Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

How to remove Currently Valid and some expired certificates from the Trusted Root Certification Authorities & Active Directory?

Posted on 2012-04-12
1
Medium Priority
?
3,239 Views
Last Modified: 2012-04-13
How to remove Currently Valid and some expired certificates from the Trusted Root Certification Authorities & Active Directory?

The CA was an exchange server (Server 2003) that was carved out of the environment and cannot be brought back.  1 certificates was not revoked and is valid until 2014 another certificate is expired.
The Domain controllers in the environment  are showing
>> Event ID 6>>Automatic certificate enrollment for local system failed (0x800706ba) The RPC server is unavailable.

>> Event ID 13>> Certificate enrollment for Local system failed to enroll for a DomainController certificate with request ID N/A from mailsvr.mydomain.com\CommonName (The RPC server is unavailable. 0x800706ba (WIN32: 1722)).

I have been in ADSI Edit and AD Sites And Services and see the references to this Server and Certificates it has issues.

I have tried using certutil -dcinfo deletebad  << however it skips the CA that it cannot reach.

***I want to remove the instances of the Server in AD along with its issued Certificates (that arent being referenced in Group Policy or being used for any real purpose in the current environment) without any issues to the Environment.  How would I do this? ***

FYI  I cannot mount the Certificate services  console on the last 2003 server because it wont communicate with a missing server.  (The Server Can't be brought back).

Any insight would be appreciated.  Thank you.
0
Comment
Question by:abpExpert
1 Comment
 

Accepted Solution

by:
abpExpert earned 0 total points
ID: 37844547
In Active Directory Sites and Services, Switched the view to Services Mode, and navigated to the Services->Public Key Services->AIA.
As you can see the CA in question (CA Server) was still listed. This was a old CA on the svr.mydomain.COM server that has since been removed. Removed this instance as well as the other listings that were in the CDP, Certificate Authorities, KRA.


Then ran the following commands in a Elevated Commad Prompt:
"certutil -dcinfo deleteBad"
"gpupdate /force"


Domain Controller servers will need a reboot (as discussed)

Certificate errors are no longer being produced
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

580 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question