Enterprise PKI.

Enterprise PKI.

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Enterprise PKI. Argus_IS 05-05-2006
`--> Re: Enterprise PKI. Miha Pihler [MV...05-05-2006
Posted by =?Utf-8?B?QXJndXNfSVM=?= on May 5, 2006, 1:50 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I have the following scenario to deal with :
windows 2003 domain, installed in Jan 2005. Enterprise Pki installed in Jan
2005 and then uninstalled in jan 2005. There are kdc errors on the domain
controllers :
Source : KDC
Event id 20
Description:
The currently selected KDC certificate was once valid, but now is invalid
and no suitable replacement was found. Smartcard logon may not function
correctly if this problem is not remedied. Have the system administrator
check on the state of the domain's public key infrastructure. The chain
status is in the error data.

Now the CRL is no longer available by any means, nor is the backup of the
servers with the PKI in place. The dc's have certificates that were issued
by this CA the certificates are valid until Dec 2006.

Now my question is: can I use the instructions in the following article to
clean out all remains of this CA even though the CRL's will never be
available?:
http://support.microsoft.com/kb/889250/en-us

Hope there is someone there who can assist me with this!



Posted by Miha Pihler [MVP] on May 5, 2006, 2:37 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

To be sure which certificates you have -- you can run

Certutil -dcinfo -verify

on DC to check which certificates are installed and then run

Certutil -dcinfo deletebad

This will remove any bad certificates...

--
Mike
Microsoft MVP - Windows Security

>I have the following scenario to deal with :
> windows 2003 domain, installed in Jan 2005. Enterprise Pki installed in
> Jan
> 2005 and then uninstalled in jan 2005. There are kdc errors on the domain
> controllers :
> Source : KDC
> Event id 20
> Description:
> The currently selected KDC certificate was once valid, but now is invalid
> and no suitable replacement was found. Smartcard logon may not function
> correctly if this problem is not remedied. Have the system administrator
> check on the state of the domain's public key infrastructure. The chain
> status is in the error data.
>
> Now the CRL is no longer available by any means, nor is the backup of the
> servers with the PKI in place. The dc's have certificates that were
> issued
> by this CA the certificates are valid until Dec 2006.
>
> Now my question is: can I use the instructions in the following article
> to
> clean out all remains of this CA even though the CRL's will never be
> available?:
> http://support.microsoft.com/kb/889250/en-us
>
> Hope there is someone there who can assist me with this!
>
>



Similar ThreadsPosted
Upgrading to Windows 2003 Enterprise Edition Enterprise CA October 18, 2005, 4:59 am
Enterprise CA May 31, 2006, 11:29 am
need to remove old Enterprise CA - April 14, 2006, 4:26 pm
redundant enterprise CA January 9, 2008, 10:41 am
Standalone/ Enterprise CA issue October 18, 2005, 2:52 am
ZeroSpyware Enterprise Evaluation March 22, 2006, 3:44 am
Can Enterprise Root CA be moved? October 23, 2006, 10:50 am
question about removing enterprise CA February 6, 2007, 3:08 pm
Stand-alone vs Enterprise subordinate CA? March 9, 2007, 12:23 pm
Enterprise CA options greyed out. September 1, 2008, 11:01 pm

The site map in XML format XML site map

Contact Us | Privacy Policy