Windows 2008 R2 Key Recovery Remove Revoked Certificates

On the WIndows 2008 R2 CA when I go to add a Key Recovery agent certificate for a user, I see a list of old or revoked certificates. How can I remove this from the list of only valid certificates are listed?
LVL 21
compdigit44Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Will SzymkowskiSenior Solution ArchitectCommented:
Personally I would not be deleting revoked certs but you can however do this using CERTUTIL -deleterow command. For the full list of commands for Certutil see the below link.

https://technet.microsoft.com/en-ca/library/cc732443.aspx#BKMK_deleterow

You may also want to look at the CA Maintenance link below which provide other types of maintenance you can perform on your CA.

Will.
0
compdigit44Author Commented:
Thanks for the link... Is there a script that could run on my CA and email out a report of all certs issued from a specific template name / type and when they will expire? or possible have certs from a specific template email a department before they expire???
0
Will SzymkowskiSenior Solution ArchitectCommented:
Personally, I would be doing this command manually to ensure that you do not delete the wrong values or revoke in correct certs. From my understanding i have not used a script in the past to complete this task.

Will.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.