Remove old CA from member servers?


hey everyone,

to start, had installed ptrg (pretty neat stuff) , instantly started give me info on servers within same subnet itself. plenty of them telling me of weak protocols being used ssl. decided cert store of member servers. surprise found our old root ca cert (although expired) in servers cert store.

google being friend found this

a great technet question answered, , followed , able clean out old cert info pki.

i noticed base crl "expiring soon"... googles more, , found this (i don't why can see answer anymore, stated:

"certutil -crl" , follow certutil -dspublish -f -dc "dc-fqdn"

however kept spitting out context if missing in syntax of command, tried google more gave on part fustrations of not having clear example of syntax command wanted me provide complete task. instead opened ca program on ca , right clicked revocation list , selected tasks -> publish.

since wasn't aware of way directly confirm or not if had worked... info on seem little lacking out there.

anyway top off, checked ca , still had old root ca in trusted ca store. went ahead , removed mmc certificate snap in. logged server , ran gpupdate, opened mmc , opened cert snap in find old root-ca , new root-ca in place... 

now if remove cert manually, , run gpupdate, not re-appear. yay!

however, have manually log each member server remove old root-ca cert? seem bit redic in mind... maybe has scripting this? on making life easier removing old cert appreciated!

it sounds listed in gpo explicitly forcing them clients then. check applicable gpos carts. in computer/policies/windows settings/security settings/public key services/trusted root certification authorities folder.

mark b. cooper, president , founder of pki solutions inc., former microsoft senior engineer , subject matter expert microsoft active directory certificate services (adcs). known “the pki guy” @ microsoft 10 years. connect mark @ http://www.pkisolutions.com



Windows Server  >  Security



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file