Windows 2000 Certificate Authority (CA) Server - Can I delete Revo

Windows 2000 Certificate Authority (CA) Server - Can I delete Revo

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Windows 2000 Certificate Authority (CA) Server - Can I delete Revo Frank 04-17-2006
Posted by =?Utf-8?B?RnJhbms=?= on April 17, 2006, 9:03 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I am setting up a Windows 2000 CA Server and I noticed that I can't
permanently delete revoked or failed Certificates. Is there a way to do this?
I have been playing with this CA server and we must have about 100 revoked
and 100 Failed certificates. Now that the server will be in production, i
would like to clear all the certificates and start new.

After doing some research I noticed that Windows 2003 server has an option
where it can delete revoked certificates, is there an option where you can do
the same thing for Windows 2000? I really hope so. Please let me know. Thanks!

-Frank

Posted by Brian Komar [MVP] on April 18, 2006, 12:35 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Frank@discussions.microsoft.com says...
> I am setting up a Windows 2000 CA Server and I noticed that I can't
> permanently delete revoked or failed Certificates. Is there a way to do this?
> I have been playing with this CA server and we must have about 100 revoked
> and 100 Failed certificates. Now that the server will be in production, i
> would like to clear all the certificates and start new.
>
> After doing some research I noticed that Windows 2003 server has an option
> where it can delete revoked certificates, is there an option where you can do
> the same thing for Windows 2000? I really hope so. Please let me know. Thanks!
>
> -Frank
>
No. The certutil -deleterow option is only available in Windows 2003.
But, remember, the deletion of rows can lead to future audit problems
when you have to explain why the records no longer exist.

Brian

Posted by Alun Jones on April 18, 2006, 12:56 am
If you were  Registered and logged in, you could reply and use other advanced thread options
>Frank@discussions.microsoft.com says...
>> I am setting up a Windows 2000 CA Server and I noticed that I can't
>> permanently delete revoked or failed Certificates. Is there a way to do this?
>
>> I have been playing with this CA server and we must have about 100 revoked
>> and 100 Failed certificates. Now that the server will be in production, i
>> would like to clear all the certificates and start new.
>>
>> After doing some research I noticed that Windows 2003 server has an option
>> where it can delete revoked certificates, is there an option where you can do
>> the same thing for Windows 2000? I really hope so. Please let me know.
> Thanks!
>>
>No. The certutil -deleterow option is only available in Windows 2003.
>But, remember, the deletion of rows can lead to future audit problems
>when you have to explain why the records no longer exist.

On the other hand, if this was just a trial install in preparation for the
real thing, you can uninstall and then reinstall the CA by removing and
reinstalling Certificate Services. This will essentially invalidate any
certificates that you have given out, for most purposes.

Alun.
~~~~

[Please don't email posters, if a Usenet response is appropriate.]
--
Texas Imperial Software | Find us at http://www.wftpd.com or email
23921 57th Ave SE | alun@wftpd.com.
Washington WA 98072-8661 | WFTPD, WFTPD Pro are Windows FTP servers.
Fax/Voice +1(425)807-1787 | Try our NEW client software, WFTPD Explorer.

Posted by =?Utf-8?B?RnJhbms=?= on April 18, 2006, 11:45 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Rats, I was hoping there was an easy way to delete these entries. Oh well,
thanks for all your help guys!

-Frank

"Alun Jones" wrote:

> >Frank@discussions.microsoft.com says...
> >> I am setting up a Windows 2000 CA Server and I noticed that I can't
> >> permanently delete revoked or failed Certificates. Is there a way to do
this?
> >
> >> I have been playing with this CA server and we must have about 100 revoked
> >> and 100 Failed certificates. Now that the server will be in production, i
> >> would like to clear all the certificates and start new.
> >>
> >> After doing some research I noticed that Windows 2003 server has an option
> >> where it can delete revoked certificates, is there an option where you can
do
> >> the same thing for Windows 2000? I really hope so. Please let me know.
> > Thanks!
> >>
> >No. The certutil -deleterow option is only available in Windows 2003.
> >But, remember, the deletion of rows can lead to future audit problems
> >when you have to explain why the records no longer exist.
>
> On the other hand, if this was just a trial install in preparation for the
> real thing, you can uninstall and then reinstall the CA by removing and
> reinstalling Certificate Services. This will essentially invalidate any
> certificates that you have given out, for most purposes.
>
> Alun.
> ~~~~
>
> [Please don't email posters, if a Usenet response is appropriate.]
> --
> Texas Imperial Software | Find us at http://www.wftpd.com or email
> 23921 57th Ave SE | alun@wftpd.com.
> Washington WA 98072-8661 | WFTPD, WFTPD Pro are Windows FTP servers.
> Fax/Voice +1(425)807-1787 | Try our NEW client software, WFTPD Explorer.
>

Similar ThreadsPosted
Windows 2000 Certificate server---->2003 August 26, 2008, 3:52 pm
Local Certificate Authority Server July 7, 2006, 1:53 am
remove certificate authority server September 4, 2007, 4:30 pm
How can I create a second certificate authority server for redunda September 20, 2006, 12:07 pm
Windows 2000 server hacked June 21, 2005, 3:53 pm
Will C# created Snap-in with MMC 3.0 runs in Windows 2000 server? January 4, 2006, 12:36 pm
PPTP, PIX firewall and Windows 2000 Server question May 2, 2006, 4:10 pm
MS04-045 (KB870763) invalid for Windows 2000 Server but not replac July 17, 2007, 5:24 am
IP Security Policy - how to block IP ranges in Windows 2000 Server November 9, 2008, 10:55 pm
Lost password on windows 2000 server. Blanked password, but still unable to login September 22, 2006, 5:40 pm

The site map in XML format XML site map

Contact Us | Privacy Policy