Microsoft CA Auto Enrollment certificate with do not auto re-enroll conflict

Nain, Aditya (Cognizant) 1 Reputation point
2020-06-22T08:37:42.79+00:00

If, Do not automatically re-enroll checkbox is ticked, what will happen if a certificate gets expired or is entering its renewal period?

Does renewal period will conflict with do not auto reenroll?

When a cert is going to expire, a new one will be issued when only 6 weeks are remaining till expiry...but "do not auto reenroll" should block it from getting issued because it will be duplicate certificate?10456-template-general-tab-2-2ca81784.png

Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
6,865 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Sedat SALMAN 13,080 Reputation points
    2023-05-02T12:16:31.71+00:00

    When the "Do not automatically re-enroll" checkbox is selected, the auto-enrollment process does not renew the certificate when it reaches its renewal period or expires. Auto-enrollment is intended to manage certificates automatically by renewing them before they expire, but by checking the "Do not automatically re-enroll" box, you effectively disable this feature for that specific certificate.

    If the certificate expires and you have the "Do not automatically re-enroll" option enabled, it will not be automatically renewed, and you may experience issues or disruptions in services that rely on the certificate for authentication or encryption.

    The renewal period will not conflict with the option "Do not auto re-enroll." If you enable this option, the renewal period is simply ignored, and the certificate is not renewed.

    If you want to manually renew the certificate, you must request a new certificate from the certification authority (CA) and replace the expired certificate in your environment.

    Allowing automatic re-enrollment for certificates that are critical to the functionality of your environment is generally recommended to avoid issues or disruptions in services. If you must disable automatic re-enrollment for any reason, keep track of the certificate expiration dates and plan for manual renewals.

    0 comments No comments