Computer certificates expiring within 6 weeks disappearing from machines when computer certificates from two certificate authorities are present

2008 R2 single tier enterprise certificate authority with root certificate expiring within 6 weeks, also domain controller
2012 R2 single tier enterprise certificate authority with root certificate valid for more than the next year, also domain controller
Both servers are approved as certificate authorities for the domain and can issue computer certificates using the computer certificate template. There is a group policy object applied to all workstations that contains an automatic computer certificate request,
but the actual "certificate services client auto-enrollment" element is "not configured". This process seems to work like a round robin in that computers with no certificate can wind up with a certificate from either certificate
authority. I need all PCs to have both certs for a DirectAccess migration. I have successfully used SCCM to ensure all PCs have both certificates using compliance rules and a script using certreq.exe.
A machine will keep both certs until the older computer certificate moves into the 6 week window of expiration, then it gets purged. I have observed this behavior for over a month, even when the CA root certificate wasn't so close to expiring. I
can't figure out what setting is triggering the purge, but need to stop it. Maybe it's coming from default settings in local machine policy for an element that should be disabled in the group policy object supplying the automatic certificate request?
The worst part of this issue is that I can't recreate the purging behavior with gpupdates or restarts on my test machines.

You should not be using Automatic Certificate Request Service (ACRS) for this - it was designed for Windows 2000 and is generally deprecated. Secondly, the reason it is acting like a round-robin as you describe it, is that templates are generally configured
to attempt to renew within 6 weeks of their expiration. Since the 2008 R2 CA is expiring within 6 weeks, it cant issue anything longer than its own remaining lifetime. It is a well known issue that issuing a certificate within the renewal period will cause
problems.
What you should do it use AutoEnrollment and issue a certificate with a very small renewal period (1 week perhaps) by creating a custom V2 template and issuing that from your 2008 R2 CA. Then on the 2012 R2 CA you will need ANOTHER template, as the computer
will only enroll for a certificate from each template. This one can be configured with a normal lifetime and renewal period.
Mark B. Cooper, President and Founder of PKI Solutions Inc., former Microsoft Senior Engineer and subject matter expert for Microsoft Active Directory Certificate Services (ADCS). Known as “The PKI Guy” at Microsoft for 10 years. Connect with Mark at http://www.pkisolutions.com

Similar Messages

  • Hi. I wanna know the reason whyI can't sync my ipad to my computer. It says that sync will resume when (computer's name) is available? My device runs with ios6.1.3 and itunes 11. Please answer. Thanks.

    Hi. I wanna know the reason whyI can't sync my ipad to my computer. It says that sync will resume when (computer's name) is available? My device runs with ios6.1.3 and itunes 11. Even I would like to transfer and view photos using the USB cable, it doesn't appear in the computer. Please answer. Thanks.

    Hi Lauren ...
    Try the troubleshooting steps here > iOS: Device not recognized in iTunes for Windows

  • I just bought a new Macbook Pro and transferred my iTunes archive of music to it. How do I transfer the playlists from my other computer(s)? iTunes on the new machine wants to start from scratch.

    How do I transfer playlists from my other Apple computer(s) to my new Macbook Pro? I think I have successfully moved the music (archive) but the new machine wants to start from scratch on the playlists.

    http://support.apple.com/kb/ht1751
    Essentially you need to copy over the itunes folder
    username/Music/itunes
    Over to your macbookpro I suggest using an ethernet cable as it is way quicker. Put it in the same spot on the new Macbook Pro
    username/music/
    This should bring over the playlists etc. Then just put the music back in from the archive

  • My contacts have been transferred from my iPhone5 to iPhone6 . I now need to back them up in a new PC in a separate address book How can I do it without adding all contacts from Outlook when I synch  from iTunes ?

    My contacts have been transferred from my iPhone5 to iPhone6 . I now need to back them up in a new PC in a separate address book How can I do it without adding all contacts from Outlook when I synch  back from iTunes ?

    From the OP: "My old computer got a virus and when that happened all my music was lost. "
    They don't have the music on their computer so they cannot transfer the iTunes folder, from the computer to their iPod and then to the new computer. And if they try to enable disk use on the iPod it will erase all the music that is on it. The method you cited is moving the files in a data format using the iPod as a flash drive. It doesn't work if they are in music format. That is why I suggested Yamipod.

