Domain controller certificate renewal issue

VIGNESHWARAN M 1 Reputation point
2025-03-18T11:33:52.8566667+00:00

Hi, Domain controller certificate auto renewal is not happening. I'm using Microsoft CA server and have to manually renew the certificates in the domain controller. Is there anyway to automatically renew this certificate without manual intervention? Thanks

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2025-03-19T03:10:30.4433333+00:00

    Hello VIGNESHWARAN M,
    Thank you for posting in Q&A forum.

    Is there anyway to automatically renew this certificate without manual intervention?

    A: Yes, you automatically renew this certificate without manual intervention, please set two steps to automatically renew Domain Controller certificate.

    Step 1

    Configure "Read and Enroll and Autoenroll" permissions on the specific Domain Controller Certificate Template you configured.

    User's image

    Issue this certificate tempalte.

    User's image

    Step 2

    Set Auto-Enrollment policy and apply it to Domain Controllers.

    1.Open Group Policy Management, edit the Default Domain Controller Policy (or create a new GPO and link this new GPO to Domain Controllers OU and edit this new GPO).

    2.Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Public Key Policies. Here you will see Certificates Services Client – Auto-Enrollment policy.

    User's image

    3.Open its properties and choose Enabled on the Configuration Model box, then check the boxes Renew expired certificates, update pending certificates, and remove revoked certificates and Update certificates that use certificate templates. Click OK when you are done. As you can see this policy will automatically renew any expired certificates and also cleans up the certificates store of any certificates that expired.

    User's image

    At last, run gpupdte /force on Domain Controller or wait for the group policy to refresh in the background (by default it refreshes every five minutes on DC).

    I hope the information above is helpful.

    If you have any questions or concerns, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.