Removing Certificate Authority impact on domain controller

jeff mcnabney 301 Reputation points
2022-01-19T18:28:14.453+00:00

Removing CA on retiring server 12r2 DC. There are 4 certificates with outstanding expirations pending in 2022/2023. One webcert for an exchange server that is using a separate 3rd party ssl certificate for all its services, however the certificate is still installed on the server itself with some services, even though the 3rd party is the primary one. Can i revoke that cert? Will it force the exchange server to spit up error messages, or should i remove it from the Exchange server first? Then there are three certs for each of the existing domain controllers, including the one to be retired. If i revoke all the certs, what side effects might they have on the DC's? Anything?

I've never been sure what they are required for on DC's in this circumstance.

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,736 questions
{count} votes