Remove Old CA in Active directory

bizcntradmin 191 Reputation points
2020-08-04T12:33:54.26+00:00

This is related to my previous question about Old Root CA certificate that appears in trusted root cert store of my servers/ computers.

I check the Group policy and the old Root certificate is not published there.

So probably that the Root CA certificate was published in AD via CERTUTIL -DSPUBLISH, also the Old certificate is Publish not only in CN=Certification Authorities. But also in CN=AIA, CN=Enrollement Services and CN=KRA. Also the old PKI server is also in CN=CDP.

I also launch Enterprise PKI > Manage AD containers and i see the objects there

What is the best way to clean this up So that new servers will not get that Expired Certificate?
What is the best way also to cleanup the one in production?

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,834 questions
{count} votes

Accepted answer
  1. Vadims Podāns 9,121 Reputation points MVP
    2020-08-04T16:34:29.127+00:00

    I also launch Enterprise PKI > Manage AD containers and i see the objects there

    use this Manage AD Containers dialog to cleanup old CA certificate from AD.


1 additional answer

Sort by: Most helpful
  1. Hannah Xiong 6,276 Reputation points
    2020-08-05T05:51:52.3+00:00

    Hello,

    Thank you so much for posting here.

    To remove the old CA, we could refer to:

    How to decommission a Windows enterprise certification authority and remove all related objects
    https://support.microsoft.com/en-in/help/889250/how-to-decommission-a-windows-enterprise-certification-authority-and-r

    For any question, please feel free to contact us.

    Best regards,
    Hannah Xiong


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.