Certificate error on all clients

Mahyar S 1 Reputation point
2021-06-30T06:46:01.617+00:00

Hi

We have a domain controller that is about 12 years old, the OS itself has been upgraded regularly (now it is Windows Server 2019) because in these years a lot of setting has been changed or a couple of services connected to Active Directory then disconnected, a lot of junks has been leftover and many services not work as proper as used to.
Therefore, we need a way to clean up our domain controller.
Recently we seize our primary DC and install a fresh OS but when making it primary again, it takes back all those crap from our additional DC, so back, to where we are

The reason I ask you is that recently an annoying problem occurred, any Windows PC that joins our domain get SSL Cert error even for google.com
I create a policy on top of the tree and import an updated version of certificates from Microsoft and enforce that policy but the problem still exists.

PS: dcdiag.exe is showing everything pass

Thank you in advanced

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,856 questions
0 comments No comments
{count} votes

7 answers

Sort by: Most helpful
  1. Hannah Xiong 6,276 Reputation points
    2021-07-01T03:27:25.98+00:00

    Hi @Mahyar S ,

    Thanks a lot for posting here.

    Before and after we make any change to our AD environment, please kindly make sure that all domain controllers work well and the replication status among the domain controllers is okay without any error.

    To check about this, we could run the below commands:

    dcdiag /v /e>c:\temp\dcdiag.txt
    repadmin /replsummary /bydst /bysrc >C:\temp\replsummary.txt
    repadmin /showrepl * /csv >C:\temp\repall.csv

    As for the certificate error, if possible, would you please share the screenshot of this error? So we could better understand this issue. Besides, may I know whether it is SSL self-signed certificate?

    Looking forward to hearing from you. Thanks.

    Best regards,
    Hannah Xiong


  2. Hannah Xiong 6,276 Reputation points
    2021-07-05T02:55:08.617+00:00

    Hi @Mahyar S ,

    Thank you so much for your kindly reply.

    Due to security consideration, it is suggested not to post any logs here. As for the confidential information, it is suggested to make them blurred.

    I have checked that there is nothing wrong with the AD replication. From the dcdiag report, there seems to be something wrong with SYSVOL replication. Would you please kindly run the below commands to check for more information?

    Net share

    dfsrmig.exe /getglobalstate

    wmic /namespace:\root\microsoftdfs path DfsrReplicatedFolderInfo get ReplicationGroupName, ReplicatedFolderName, State

    As for the SSL certificate issue, it is showing that "This certificate cannot be verified up to a trusted certificate authority". I have found this documentation and hope it would be of some help.

    https://techcommunity.microsoft.com/t5/iis-support-blog/you-get-a-security-alert-when-you-try-to-access-an-ssl-enabled/ba-p/348093#:~:text=You%20get%20%22%20This%20certificate%20cannot%20be%20verified,and%20users%20accessing%20the%20web%20site%20over%20Internet.

    Best regards,
    Hannah Xiong


  3. Mahyar S 1 Reputation point
    2021-07-19T04:31:51.497+00:00

    Hi
    I checked the SYSVOL replication and it was ok.
    about the certificate problem, now none of the domain clients get a certificate error because of the policy but the SSL sites became slow and don't work right!
    I thought maybe the problem is our internet provider or our firewall config but no, if a client uses our network without joining our domain everything works perfectly, but if a joined client wants to work with the internet works badly! I even test a joined client out of our network with deferent internet but still works badly!

    Thank you for your time.

    0 comments No comments

  4. Hannah Xiong 6,276 Reputation points
    2021-07-19T09:34:36.477+00:00

    Hi @Mahyar S ,

    Thank you so much for your kindly reply.

    As mentioned, the certificate error has been resolved because of the policy, but now our SSL sites became slow and do not work right.

    Based on my understanding, we access the SSL site google.com via https. If so, it will verify the validity of the certificate. May I know whether we could successfully access the site finally? Or is there any error message we would see?

    To figure out this issue, I would suggest capturing network trace and maybe CAPI2 logging for further analysis. Due to the security reason,I would suggest you contact Microsoft Customer Services and Support to get an efficient solution:

    https://support.serviceshub.microsoft.com/supportforbusiness

    Thanks a lot and have a nice day.

    Best regards,
    Hannah Xiong

    0 comments No comments

  5. Mahyar S 1 Reputation point
    2021-07-20T04:20:22.927+00:00

    Hi @Hannah Xiong
    The certificate error it's gone but when you want to use a site with SSL, the website gets stuck on loading or maybe some part of that website load and not all of it.
    Anyway thank you so much for your help

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.