  • Error -2147415740 from Keychain when importing a root CA certificate

    I've been given an iMac at work to use as my primary workstation, and work in an environment that uses certificate based authentication. I was provided the root CA certificate as a .pem file to import into my system, and every time I try, Keychain Access throws an error of "-2147415740".
    Running "openssl x509 -inform pem -in cacert.pem -text" shows the certificate as valid, and specifically:
    Subject Public Key Info:
    Public Key Algorithm: rsaEncryption
    RSA Public Key: (8192 bit)
    Modulus (8192 bit):
    I've seen a few other reports of this, and it seems to be tied to the certificate being signed with an 8192 bit key. Asking the company to change to a lower key to sign the certificate is not a possibility, as it would require redistribution across a high number of machines to work around what appears to be an OS X specific bug. Does anyone know a workaround?
    Out of curiosity, I took the certificate and imported it successfully into an iBook running OS X 10.4.0. The certificate continues to work all the way up to 10.4.8, but breaks once Security Update 2006-007 or 10.4.9 is applied. The certificate is also imported just fine on an iPad running iOS 4.2.1.
    For now, I have to avoid using any Apple provided tools, and many 3rd party OS X programs, negating the benefit of using OS X and an iMac.

    sigh
    Result 1, this thread
    Result 2, another person encountering the same problem and posted here on the discussion forums, unanswered, beyond me responding to see if it is the exact same situation I'm now running into.
    Result 3, a posting to the OpenCA users list, also confirming the problem, with no specific solution to the error. Only a workaround of resigning the CA with a 4096bit or lower key, a workaround that as I mentioned already, cannot be done here without forcing every other user in the company to do work for what appears to only be an OS X specific problem/bug.
    Please only respond again if you have an actual useful suggestion for this exact problem. These boards are to help facilitate discussion about problems leading to a solution. Neither of your generic responses has helped, and I'd appreciate it if you could avoid wasting more of my time following up on a new post notification.

  • How to prevent computer from sleeping when downloading Lion from the recovery partition?

    Hello,
    I just got a new MacBook Pro that came with Lion. I'm reinstalling from the recovery partition and I'm on the downloading additional components stage. It has 3 hours to go and the computer keeps going to sleep. How can I prevent this? I don't want to have to babysit the computer for 3 more hours.
    Thanks.

    Looking for an answer to this question now.  Did you find one?  I'm about an hour into a 6+ hour reinstall of Mountain Lion from the Recovery partition on my MacBook Pro.  So I can't change the sleep corners or caffenate it or do much of anything but wait.   I want to go to bed and let it install overnight, but I assume it will go to sleep, and that will kill the download.  It there any way to prevent it from sleeping now? 
    Even trying to think of something I can put on the trackpad to trick it into thinking I'm touching it.
    Maybe ill put it under my dog, and her movements will keep it awake?  Thinking outside the box here.
    Any ideas would be appreciated.

  • Booting From Ipod When Computer Restarts

    I used to have this problem with my ipod whenever i restarted my computer, it would freeze at the beginning of the starting up process unless the ipod was disconnected
    Then i bought a usb hub and it seemed to fix the problem, i could restart and it wouldnt interfere
    but now its started doing it again and i was wondering if someone knew how i can fix this?
    Its not in the main settings, cuz the boot order is all normal!
    thanx

    any kind of help would be great lol

  • IPod touch won't play ANY music, only skips. All music plays when FROM ipod when plugged into iTunes. No, songs are not corrupt, I was playing an album through iTunes from my iPod and for no reason iTunes froze and now I'm having issues with my iPod.

    So I was playing an album from my iPod through iTunes like normal, and the album ended. I switched to iTunes view to change to a new one and it said "iPod is done syncing" (I did not choose to sync, nor did anything appear different). I tried to click on a song to play and iTunes froze. I had to restart iTunes and when I ejected my iPod (properly) the syncing sign was still turning on my iPod. As of now my iPod only skips through every song I try to play, but when I plug it into iTunes every song FROM my iPod plays perfectly.
    No, I do not want to "factory reset" my iPod. No I do not wish to do anything crazy long or hard to fix this. Everything was working fine before when it decided to do this with very little effort, therefore I would like it fixed with very little effort.
    I have tried resycing my iPod multiple times (every time I eject it from iTunes it appears to do so properly [iPod icon goes away] but the syncing icon still appears on my iPod).
    I have almost 58 GB of music on my iPod so I'm not interested in starting from scratch. Also a good portion of my music is on a computer I don't have access to anymore so that's out of the question. Since the music seems to be uncorrupted (still plays from iPod in iTunes) I want a way to fix this iPod issue without having to erase anything.

    Try:
    - Reset the iOS device. Nothing will be lost
    Reset iOS device: Hold down the On/Off button and the Home button at the same time for at
    least ten seconds, until the Apple logo appears.
    - Unsync all music and resync
    - Reset all settings      
    Go to Settings > General > Reset and tap Reset All Settings.
    All your preferences and settings are reset. Information (such as contacts and calendars) and media (such as songs and videos) aren’t affected.
    - Restore from backup. See:                                 
    iOS: How to back up           
    - Restore to factory settings/new iOS device.
    If still problem, make an appointment at the Genius Bar of an Apple store since it appears you have a hardware problem.
    Apple Retail Store - Genius Bar          
    You said:
    No, I do not want to "factory reset" my iPod. No I do not wish to do anything crazy long or hard to fix this. 
    That may be necessary, It is not what you want to do/not do but what is required to resolve your problem.

  • Distortion from SP when video sent from FCP

    Loops play fine when a stand alone project is open, but when I 'send' my timeline from FCP to SP, every loop played is distorted. The video plays back fine, but the distortion remains with or without imported audio, as well. Any help?
    Also, my timeline: DVCPROHD 720P at 29.97fps, 48kHz, 16-bit depth.
    Any help is appreciated. thx.
    Message was edited by: erackblack

    WOW! A new development. The clips that will not show changes come from a sequence that contains other clips that I was able to color and send back to FCP successfully. So i copied the clips that I want to color and pasted them in another sequence with some other random clips (not colored) and sent everything to Color! I did some test grading on all the clips and sent them back to FCP. The random clips that were already in that sequence reflected the changes I made in color. The clips that I pasted (the ones I need) did not reflect any changes from Color. I think the problem is within the clips. That is so weird. Anyone know what is going on?

  • Mail, why doesn't it just delete from everywhere when I delete from iphone?

    This is another issue I can't seem to resolve. As per my other post about iCal, I expected my iphone to offer a seamless environment. I even, somewhat begrudgingly, would pay the $120 a year to mobileme if it did everything I want... sadly what I think I want is what the blackberry does!
    Anyway, to get more specific. I want to be able to only have to delete and email once (e.g. if I read it and delete it on the iphone I don't want it to still be existing on my mac) and I want my mac and iphone to effectively be two components of one integrated system. Is this possible with mobileme or anything else without having to set up a dedicated server using microsoft exchange?

    If you are dealing with IMAP or Exchange (ones that use ActiveSync) they will delete everywhere as those protocols do sync all up.
    If you are using POP, remember POP was not meant to be used from so many locations. It doesn't SYNC. It in a sense copies. There are advanced settings for your POP account though that you can say remove from server once moved out of inbox but note that won't happen until next poll.
    Your complaint has to do with the type of protocol your mail account uses.
    For me, I do most of my email that I care about having access to when not at work via gMail and gMail uses IMAP thus it does sync up. If I delete or move a message on the phone, it deletes/moves on the server, if I do it via the computer or mail client that I use to interact with gMail, it updates my phone. All nice and synced.
    So sounds like to me you are just using a POP account the POP protocol is very limited.
    Message was edited by: DaVBMan

  • No sound from TV when using HDMI from HP Envy Ultrabook4 despite downloading drivers

    Problem: When using an HDMI cord from my HP Envy Touchsmart Ultrabook 4 (4-1105dx)to connect to my TV to view movies, the video appears on my TV screen, but there is NO sound from the TV. Instead the sound comes from my lap top.
    Troubleshooting: I have looked under Sounds in the Control Panel, but the only choice listed is Speakers & Headphones IDT High Definition (which is the default) and does not allow sound from the TV when using the HDMI. I have also tried to download Driver and Audio Graphics, but wasn't sure which one & the ones which were downloaded have not solved the problem.
    Can you assist me? Which is the correct Audio/Graphic Driver to download? Or is there another possible reason why I cannot hear sound from my TV when using the HDMI to connect to my lap top?

