Link to home
Start Free TrialLog in
Avatar of symde
symde

asked on

How to remove Trusted root certificate using GPO

We are testing a temporary trusted root certificate issued by a Mainframe in our organisation. this root will be trusted only by computers in a certain OU, not enterprisewide.

The certificate can be delivered to an OU by importing the certificate into a GPO ( Computer config>Windows>Security>Public Key>Trusted Root.

My question is, once we are done testing, how do I take this certificate out of the Computer's Trusted root cert store for computers in the OU?
I'd rather not create a CRL/CTL, as this is just a temp cert.
- Is it doable using a GPO?
- If not, can this be deleted by a commandline?
ASKER CERTIFIED SOLUTION
Avatar of CoccoBill
CoccoBill
Flag of Finland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
note that certificates in general are just registry keys - local machine or user depending on where they were imported to. so, a GPO that can delete that specific registry key (from \Software\Microsoft\SystemCertificates\ ) would be enough.
Avatar of symde
symde

ASKER

Thanks for the quick replies. CoccoBill's solution works but with one issue.
I get a delete confirmation popup.

Apart from using an autoit tab>enter script, is there an undocument silent or force switch?
I will close the question after getting response for this (do-able or otherwise)