How to Remove Decommissioned CA's from PKIVIEW Locations


hello,

i decommissioned 2 of our enterprise issuing certificate authorities our pki environment. have removed decommissioned ca http references on each of our existing ca management console's extensions tabs and ensured ca exchange certs not have decommissioned cdp locations referenced. have restarted cas, decommissioned servers still appear in cdp , deltacrl http locations. i've verified don't exist in registry , don't exist in ntauthcertificates container viewed through pkiview.msc > enterprise pki > manage ad containers.

environment consists of windows server 2008 offline root , policy cas 5 online issuing cas (which consist of 2 2008 , 3 2012 servers)

any other ideas of how rid of decom'd locations in pkiview.msc?

thanks! patrick

you need revoke recent ca exchange certificate , re-run pkiview.msc.

vadims podāns, aka powershell cryptoguy
weblog: en-us.sysadmins.lv
powershell pki module: pspki.codeplex.com
powershell cmdlet editor pscmdlethelpeditor.codeplex.com
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.



Windows Server  >  Security



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS