Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Questions regarding decommissioning an enterprise certificate authority in Server 2008

Posted on 2016-11-18
1
Medium Priority
?
78 Views
Last Modified: 2017-01-17
Hello Experts,

A couple of days ago my manager asked me to work on decommissioning our last Server 2008 domain controller.  While going through the server's configuration, I realized that at some point in time in the past, someone had installed the Active Directory Certificate Services role and this server has been issuing certificates.  Since certificate management is not something I have a lot of experience in, I have a couple of questions:
1.  What is the best way to stop this certificate server from issuing new certificates?
2.  In researching how to decommission a certificate authority, it looks like the process is to revoke the issued certificates and extend the life of the CRL.  If I revoke the certificates on this CA server, will the computers whose certificates have been revoked automatically get new certificates from our actual CA server?

Thanks,
Nick
0
Comment
Question by:ndalmolin_13
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 6

Accepted Solution

by:
sAMAccountName earned 2000 total points
ID: 41893154
Assuming you have a two or three tier hierarchy...

Yes, when you revoke a certificate, the member server will request a new certificate from whatever authority it is aware of.  Depending on how big your environment is, you might want to hit all hosts and look in their stores (scriptomagically) for the thumbprint on the cert you are going to revoke.  This may help you scope what your AoE is going to be.  Undoubtedly, you will have a small number of hosts which complain for one reason or another.  Typically forcing the request again using certutil or restarting the host will fix the issue, so long as your online responder, issuing CA(s) and GPO are all inline
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

664 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question