Domain Controller Certificates


i opened local certificate store on domain controller renew dc certs. renewed them successfully, right-clicked "personal - certificates" , selected "all tasks - request new certificate" make sure had ones needed. under options saw:

  • domain controller
  • domain controller authentication
  • directory email replication
  • kerberos authentication

because certs had installed didn't have same titles under "intended purposes" selected them , have duplicates , wary remove them. should remove duplicates , there implications?

thanks

i recommend removing them , selecting kerberos authentication certificate. if setup correctly (in environment), should deploy using autoenrollment.

brian



Windows Server  >  Security



Comments

Popular posts from this blog

Generating Event ID 91, 44 with CA (In Event Viewer with source as Certsvc)

Group policy default policy cannot be edited because network name not found

Problem when changing update source