Forum Discussion

ben_2's avatar
ben_2
Tin Contributor
Aug 04, 2026

Removal of old CA server stale data

Hi,

 

I'm rebuilding some DC's and figured I'd tidy everything up before doing so as I've come into this with a messy environment. from this, I found an old Trusted Root CA, the certificate authority server was decommissioned in 2021 and all certificates have had an expiry date from 2021. its still being pushed out to domain devices such as servers and desktops. I tried running the 'certutil -dsdelca' command however this comes back with invalid command. 

I guess the best option is just to remove the class objects from the ADSI edit?

as there is a class in AIA, CDP, Certification Authorities, KRA with the certificate name

 

 

No RepliesBe the first to reply