Trusted root certification authority.

Hello,

I notice with every server and client machine in our organisation, that some how 2 root certificates (purpose: All) are getting added automatically.

These root certificates are already expired and not related to our current enterprise CA server.

I checked RSOP.html on client machine and or GPO's on DC, but could not figure out the source.

Any help greatly appreciated.

Thanks.

April 19th, 2015 10:43am

Hi,

Since these root certificates dont belong to your own CA, neither were published through Group Policy, then they could be added by Windows Root Certificate program.

More information for you:

Introduction to The Microsoft Root Certificate Program

http://social.technet.microsoft.com/wiki/contents/articles/3281.introduction-to-the-microsoft-root-certificate-program.aspx

Best Regards,

Free Windows Admin Tool Kit Click here and download it now
April 20th, 2015 9:37am

Thanks for your reply Amy,

Sorry, what I mean to say it does not belong to our current CA,

but they clearly are (self-signed) from our organisation.

How they are still getting distributed is unsure.

April 20th, 2015 11:46am

Hi,

You are welcome.

You may enable CAPI2 log to monitor certificate store operations, which is under Applications and Services Logs\Microsoft\Windows\CAPI.

After you enable CAPI2 log, delete those 2 root certificates, wait to see whether they will be added again. If they do, check CAPI2 log to find detailed information.

More information for you:

Enable CAPI2 event logging to troubleshoot PKI and SSL Certificate Issues

http://blogs.msdn.com/b/benjaminperkins/archive/2013/10/01/enable-capi2-event-logging-to-troubleshoot-pki-and-ssl-certificate-issues.aspx

Best Regards,

Amy

Free Windows Admin Tool Kit Click here and download it now
April 21st, 2015 1:58am

Try to use PKIView utility. In PKIView, right click on your enterprise PKI object on the left panel and select manage containers option. Verify the root CA centificates and see if you can find them in the root CA container. Delete them from the container. HTH.
April 21st, 2015 3:59pm

Also check the AIA container for the same.
Free Windows Admin Tool Kit Click here and download it now
April 21st, 2015 4:10pm

Great. Thanks 

I can see those 2 root certs under "Certification Authorities Container, CDP container and AIA Container"

So what does this means? does it means they were some old CA in our organisation from past?

and once I remove them from here, I understand they wont be further deployed to client - right?

Will I also need to run some script to get removed from all client machine.




  • Edited by Beadmin 5 minutes ago correct2
April 22nd, 2015 3:24am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics