Solved

Microsoft CA - how to renew a local issued certificate via the Certification Authority

Posted on 2014-02-05
3
1,892 Views
Last Modified: 2014-02-24
Hi all,

We've got a certificate which was generated on one of our workstations locally. This cert has been published to ~210 workstation and it's working perfectly, but it's end time is coming and in 2 weeks the validity time will be finished.

Now, I think what is the best thing to do:
1. Renew this cert via the CA? Is it possible? How to deploy it via GPO to all users?
2. Create a new cert via the CA and deploy it to all users via GPO.

Thanks in advance
0
Comment
Question by:IT_Group1
3 Comments
 
LVL 79

Expert Comment

by:David Johnson, CD, MVP
ID: 39837924
How was the CA set up?? please don't tell me, next, next, next, done

are you publishing your CRL's, are your online responders set to auto-authorize requests?
Which certificate is expiring the root ca's? issuing ca's or server/personal cert's ?

view these  videos and see if you have to rebuild from scratch
http://vimeo.com/search?q=brian+komar

Which version of the CA -- server 2008/ server 2008R2 / server 2012 ?
0
 
LVL 36

Accepted Solution

by:
Mahesh earned 500 total points
ID: 39838639
Your comment:
This cert has been published to ~210 workstation

Unable to get clarity on above comment

Is the existing certificate is self signed \ issued by internal CA \ External CA server ?

If this is self signed certificate, you cannot renew it.

If certificate is issued by internal CA (AD integrated CA), you can renew it from client machine itself.

If you have Standalone Root CA already in place it cannot work with certificate auto Enrollment and GPO.
In order to automatically enrol certificates to client computers and users, you have to have Enterprise root CA (AD Integrated) server.
Now based on your question I assumed that you have AD integrated enterprise root \ subordinate CA already in place
Please find below article step by step to auto enrol users and computers certificate in active directory
http://www.isaserver.org/img/upl/vpnkitbeta2/autoenroll.htm
The article is written for windows 2003 server, but still work with 2008 \ 2008 R2
Also check below video for better clarity
http://www.labminutes.com/sec0029_user_computer_certificate_auto-entollment

If you have not deployed AD integrated CA server yet, then you must deploy one
http://www.youtube.com/watch?v=Qg_izJtWuiA
Note that you need to install Enterprise root CA on either windows 2008 \ 2008 R2 enterprise edition in order to avail all available option with enterprise CA or you can simply use windows 2012 \ 2012 R2 standard edition.
Also you must be logged on CA server as enterprise admins in a forest
http://technet.microsoft.com/en-us/library/cc772393(v=ws.10).aspx

Mahesh
0
 

Author Closing Comment

by:IT_Group1
ID: 39881976
Thanks
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It Is not possible to enable LLDP in vSwitch(at least is not supported by VMware), so in this article we will enable this, and also go trough how to enabled CDP and how to get this information in vSwitches and also in vDS.
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question