New certificates are being issued every time a user authenticates, creating hundreds of duplicates


i configured basic root ca on 2008 r2 domain controller. have created duplicate user , workstation templates , set permissions domain users , domain computers allow "enroll" , "autoenroll" permissions, , changed gpo allow auto enrollment. each user , machine being issued certificate, can see in "issued" folder on ca server.

however, i'm seeing hundreds of duplicate certificates. seems each time user or machine authenticates, generates certificate. servers , dc's each have dozens of certs, , none of them expired or revoked.

is normal behavior? thought each user/device gets 1 certificate? or did configure incorrectly?

 

thanks



you need research credential roaming allow roaming of certificates (preventing duplicates)

also, never use duplicate of user, enables smime , basic efs without key archival.

it worst practice, imho, combine signing , encryption purposes in single certificate

brian



Windows Server  >  Security



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Domain migration ERR3:7075 Failed to change domain affiliation, hr=8007054a This operation is only allowed for the Primary Domain Controller of the domain

How do a find data in one file, search for it in another file and if not found, write a custom message to another file