New certificates are being issued every time a user authenticates, creating hundreds of duplicates
i configured basic root ca on 2008 r2 domain controller. have created duplicate user , workstation templates , set permissions domain users , domain computers allow "enroll" , "autoenroll" permissions, , changed gpo allow auto enrollment. each user , machine being issued certificate, can see in "issued" folder on ca server.
however, i'm seeing hundreds of duplicate certificates. seems each time user or machine authenticates, generates certificate. servers , dc's each have dozens of certs, , none of them expired or revoked.
is normal behavior? thought each user/device gets 1 certificate? or did configure incorrectly?
thanks
you need research credential roaming allow roaming of certificates (preventing duplicates)
also, never use duplicate of user, enables smime , basic efs without key archival.
it worst practice, imho, combine signing , encryption purposes in single certificate
brian
Windows Server > Security
Comments
Post a Comment