New internal CA


i had old internal enterprise ca1 issued computer certificates , domain controller certificates.

now installed brand new enterprise ca2 new key etc.

i removed certificate templates ca1 , added them ca2

now see clients getting new computer certificates ca2 domain controllers not trying new certificates.

am or domain in danger when turn off ca1 ?

what best steps can now, cannot use reenroll certificate holders cause computer template

i recommend explicitly delete existing certificates dcs , run 'certutil -pulse' on them reenroll certificates.

my weblog: http://en-us.sysadmins.lv
powershell pki module: http://pspki.codeplex.com
windows pki reference: on technet wiki



Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client