Windows PKI CA: "The certificate has invalid policy"

When you try to issue a new certificate on a Windows client, this might not work and you get the following error: The certificate has invalid policy. 0x800b0113 (CERT_E_INVALID_POLICY) The root cause of this is that the issuing CA has restricted the issuance policies you can use. If you have created a certificate template that uses a policy that is not allowed, you will get that error message. There is a quick and dirty method to get rid of this error (but it also makes your CA a bit more Read more [...]

Windows: USB stick not recognized after formatting with Linux

I had recently created a bootable USB disk for a Linux distro. After I did not use that anymore, I wanted to format it in my Windows 10 machine. But it was not recognized anymore. No drive letter, not visible in File Explorer. In "Disk Management" it was visible, but I could not format it there either. Using command line tool "Diskpart" did not help either as the "clean" command ended with an "Access Denied" error. In the end, the folloing sequence of commands helped me in "Diskpart": list Read more [...]

Windows CA Server: Trust relationship to the Domain Failed

When a client of a server that is joined to a Windows Domain loses the trust relationship to its object in Active Directory, you normally get this error message, when you try to login: The trust relationship between this workstation and the primary domain failed What you then normally do is to un-join the computer from the domain and join it again. The problem with with a Windows CA (Certificate Authority) Server is that you cannot un-join it from the domain. So that would mean you have to completely Read more [...]

Windows: Delete Folder with a trailing Space Character

Recently, I had the problem that a Robocopy script created folder with a space character at the end on the Windows NTFS file system. So for example

"FolderName "

In File Explorer, I could not delete the folder, the error message said "Object does not exist". Also renaming the folder was not possible.

The onyl solution was to go to a CMD box and issue the command

rd /s "\\?\D:\bad\folder\path "

Just answer "y* when you are asked if you really want to delete the folder.

Windows Server: How to Force a Solid Background Color

To avoid the typical picture on the background of your desktop, use the following procedure to force a solid blue color as background: Start the Group Policy Editor: gpedit.msc Go to User Configuration > Administrative Templates > Desktop > Desktop Open Desktop Wallpaper Enable it and set the Wallpaper Name to: C:\Windows\Web\Screen\img105.jpg Click on OK to save the changes While you could also just right-click on the desktop and choose Personalize and set a Read more [...]

Windows: Shared Printers Cannot be Installed after the September 2021 Windows Update

After the September 2021 Windows Update, non-administrator users will no longer be able to add remote printers without an elevation of privilege to administrator. To allow normal users to add remote printers (hosted on a print server), you can now add the following Registry value on the client: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint RestrictDriverInstallationToAdministrators = 0 (DWORD 32) No restart of the client is needed. If things still do Read more [...]

Windows: Shared Printer Cannot Be Added (Error 740)

When logged in as Administrator in a Windows 10 or 11 machine, when you try to add a shared printer, you get the error: That didn't work. We can't install this printer right now. Try again later or contact your network administrator for help. Error: #740. The underlying problem is this: Error 740 means: "The requested operation requires elevation". This is a problem as you are already logged in as Administrator. So the solution is to start the "Add Printer Wizard" as Administrator. To do this: Read more [...]

Microsoft Exchange 2019: Search Results are Incomplete on Server

With Exchange 2019, Microsoft has introduced a new search engine: BigFunnel. This is the same engine that is used in Bing and in Exchange Online. Unfortunately, sometimes, the search results are incomplete. While this might have different reasons, I am just looking at one prticular case here: Incomplete search results are happening on OWA, i.e. this is an issue on the server, not on Outlook (the client) The number of missing emails from the search results is visible in "BigFunnelNotIndexedCount" Read more [...]

My experience with servers, networks and gadgets.