Multiple User Certificates


we have 2 tier certificate server (one offline , 1 issuing ca) our domain.  our o365 people noticed users have 10+ user certificates issued , certificates are getting published in ad (and eventually into gal).  

the user's laptop has 1 user certificate list in certmgr.msc\personal.

my understanding 1 certificate published user in ad , renewed automatically when certificate nearing expiration date.

what cause multiple user certificates published in ad? 

your thoughts?

thanks

this happens when users logged multiple systems , have never logged out. such rdp sessions, laptops, desktops, etc.. can difficult track down logged in , consequently user profile still active , gpo refresh creating new certificate requests. can modify certificate template on general tab of template prevent enrollment if user has certificate based on template. there no way know single enrollment occurred.

credential roaming can used ensure users single certificate , available them ever logon in domain.


mark b. cooper, president , founder of pki solutions inc., former microsoft senior engineer , subject matter expert microsoft active directory certificate services (adcs). known “the pki guy” @ microsoft 10 years. connect mark @ http://www.pkisolutions.com



Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group