    Hi,
    Please try this first to enable Speakers in Playback devices as follows:
    1. Right click speaker icon (bottom right hand corner)
    2. Select Playback devices
    3. Right click HDMI sound
    4. Enable it
    5. Click Apply/Ok
    Regards.
    BH
    **Click the KUDOS thumb up on the left to say 'Thanks'**
    Make it easier for other people to find solutions by marking a Reply 'Accept as Solution' if it solves your problem.

  • Is it possible to keep the outline auto formatting from Pages when copying and pasting that outline to the Presenter Notes on Keynote?

    I have been using my iPad for my notes, but I want to start using it as a remote for my macbook. When I copy and paste the notes into the Presenter Notes section of Keynote on the macbook, it unformatted. Any bullet point formatting that I do on my macbook is not showing on my iPad's Remote view Presenter Notes. Is there a way to create consistency here that does not involved formatting each one separately?

    Use Drag and Drop
    Have both applications open side by side
    select the text in Pages
    with the mouse drag the text from pages into presenter Notes pane in Keynote

  • No sound from TV when AirPlaying Keynote from iPad

    I'm AirPlaying a keynote presentation from my iPad Air to my Apple TV 3rd generation. There's a video in the Keynote and when it plays, there's no sound but I can still see the video. I addes a short audio track to the presentation as a test and it couldn't be heard either. I would try to see if they play on my iPad without AirPlaying it but the app crashes after the first slide, yet I'm able to get through the whole presentation when I'm AirPlaying it. I've tested other sounds on my iPad and they all AirPlay fine to my TV, it's just the Keynote presentation. Everything works fine on my iMac. Any help?

    Nevermind. I knew I was doing something stupid. The iPad's ringer was on silent the whole time :/
    But keynote still crashes on the second animation when I try to play the presentation on my iPad without AirPlaying it. I'd still like some help there if anybody thinks they can.

  • Error when Saving FR Report from Studio when Making Changes from Client PC

    We get the following error when trying to save a report when using FR Studio from a Client PC: *"Expecting a transferable end, but received -4352: 2067198, expected: -4113, <-4098>, 8074 -4098"*. We do not get this error if we so a Save As instead of a Save.
    If we use FR Studio while remoted into the FR server, we do not get this error.
    Any idea what may be the cause of this error message?
    Thanks.
    Terri

    We had a similar issue on 11.1.2, which was never really resolved. Is this the version you are on?

  • Triger/transmit light from projector when i sanp from camera with IMAQ PCI 1407

    I want to activate projector to emit light when i snap

    Take a look at the low level snap example. Put the IMAQ Trigger Drive VI between the IMAQ Configure Buffer and IMAQ Start and set the "trigger drive" input to asserted. This will drive the trigger line as soon as the VI is called. Alternately, you could choose another condition such as "acquisition done" to drive the trigger after the frame is acquired. Please note, as soon as you call IMAQ Close, the trigger line will return to the default tri-state.
    Regards,
    Brent R.
    Applications Engineer
    National Instruments

Maybe you are looking for

  • InDesign JPG Compression vs Illustrator/Photoshop

    I am working on a website and need to put in a lot of images. For most images, I use photoshop. I create the correct size then export using "Save As for Web & Devices." This works great, but I need to display several small images in a grid format. Wh

  • MSCS cluster installation on win + sql server 2005

    Dear Guru, I want to  installing MSCS cluster installation on win 2003 ENT.with sql server 2005 . Choosing High availability (ABAP) Please Guide me prerequisit & partation on local & shared disk. Its Urgent. Personal mail ID is [email protected] Rega

  • Screen Saver and IPTV

    How can I prevent the Screen Saver coming on while watching IPTV programs?

  • Purpose of .jar

    Hello,All ! I am a begaining of java learner.I want to know about the purpose of .jar file. And which way I should use for changing .jar file in eclipse platform.If you know,please tell me. Thanks.

  • Disk Info not showing capacities

    Hi everyone, I have an old G4 as a classroom computer and something odd is happening to how it sees the hard drives. I tried to copy a file to them from a networked computer and there was not enough space which was not true. The Finder will not show