Key-based renewal provides the ability for automatic certificate renewal for computers that are not connected directly to ...

Key-based renewal provides the ability for automatic certificate renewal for computers that are not connected directly to the internal network. When the Certificate Enrollment Web Service (CES) is deployed in this mode, certificates can be renewed when the renewal request is signed by an existing valid certificate. There is no additional requirement for explicit authentication or identity information.

Note:  Key-based renewal mode requires that the targeted CA run at least Windows Server 2012.