Guides
Hands-on guides for certificates on Windows servers and Microsoft PKI – with commands you can copy.
Find expiring certificates on Windows servers
Use PowerShell to find expiring certificates in the computer store – on one server or many – and work out which service uses them.
RDP certificates: check, replace and enroll from your own CA
Get rid of the warning that the identity of the remote computer cannot be verified: deploy RDP certificates from your own CA via Group Policy.
LDAPS certificates on domain controllers: check and renew
Which certificate does a domain controller use for LDAPS, when does it expire and how do you swap it without a reboot? Includes a PowerShell test for port 636.
Autoenrollment not renewing certificates? A checklist
Group Policy, template permissions, CA connectivity, event log: work out step by step why certificates are not renewed automatically.
Expired CRL: an emergency runbook for Microsoft PKI
Wi-Fi, VPN or logons failing because a CRL expired? How to publish a new CRL – including from the offline root – and prevent the next outage.