Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Expired logon certificates on smartcards not being deleted

Reply
Thread Tools Display Modes

Expired logon certificates on smartcards not being deleted

 
 
Egil
Guest
Posts: n/a

 
      08-18-2009
Hello,

I have a problem with expired logon certificates on smartcards not being
deleted. This leads to full smartcards.

In Windows Server 2008 PKI and Certificate Security by Brian Komar, p. 270,
it is stated that on a certificate template the "Delete revoked or expired
certificates" option is critical for conserving space on smartcards. However,
this option is not possible to enable when choosing purpose "Signature and
smart card logon" on the template. Is there another way of automatically
deleting expired certificates on smartcards (without using ILM! Our
organisation is way to small to utilise ILM)?
I have also tried using the "Signature" purpose (which enables the
delete-option), but without any further luck in automatically deletion of
expired certs. This purpose also places the cert inside the AT_SIGNATURE key
container of the smartcard, and this again leads to more trouble when joining
clients to domain because of the default setting of not accepting signature
keys for logon (strange default setting by the way).

Any enlightment on the subject is greatly appreciated!
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Delete revoked or expired certificates and smartcards Egil Windows Server 0 08-05-2009 09:18 AM
deleting expired certificates luke007 Windows Server 0 09-05-2008 11:08 AM
Logon to Citrix/RDP with smartcards Dennis van Leur Active Directory 0 01-25-2007 11:56 AM
Expired Certificates Hans Stope Windows Server 3 06-29-2005 09:41 PM
Expired Certificates Tech LA Server Security 3 04-26-2005 02:20 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59