Deleting Archived Certificates from Users' My store on Workstations

Deleting Archived Certificates from Users' My store on Workstations

Secure Home | Search | About

Microsoft Applications Security - Microsoft's general security discussions and announcements 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Deleting Archived Certificates from Users' My store on Workstations BillL 07-08-2008
Posted by BillL on July 8, 2008, 3:50 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

We have a piece of software that only checks for the existence of a
certificate not whether it has been revoked or not. For this reason
we would like to remove all of the archived certificates from the user
My Store on workstations in the environment. The certs all had
encryption set as a purpose so they have been archived and not
deleted.

I know that I can use a "certutil -delstore -user MY 999999999999999"
command to remove individual certificates but I'm looking for a way to
manage this across 5000 workstations. Is there an easy way that I am
missing?

Thanks,
Bill

Posted by Brian Komar \(MVP\) on July 8, 2008, 4:19 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
ummmm, do you have any encrypted data on those 5000 workstations.
You goal appears to be to get 5000 angry users calling you that they can no
longer open their encrypted files/emails from a few years ago.
Brian

> Hi,
>
> We have a piece of software that only checks for the existence of a
> certificate not whether it has been revoked or not. For this reason
> we would like to remove all of the archived certificates from the user
> My Store on workstations in the environment. The certs all had
> encryption set as a purpose so they have been archived and not
> deleted.
>
> I know that I can use a "certutil -delstore -user MY 999999999999999"
> command to remove individual certificates but I'm looking for a way to
> manage this across 5000 workstations. Is there an easy way that I am
> missing?
>
> Thanks,
> Bill


Posted by David H. Lipman on July 8, 2008, 7:38 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Hi,

| We have a piece of software that only checks for the existence of a
| certificate not whether it has been revoked or not. For this reason
| we would like to remove all of the archived certificates from the user
| My Store on workstations in the environment. The certs all had
| encryption set as a purpose so they have been archived and not
| deleted.

| I know that I can use a "certutil -delstore -user MY 999999999999999"
| command to remove individual certificates but I'm looking for a way to
| manage this across 5000 workstations. Is there an easy way that I am
| missing?

| Thanks,
| Bill

Look into Tumbleweed.
http://www.tumbleweed.com/solutions/identity_validation.html

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Similar ThreadsPosted
how to check .pfx certificates in personal store remotely April 5, 2006, 11:50 am
Certificates, Autoenrollment, Credential Roaming and User's Personal Store April 29, 2008, 10:53 am
Stop Users Deleting and Moving Files June 16, 2006, 10:21 am
How to prevent users from deleting Word/Excel files in a Share? May 14, 2008, 9:45 pm
clm users certificates expiration March 30, 2008, 5:39 am
My Domain users have users have many domain User certificates June 26, 2009, 1:28 pm
how to know when new apps are installed in workstations June 12, 2006, 7:36 am
Tasklist.exe -- credential caching for remote workstations? January 19, 2006, 6:47 pm
How do you prevent workstations in a server 2003 domain from locki October 22, 2007, 11:01 am
How does your organizations manage the local administrator account on workstations? August 29, 2008, 11:32 pm

The site map in XML format XML site map

Contact Us | Privacy Policy