Should I remove msPKI-PrivateKeyRecoveryAgent object after Enterprise Root CA has been decomissioned?
hello guys,
i've decommissioned old enterprise root ca (windows server 2008 r2). have uninstalled ad cs role old server , cleaning ad objects listed in article below. new enterprise root ca in place.
https://support.microsoft.com/en-us/help/889250/how-to-decommission-a-windows-enterprise-certification-authority-and-remove-all-related-objects
while cleaning ad objects came across mspki-privatekeyrecoveryagent object in
cn=kra,cn=public key services,cn=services,cn=configuration,dc=domain,dc=local. there 2 objects
in container, 1 old , 1 new ca.
article doesn't advice directly remove this. used , should simple remove it?
thank help!
vadims podāns, aka powershell cryptoguy
weblog: www.sysadmins.lv
powershell pki module: pspki
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.
Windows Server > Security
Comments
Post a Comment