Link to home
Start Free TrialLog in
Avatar of smyers051972
smyers051972Flag for United States of America

asked on

Certificate for local system with Thumbprint is about to expire or already expired.

Strange event log here, I have two DC's in this location particularly that are complaining about the certificate being expired or about to expire.

I look and it says its valid until 2015 on the computer account BUT on the user account there are no certs.  am I missing something? :)

Thanks!
Avatar of Mahesh
Mahesh
Flag of India image

On domain controllers you do not require user certificates

You do have Domain controller certificate on domain controller that is issued by your internal AD integrated enterprise CA server automatically

What errors are you getting on DCs?

Just ensure that you can telnet CA server on TCP 135 from domain controller

Mahesh
Avatar of smyers051972

ASKER

I forgot to attach screen shots, here they are.
evt64-1.png
evt64-2.png
evt64-3.png
Hi Mahesh

I _JUST_ uploaded them hope it helps :)

I can telnet to 135 no problem.
ASKER CERTIFIED SOLUTION
Avatar of Mahesh
Mahesh
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ill check it out thank you!
They reference 2003 though we are all 2008 R2 any difference?
Are you using smart card to logon on domain controllers ?

I guess not

2003 and 2008 R2 won't make any difference and you can simply delete those certificates
Thank you!