Solved

Microsoft CA - how to renew a local issued certificate via the Certification Authority

Posted on 2014-02-05
3
1,849 Views
Last Modified: 2014-02-24
Hi all,

We've got a certificate which was generated on one of our workstations locally. This cert has been published to ~210 workstation and it's working perfectly, but it's end time is coming and in 2 weeks the validity time will be finished.

Now, I think what is the best thing to do:
1. Renew this cert via the CA? Is it possible? How to deploy it via GPO to all users?
2. Create a new cert via the CA and deploy it to all users via GPO.

Thanks in advance
0
Comment
Question by:IT_Group1
3 Comments
 
LVL 78

Expert Comment

by:David Johnson, CD, MVP
ID: 39837924
How was the CA set up?? please don't tell me, next, next, next, done

are you publishing your CRL's, are your online responders set to auto-authorize requests?
Which certificate is expiring the root ca's? issuing ca's or server/personal cert's ?

view these  videos and see if you have to rebuild from scratch
http://vimeo.com/search?q=brian+komar

Which version of the CA -- server 2008/ server 2008R2 / server 2012 ?
0
 
LVL 35

Accepted Solution

by:
Mahesh earned 500 total points
ID: 39838639
Your comment:
This cert has been published to ~210 workstation

Unable to get clarity on above comment

Is the existing certificate is self signed \ issued by internal CA \ External CA server ?

If this is self signed certificate, you cannot renew it.

If certificate is issued by internal CA (AD integrated CA), you can renew it from client machine itself.

If you have Standalone Root CA already in place it cannot work with certificate auto Enrollment and GPO.
In order to automatically enrol certificates to client computers and users, you have to have Enterprise root CA (AD Integrated) server.
Now based on your question I assumed that you have AD integrated enterprise root \ subordinate CA already in place
Please find below article step by step to auto enrol users and computers certificate in active directory
http://www.isaserver.org/img/upl/vpnkitbeta2/autoenroll.htm
The article is written for windows 2003 server, but still work with 2008 \ 2008 R2
Also check below video for better clarity
http://www.labminutes.com/sec0029_user_computer_certificate_auto-entollment

If you have not deployed AD integrated CA server yet, then you must deploy one
http://www.youtube.com/watch?v=Qg_izJtWuiA
Note that you need to install Enterprise root CA on either windows 2008 \ 2008 R2 enterprise edition in order to avail all available option with enterprise CA or you can simply use windows 2012 \ 2012 R2 standard edition.
Also you must be logged on CA server as enterprise admins in a forest
http://technet.microsoft.com/en-us/library/cc772393(v=ws.10).aspx

Mahesh
0
 

Author Closing Comment

by:IT_Group1
ID: 39881976
Thanks
0

Featured Post

Too many email signature changes to deal with?

Are you constantly being asked to update your organization's email signatures? Do they take up too much of your time? Wouldn't you love to be able to manage all signatures from one central location, easily design them and deploy them quickly to users. Well, you can!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

OfficeMate Freezes on login or does not load after login credentials are input.
Will try to explain how to use the VMware feature TAGs in the VMs and create Veeam Backup Jobs using TAGs. Since this article is too long, I will create second article for the Veeam tasks.
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
In this video tutorial I show you the main steps to install and configure  a VMware ESXi6.0 server. The video has my comments as text on the screen and you can pause anytime when needed. Hope this will be helpful. Verify that your hardware and BIO…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now