Certificate error on all clients

Mahyar S 1 Reputation point
2021-06-30T06:46:01.617+00:00

Hi

We have a domain controller that is about 12 years old, the OS itself has been upgraded regularly (now it is Windows Server 2019) because in these years a lot of setting has been changed or a couple of services connected to Active Directory then disconnected, a lot of junks has been leftover and many services not work as proper as used to.
Therefore, we need a way to clean up our domain controller.
Recently we seize our primary DC and install a fresh OS but when making it primary again, it takes back all those crap from our additional DC, so back, to where we are

The reason I ask you is that recently an annoying problem occurred, any Windows PC that joins our domain get SSL Cert error even for google.com
I create a policy on top of the tree and import an updated version of certificates from Microsoft and enforce that policy but the problem still exists.

PS: dcdiag.exe is showing everything pass

Thank you in advanced

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,838 questions
0 comments No comments
{count} votes

7 answers

Sort by: Most helpful
  1. Hannah Xiong 6,276 Reputation points
    2021-07-21T04:54:01.893+00:00

    Hi @Mahyar S ,

    You are welcome. Thank you so much for your kindly reply.

    So glad that the certificate error is gone. Based on the scenario we described, it is hard to judge the causes of the issue. And based on my understanding, it is more like a performance issue. Have we tried to use a different Browser to open the website?

    Greatly appreciate your time and support.

    Best regards,
    Hannah Xiong


  2. Mahyar S 1 Reputation point
    2021-08-07T06:41:56.05+00:00

    Hi @Hannah Xiong
    I'm sorry to bring up this topic again!
    I see something new and thought I should update this topic
    as you can see below I screenshot certificate of this site (https://learn.microsoft.com) in two different PC

    1.PC Joined to our domain that has a problem

    121327-incorrect.jpg

    2.PC joined to a clean test domain

    121326-correct.jpg

    As you can see PC number 2 have the correct certificate but the certificate of PC number 1 is not correct at all! it's issued by PC itself not Microsoft and all the details are different.

    both of the PCs use the same internet, same browser, same OS but performance of opening site like this topic is very different.
    I think this problem is because of an old certificate authority that was in our domain and now it doesn't exist.

    Do you have any thoughts?

    Thank you for your time

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.