How do I know what my certification server is doing
Excuse my noobness here, but I just realized my domain controller that I want to replace is also a certificate authority.  I noticed its issued some certificates and it has about 8 or 9 outstanding certifications that have not expired.  It shows the issued certificates are CA Exchange, Basic EFS and Domain Controller.  I've looked on Microsofts website and it explains what each template is used for (ie: domain controller template used for client and server authentication).  So my question is how do I know whats using those certificates or if they are even needed?  I have no clue this service was even running and I'd really like to just turn it off, but I'd like to find out if its going to cause any issues.  Is there any way I can find out what exactly my domain controllers are doing with these certificates?
March 25th, 2015 1:02pm

Domain Controller template is used by DCs to allow LDAPs (LDAP over SSL), smart card authentication and SMTP replication traffic signing.

CA Exchange template is used for key archival purposes, to securily transfer client private key to CA server.

In your case it is most likely that they are not used, so you can safely decommission your CA server and domain controller.

Free Windows Admin Tool Kit Click here and download it now
March 26th, 2015 2:58am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics