Jump to content

Recommended Posts

Posted

Afternoon all,

 

I am in the process of planning for a main physical DC upgrade to 2012R2 from 2008R2.

 

I have weighed up the pros and cons of doing an in place upgrade and want to do a fresh install on the physical server of 2012R2.

 

I have transferred all the FSMO & DHCP roles to my other physical domain controller. All fine there. Left it a couple of weeks to make sure no problems.

 

All that I have left on the original Physical domain controller is the certificate authority service.

 

I checked the certificates and there was only a few to random machines across the site. (about 2 or 3) i revoked them certificates. Tested the machines and no problems still.

 

However all i have left is one more certificate which i am un-sure about. One of my virtual domain controllers keeps requesting a certificate (Which is being granted) by the physical DC. What would this certificate be for? Is it safe to just remove the certificate services and flatten the DC?

 

Capture.PNG

 

Any help appreciated.

 

Thanks

Posted

I'd be careful, make sure your DC isn't using encryption anywhere before killing the CA off.

 

You may find that the DC has a setting applied in a GPO which is telling it to request certificates. Should be under Computer > Security > PKI > Certificate Services Client - Auto-Enrollment

 

If this is applied to a DC, and in your certification authority a template is enabled to allocate certificates to a DC, this would explain what's going on! :)

  • Thanks 1
Posted
I'd be careful, make sure your DC isn't using encryption anywhere before killing the CA off.

 

You may find that the DC has a setting applied in a GPO which is telling it to request certificates. Should be under Computer > Security > PKI > Certificate Services Client - Auto-Enrollment

 

If this is applied to a DC, and in your certification authority a template is enabled to allocate certificates to a DC, this would explain what's going on! :)

 

Thanks, ill take a look at the group policy.

 

In regards to encryption, we use truecrypt on the laptops so i cant think of anything that is doing it.

 

What i find strange is that the other physical DC isn't requesting a certificate only the one virtual one!?

Posted (edited)
I'd be careful, make sure your DC isn't using encryption anywhere before killing the CA off.

 

You may find that the DC has a setting applied in a GPO which is telling it to request certificates. Should be under Computer > Security > PKI > Certificate Services Client - Auto-Enrollment

 

If this is applied to a DC, and in your certification authority a template is enabled to allocate certificates to a DC, this would explain what's going on! :)

 

Group policy says "not configured".

 

So what do i need to do...

 

Capture.PNG

Edited by Wubbalubbadub

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...