Jump to content

Recommended Posts

Posted

Hi all,

 

A little help on certificates please!

 

I have 2 DCs, I noticed a couple of certificate errors and investigated certificates on one of the DCs. Under the local computer certificates-> personal-> certificates, the certificate in there (client auth and server auth cert) has expired. I thought it would be a case of, "Request new certificate with the same key", however there is no Certificate Authority installed. I checked and we do not have a CA server on our domain.

 

I am now at the point where I have installed the role of Certificate Authority but haven't configured it yet. Can anybody point out any pitfalls to me or anything I should be careful with or is the case of configure it update the certificate's on the DCs and the rest takes care of itself?

 

Any help appreciated.

 

Regards

 

Nick

Posted (edited)
Yeah I would try to not install your root CA on your DC if you can avoid it. If you follow the strict guidelines on this you should try to have an offline root and an intermediate CA, but I suppose its all about scale. Sha-2 not 1 any other things I can think of I will post...... Edited by HPlum78
Typing with my face
  • Thanks 1
Posted
I'd always avoid putting any certification authority stuff on a DC - It is difficult to rename the machine it's installed on (I think it gives you a warning to that effect when configuring ADCS) and if it is a DC, you'll need to remove ADCS before demoting the DC
Posted
Noted, Removed from DC (hadn't configured it) and also now not sure whether I need to install it at all or not. Am waiting to see if anything broken as certificate expired 2 months ago.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...