Orphaned Enterprise CAs....

Lynx1997 1 Reputation point
2020-10-01T15:32:45.6+00:00

I inherited a network with two orphaned Enterprise CAs in Active Directory. Both DCs that were running these CAs, are long gone.... I found the following article and would like to confirm that it still applies to get rid of these orphaned CAs. The current DCs are a 2008 R2 DC and a Server 2016 DC. The Forest and Domain Functional Levels are both at 2008 R2.

https://video2.skills-academy.com/en-us/troubleshoot/windows-server/identity/delete-enterprise-windows-certificate-authority

Thanks for any help with this!!

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,204 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,777 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Vadims Podāns 9,116 Reputation points MVP
    2020-10-01T19:06:57.167+00:00

    Here you go: How to Decommission a Windows Enterprise Certification Authority and How to Remove All Related Objects

    Do only step 6 and step 7. After that, they will gone completely.

    0 comments No comments

  2. Thameur-BOURBITA 32,626 Reputation points
    2020-10-01T20:27:26.583+00:00

    Hi,

    If you want delete a orphaned enterprise PKI , you can use adsiedit.msc tool to delete all PKI settings saved in configuration partition:

    CN=Public Key Services,CN=Services,CN=Configuration,DC=ForestRoot,DC=com
    

    Please don't forget to mark this reply as answer if if help you to fix you issue

    0 comments No comments

  3. Fan Fan 15,321 Reputation points Microsoft Vendor
    2020-10-01T23:57:25.89+00:00

    Hi,
    Based on my understanding , the CAs running on the old DCs have been removed , you want to manually remove old CA references in Active Directory, right?
    Based on my research ,yes, you can try the way mentioned above.
    If there are progress , welcome to share here!
    Best Regards,

    0 comments No comments