Domain controller auto renews multiple times


we have parent domain (w) , 3 child domains (x, y, z).  we have enterprise ca renewed root certificate on couple days ago.   3 of domains  (w, x, , y) renew domain controller authentication cert fine.  the other domain (z), renewed new cert, @ intervals renew dca cert directory email replication cert.  the interval 8 hours after initial renewal 24 hours later, 48 hours, believe 72 cant recall.  i have verified gpo settings , else can think of between domains , cant find culprit.   clues?

hi,

please try enable capi2 event log to see if information further assistances:

https://blogs.msdn.microsoft.com/benjaminperkins/2013/09/30/enable-capi2-event-logging-to-troubleshoot-pki-and-ssl-certificate-issues/

best regards,

andy


please remember mark replies answers if help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Security



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS