About Domain Controller and Domain Controller Authentication Certificate


i'm taking on new domain, domain controllers above windows 2003.

when @ auto-enrollment that dcs see template used certificate is domain controller. normal ? should not certificate build based on "domain controller authentication" template instead ?

if i'm correct how fix ? should delete "domain controller" template ?

when @ template properties, see "domain controller" template being published in ad, , options greyed out, , therefore cannot modified.

the "domain controller authentication" template not published in ad, , options accessible.

thanks input



life short, enjoy now. cyreli

hi,

the main point issuing certificates domain controllers "server authentication" included in key usage (intended puposes), if current certificate template has that, can keep was. however, if need issue new certificates domain controllers based on new certificate templates, can remove certificate template issue list , add new certificate template issue list want.

regards,
cicely



Windows Server  >  Security



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS