Event ID 9 — AD CS Policy Module Processing

Applies To: Windows Server 2008 R2

The policy module contains the set of rules governing issuance, renewal, and revocation of certificates. This policy is created from hard-coded values, registry settings, and, if you are using an enterprise certification authority (CA), certificate templates. The policy module determines whether a certificate request is approved, denied, or marked as pending for an administrator to approve or deny. Problems detected with a policy module can cause a CA to fail to start or to cease functioning.

Event Details

Product: Windows Operating System
ID: 9
Source: Microsoft-Windows-CertificationAuthority
Version: 6.1
Symbolic Name: MSG_NO_POLICY
Message: Active Directory Certificate Services did not start: Unable to load a policy module.

Resolve

Enable AD CS to load a policy module

The AD CS policy modules must have sufficient memory and disk space to start correctly. If the policy modules did not start, resolve this error by :

  • Initializing the policy module.

If this does not resolve the error:

  • Identify the policy module name and contact the vendor for support.

To perform these procedures, you must have Manage CA permission, or you must have been delegated the appropriate authority.

Initialize a policy module

To enable Active Directory Certificate Services (AD CS) to initialize a policy module:

  1. On the computer hosting the CA, clickk Start, point to Administrative Tools, and click Reliability and Performance Monitor.
  2. Check memory usage on the computer and, if necessary, add system resources.
  3. Restart the computer and CA.
  4. If the policy module is not loaded and the warnings cannot be resolved by addressing related symptoms, there is likely a problem with the policy module that only the vendor can address. Therefore, identify the name of the policy module and contact the vendor for support.
    • For a non-Microsoft policy module, contact the policy module provider for assistance.
    • For a Microsoft policy module, contact Microsoft Customer Service and Support. For more information, see https://go.microsoft.com/fwlink/?LinkId=89446.

Identify the policy module name 

To identify the policy module name:

  1. On the computer hosting the CA, click Start, point to Administrative Tools, and click Certification Authority.
  2. Right-click the name of the CA, and click Properties.
  3. Click the Policy Module tab, and then click Properties.
  4. Write down the identifying information for the policy module.

Verify

To perform this procedure, you must have membership in local Administrators on the computer hosting the certification authority (CA), or you must have been delegated the appropriate authority.

To confirm that the policy module is operational:

  1. On the computer hosting the CA, click Start, point to Administrative Tools, and click Services.
  2. Right-click the Active Directory Certificate Services (AD CS) service, and click Restart.
  3. Open the event log, and confirm that it does not contain any errors relating to the policy module.

Errors relating to the policy module are:

  • Event 9: Source: Microsoft-Windows-CertificationAuthority. "Active Directory Certificate Services did not start: Unable to load a policy module."
  • Event 43: Microsoft-Windows-CertificationAuthority. "The "%1" policy module "%2" method caused an exception at address %4. The exception code is %3."
  • Event 44: Microsoft-Windows-CertificationAuthority. "The "%1" policy module "%2" method returned an error. %5 The returned status code is %3. %4"
  • Event 77: Microsoft-Windows-CertificationAuthority. "The "%1" policy module logged the following warning: %2"
  • Event 78: Microsoft-Windows-CertificationAuthority. "The "%1" policy module logged the following error: %2"

AD CS Policy Module Processing

Active Directory Certificate Services