Click here to get back home

Re: Expired SSL cert for LDAPS

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Re: Expired SSL cert for LDAPS Paul Bergson [MVP-DS] 06-14-2007
Posted by Paul Bergson [MVP-DS] on June 14, 2007, 1:24 pm
Please log in for more thread options
Best ask in the Security NG. I have copied them in.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

> We have MS Certificate Services installed in our domain and the domain
> controllers use Autoenrollment to obtain certificates and provide
> Secure LDAP on port 636. One of our DC's, the one running certificate
> services, is still presenting an expired certificate. It has a new
> valid one it it's certificate store, but when an SSL client connects
> to port 636, it's presented with the old cert. I assume the old cert
> is cached somehow and that a reboot will correct this. However, I'm
> wondering if there's another way to tell it to clear out that cache
> and start using the new, valid certificate? This is a Server 2003 box.
>



Posted by S. Pidgorny on June 16, 2007, 7:04 am
Please log in for more thread options
Reboot will indeed correct this. LSASS.exe is the process responsible for
LDAP and you need a reboot to restart it.


--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

> Best ask in the Security NG. I have copied them in.
>
> --
> Paul Bergson
> MVP - Directory Services
> MCT, MCSE, MCSA, Security+, BS CSci
> 2003, 2000 (Early Achiever), NT
>
> http://www.pbbergs.com
>
> Please no e-mails, any questions should be posted in the NewsGroup
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>
>> We have MS Certificate Services installed in our domain and the domain
>> controllers use Autoenrollment to obtain certificates and provide
>> Secure LDAP on port 636. One of our DC's, the one running certificate
>> services, is still presenting an expired certificate. It has a new
>> valid one it it's certificate store, but when an SSL client connects
>> to port 636, it's presented with the old cert. I assume the old cert
>> is cached somehow and that a reboot will correct this. However, I'm
>> wondering if there's another way to tell it to clear out that cache
>> and start using the new, valid certificate? This is a Server 2003 box.
>>
>
>



Similar ThreadsPosted
Expired Code Signing Cert with VBScript September 12, 2006, 9:17 am
2K3 Cert Svcs gives invalid policy error on OpenSSL gen'd cert req June 4, 2007, 1:56 pm
Requesting Code signing cert from cert services November 4, 2005, 12:11 pm
Setting up LDAPS July 11, 2007, 2:41 pm
Create certificate with makecert for LDAPS on a DC ? December 12, 2007, 5:17 am
Expired certificate October 1, 2007, 10:41 am
Urgent - Subordinate CA certificate expired April 2, 2007, 12:04 pm
IISADMPWD solution for AD expired password ? December 7, 2007, 10:30 am
Certification Authority root certificate seems to have expired early??? September 25, 2006, 4:40 pm
CA cert renew July 18, 2007, 9:07 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap