Should I remove msPKI-PrivateKeyRecoveryAgent object after Enterprise Root CA has been decomissioned?


hello guys,

i've decommissioned old enterprise root ca (windows server 2008 r2). have uninstalled ad cs role old server , cleaning ad objects listed in article below. new enterprise root ca in place.

https://support.microsoft.com/en-us/help/889250/how-to-decommission-a-windows-enterprise-certification-authority-and-remove-all-related-objects

while cleaning ad objects came across mspki-privatekeyrecoveryagent object in
cn=kra,cn=public key services,cn=services,cn=configuration,dc=domain,dc=local. there 2 objects
in container, 1 old , 1 new ca.

article doesn't advice directly remove this. used , should simple remove it?

thank help!

yes, safe remove kra certificates active directory because unlikely valid , can used further encryption.

vadims podāns, aka powershell cryptoguy
weblog: www.sysadmins.lv
powershell pki module: pspki
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.



Windows Server  >  Security



Comments

Popular posts from this blog

Group Policy Event ID 1058 Error Code 1326 (The user name or password is incorrect)

Suspicious event log Event ID: 4905

DCOM received error "2147746132" from...