ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Certificate Authority Quagmire

    Scheduled Pinned Locked Moved IT Discussion
    17 Posts 4 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GreyG
      Grey @Dashrender
      last edited by

      @Dashrender said in Certificate Authority Quagmire:

      That seems weird why would you import a certificate from another active directory server instead of making a new one or requesting a new one

      I can advise, suggest and document, but at the end of the day I still have to work with what I have and follow the business directive. Unfortunately, this is one of those times.

      1 Reply Last reply Reply Quote 0
      • ObsolesceO
        Obsolesce
        last edited by

        Have you had a chance to replace the certificate yet?

        GreyG 1 Reply Last reply Reply Quote 0
        • GreyG
          Grey @Obsolesce
          last edited by

          @Tim_G said in Certificate Authority Quagmire:

          Have you had a chance to replace the certificate yet?

          I have a new wildcard cert. I'm not sure I want to use that on the DC. Has anyone done that? I'm unsure if it's a best practice or not.

          1 Reply Last reply Reply Quote 0
          • ObsolesceO
            Obsolesce
            last edited by

            On the DC, can't you request another one from your CA via certlm.msc?

            GreyG 1 Reply Last reply Reply Quote 0
            • GreyG
              Grey @Obsolesce
              last edited by

              @Tim_G said in Certificate Authority Quagmire:

              On the DC, can't you request another one from your CA via certlm.msc?

              The DC is the CA.

              ObsolesceO 1 Reply Last reply Reply Quote 0
              • ObsolesceO
                Obsolesce @Grey
                last edited by

                @Grey said in Certificate Authority Quagmire:

                @Tim_G said in Certificate Authority Quagmire:

                On the DC, can't you request another one from your CA via certlm.msc?

                The DC is the CA.

                Not good... But I guess it is what it is. So let's just focus on fixing it.

                Is starting over an option?

                If not...
                How is your pki set up? How many tiers? From where did you import the wrongly named cert?

                GreyG 1 Reply Last reply Reply Quote 0
                • GreyG
                  Grey @Obsolesce
                  last edited by

                  @Tim_G said in Certificate Authority Quagmire:

                  @Grey said in Certificate Authority Quagmire:

                  @Tim_G said in Certificate Authority Quagmire:

                  On the DC, can't you request another one from your CA via certlm.msc?

                  The DC is the CA.

                  Not good... But I guess it is what it is. So let's just focus on fixing it.

                  Is starting over an option?

                  If not...
                  How is your pki set up? How many tiers? From where did you import the wrongly named cert?

                  No. Unsure; I inherited this and I'm hazy on CAs. A previous DC was in use and is decommissioned, but the old cert was imported to keep some cisco products from complaining.

                  ObsolesceO 1 Reply Last reply Reply Quote 0
                  • ObsolesceO
                    Obsolesce @Grey
                    last edited by

                    @Grey said in Certificate Authority Quagmire:

                    @Tim_G said in Certificate Authority Quagmire:

                    @Grey said in Certificate Authority Quagmire:

                    @Tim_G said in Certificate Authority Quagmire:

                    On the DC, can't you request another one from your CA via certlm.msc?

                    The DC is the CA.

                    Not good... But I guess it is what it is. So let's just focus on fixing it.

                    Is starting over an option?

                    If not...
                    How is your pki set up? How many tiers? From where did you import the wrongly named cert?

                    No. Unsure; I inherited this and I'm hazy on CAs. A previous DC was in use and is decommissioned, but the old cert was imported to keep some cisco products from complaining.

                    You still need to renew the certificate. You can do it in CA management.

                    1 Reply Last reply Reply Quote 0
                    • GreyG
                      Grey
                      last edited by

                      Is there an article for that on technet? I don't want to screw it up.

                      1 Reply Last reply Reply Quote 0
                      • ObsolesceO
                        Obsolesce
                        last edited by

                        Do you have an offline root CA or is do you just have a single CA that does it all: certificate issuing, CDP, etc.?

                        1 Reply Last reply Reply Quote 0
                        • 1 / 1
                        • First post
                          Last post