1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Calling Windows Active Directory Experts - CA Authority Question

Discussion in 'General' started by Cannoli, Dec 7, 2015.

  1. Cannoli

    Cannoli Typical Uccio

    Can you tell me where in AD the enterprise CA servers are listed? I built a certificate authority server on a separate 2012 R2 VM for the local domain, and had to rebuild it. Now when I create a machine certificate for a system, I can "browse" and see the old server that no longer exists, listed as one of the choices for the CA root server in the domain to request the cert from.

    Where is the metadata stored on the domain controller that lists the Enterprise CA servers? I want to clean up the remnants of the first install.
     
  2. joec

    joec brace yourself

    Did you try power cycling it?
     
  3. joec

    joec brace yourself

  4. bjs8579

    bjs8579 Well-Known Member

    Open ADSI edit and select Configuration from the well known naming context. After that expand Services, and then Public Key Services. All previous CA's should be listed in the containers and you can delete the records from there. Here are detailed steps:

    http://retrohack.com/cleaning-up-after-a-failed-2008-certificate-authority/


    This should work for Server 2012 R2 as well.
     
  5. Cannoli

    Cannoli Typical Uccio

    Thanks for the info. I knocked it out this morning!
     

Share This Page