Multiple User Certificates
we have 2 tier certificate server (one offline , 1 issuing ca) our domain. our o365 people noticed users have 10+ user certificates issued , certificates are getting published in ad (and eventually into gal).
the user's laptop has 1 user certificate list in certmgr.msc\personal.
my understanding 1 certificate published user in ad , renewed automatically when certificate nearing expiration date.
what cause multiple user certificates published in ad?
your thoughts?
thanks
this happens when users logged multiple systems , have never logged out. such rdp sessions, laptops, desktops, etc.. can difficult track down logged in , consequently user profile still active , gpo refresh creating new certificate requests. can modify certificate template on general tab of template prevent enrollment if user has certificate based on template. there no way know single enrollment occurred.
credential roaming can used ensure users single certificate , available them ever logon in domain.
mark b. cooper, president , founder of pki solutions inc., former microsoft senior engineer , subject matter expert microsoft active directory certificate services (adcs). known “the pki guy” @ microsoft 10 years. connect mark @ http://www.pkisolutions.com
Windows Server > Security
Comments
Post a Comment