CA cannot read the template regardless of publishing, and the published fix is to give every CA computer account Read.
Why does the template not appear in the list I can add?
Because its compatibility settings name a certification authority version newer than the CA you are running. That is a capability limit, not a permission.
What name does certutil -SetCATemplates want?
The template’s internal name, not its display name. They are often different, and a wrong name publishes nothing without complaining.
An appliance’s request is rejected with 0x80094801. Is that the same problem?
No. That code means the request carries no template information at all, which is normal for a request generated outside Windows. Submit it against a named template with certreq instead.
Do I need a newer Windows Server to fix this?
Only in the version case, where the template requires a CA newer than yours. Publishing and ACL problems cost nothing to fix.
