Tag Archives: PKI

My PowerShell based certificate viewer

For some time now, I have been a little bit tired of certmgr.msc, the certificate management MMC-snap in. Not only by the fact that a user needs local administrator rights to be able to open it (because MMC itself needs … Continue reading

Posted in PKI, PowerShell Blogs | Tagged , , , | Leave a comment

Automated certificate management in ADFS using PowerShell

Now don’t get me wrong, I absolutely love ADFS. I think is a great way to enable single sign on and federated login on a per application basis using existing identities in your infrastructure. However, the only thing I don’t … Continue reading

Posted in PKI | Tagged , , , , , | 6 Comments

Some fun with the Public Key Services container and the ADCS wizard

Recently, I did an experiment of how well the ADCS wizard handles an administrator who “destroys” the Public Key Services container were ADCS and ADDS stores all PKI related information. I did many different tests and one of the was … Continue reading

Posted in PKI | Tagged , , | 1 Comment

CADCT – CA Decommission Tool

Have you ever wonder how­ to remove, uninstall or delete a specific CA from Active Directory in an easy way? Well, for some time now, I have been playing with a little PowerShell script I have created for easy decommission … Continue reading

Posted in PKI, PowerShell Blogs | Tagged , , , | 8 Comments

certutil–dsdel does not clean up completely

I have noticed that some people have tried to do a CA decommission with the dsdel option in certutil. However, there is just a little, little problem with it: it does not remove everything!   Now, what is wrong with … Continue reading

Posted in PKI | Tagged , , , | Leave a comment

The BitLocker certificate EKU and Windows Server 2008 R2

Today, I discovered something that kind of bothered me.   I enrolled a number certificates in my test environment and the BitLocker Drive Encryption EKU (1.3.6.1.4.1.311.67.1.1) was one of the EKU’s present in the certificates. I looked at one of … Continue reading

Posted in PKI | Tagged , , | Leave a comment

PKI cleanup in AD with PS

Yesterday I created this little script and I wanted to share it with you guys. Now that PKI View is removed from KB889250, some people has asked me how to remove all references to old PKI structures in Active Directory … Continue reading

Posted in PKI | Tagged , , , | 5 Comments

Network Access Protection – How to do it, step by step…

One of my favorite Microsoft documents is “Demonstrate NAP 802.1X Enforcement in a Test Lab”. Many people usually ask me how NAP works and it is always nice to be able to give a document as a reference when you … Continue reading

Posted in News | Tagged , | Leave a comment

PKI View is no longer a supported way for CA decommission

Thanks to my post http://poweradmin.se/blog/2010/05/08/pkiview-msc-doesnt-say-the-entire-truth and the great, open and quick communication between myself and Microsoft, PKI View is no longer a part of KB889250, which is the step by step guide for CA decommission. I really salute Microsoft for … Continue reading

Posted in News, PKI, PowerShell Blogs | Tagged , , | 1 Comment

Pkiview.msc doesn't say the entire truth…

I guess I am not the only one that usually removes old PKI stuff from the Public Key Container in Active Directory with pkiview.msc.   However, recently I discovered something that kind of bothered me. I was working with a … Continue reading

Posted in News, PKI | Tagged , , | 4 Comments