Subordinate showing two certificates,how we can clean manaully.

2020-12-01T09:28:19.23+00:00

Hi Team

Due to some circumstance, my subordinate certificate showing two certificate, Please guide me how to remove manually from the certificate authority.

43910-subordinate.png

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,799 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Abhijeet-MSFT 546 Reputation points Microsoft Employee
    2020-12-01T15:38:55.587+00:00

    On the subordinate CA, navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\CA-NAME. Look for cacerthash registry. This will contain the hash of your CA Certificate. Please remove the unwanted hash entry.

    Make sure to take a backup of registry before making any change.

    1 person found this answer helpful.

  2. Daisy Zhou 25,296 Reputation points Microsoft Vendor
    2020-12-02T07:17:36.383+00:00

    Hello @MohammadEhteshamuddinKhanACCESS-3899,

    Thank you for posting here.

    We can not delete the two certificates if the two certificates are not expired.

    If one or more certificates expired, we can delete it.
    44248-1111111.png

    And the deletion method is as follows:

    Open PKIview.msc on Enterprise CA server.

    1) Start pkiview.msc.

    2) Right-click Enterprise PKI, and then click Manage AD Containers

    3) Click the each tab to check this expired certificate and compare the serial number (if the serial number is the certificate that expired and we want to delete, we can delete it).

    4) Select the old root CA certificate and then delete it
    44199-111.png

    Tip:
    Why there are two certificates (certificate #0 and certificate#1), because we have renewed the subordinate certificate.

    Best Regards,
    Daisy Zhou


  3. Daisy Zhou 25,296 Reputation points Microsoft Vendor
    2020-12-03T03:38:36.907+00:00

    Hello @Mohammad Ehteshamuddin Khan - AC CESS ,

    If there is no any relationship between certificate #0 and certificate #1, I mean certificate #1 does not use certificate #0's thumbprint to signature, and no certificates issued by certificate #0 and you must to delete certificate #0, it is the same step.

    For example:
    45036-thru.png

    Hope the infomration is helpful. If anything is unclear, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.