Remove OLD CA certificate in AD

bizcntradmin 191 Reputation points
2020-08-19T09:31:52.637+00:00

If i use Enterprise PKI > Manage AD containers and remove a certificate let say in AIA container will that also delete that certificate in Site and Services PKI Services container? Can i do that using just a domain admin rights or do i need an Enterprise Admin Rights?

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,525 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,154 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Hannah Xiong 6,256 Reputation points
    2020-08-20T02:38:50.793+00:00

    Hello,

    Thank you so much for posting here.

    According to this document:
    "Note! You can also do some of these steps with Manage AD Containers in the Enterprise PKI snap-in , but there are some issues there (KRA entrys aren’t shown), so I’d stick to Active Directory Sites and Services."

    So it is suggested that we could choose to remove old CA references in AD through Active Directory Sites and Service.

    Besides, to do the AD clean, please logon into the system with account that have the permissions bellow:

    1. Enterprise Administrator
    2. Domain Administrator
    3. Certificate Authority Administrator
    4. Schema Administrator (The server that function as Schema Master FSMO should be online during the process)

    For more information, we could refer to:

    Manually remove old CA references in Active Directory
    https://mssec.wordpress.com/2013/03/19/manually-remove-old-ca-references-in-active-directory/

    How to remove manually Enterprise Windows Certificate Authority from Windows 2000/2003 Domain
    https://support.microsoft.com/en-us/help/555151

    How to decommission a Windows enterprise certification authority and remove all related objects
    https://support.microsoft.com/en-us/help/889250/how-to-decommission-a-windows-enterprise-certification-authority-and-r

    Hope the information is helpful. For any question, please feel free to contact us.

    Please note: Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.

    Best regards,
    Hannah Xiong