In the Windows domain, enable the certificate auto-enrollment for computers and domain controllers.

To enable certificate auto-enrollment for computers and domain controllers

  1. Log in to the server hosting Active Directory.
  2. Open the Group Policy Management administrative tool. Select Start > Windows Administrative Tools > Group Policy Management.
    The Group Policy Management dialog box appears.
  3. In the tree view, expand the Domain Controller you will modify.
  4. Right-click Default Domain Policy > Edit.
    The Group Policy Management Editor dialog box appears.
  5. Expand to Computer Configuration > Policies > Windows Settings > Security Settings > Public Key Policies.
  6. In the content pane, right-click Certificate Services Client Auto Enrollment > Properties.
    The Certificate Services Client Auto Enrollment Properties dialog box appears.
  7. In the Configuration Model drop-down list, select Enabled.
  8. Select Renew expired certificates, update pending certificates, and remove revoked certificates.
  9. Select Update certificates that use certificate templates.
  10. Click OK.