Replacing a DC cert

33 views
Skip to first unread message

Mike Leone

unread,
Jul 16, 2026, 4:07:44 PMJul 16
to NTSysAdmin
So I'm sure this is as simple an answer as it appears, but I need to make sure.

I created a cert for a new DC, installed it, all looks good. Tested
LDAP and LDAPS, and that all passed. That's when I noticed that I had
misspelled one of the SANs on the certificate. LOL I have the FQDN as
a SAN, and just the short hostname. But I mispelled the short hostname
...

I should just be able to create a new CSR, with the right SAN, issue a
new cert (from our own CA, I mean). Then I can just add it to the DC
the usual way, "certreq -accpt "corrected named cert"?

The new cert will just replace the old one, and I can then go and
revoke it in my CA.


--

Mike. Leone, <mailto:tur...@mike-leone.com>

PGP Fingerprint: 0AA8 DC47 CB63 AE3F C739 6BF9 9AB4 1EF6 5AA5 BCDF
Photo Gallery: <http://www.flickr.com/photos/mikeleonephotos>

Sean Rector

unread,
Jul 16, 2026, 4:13:13 PMJul 16
to ntsys...@googlegroups.com
Done this many times. You're on the right track.



Sent with Proton Mail secure email.

On Thursday, July 16th, 2026 at 4:07 PM, Mike Leone
> --
> You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to ntsysadmin+...@googlegroups.com.
> To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/CAHBr%2B%2Bg2KCwhEi%3DDF74hvDD%3DXsX5Y_V8FS1f_V9Ks2AMnf8oCw%40mail.gmail.com.
>

Mike Leone

unread,
Jul 16, 2026, 8:02:44 PMJul 16
to ntsys...@googlegroups.com



Mike. Leone, <mailto:tur...@mike-leone.com>

PGP Fingerprint: 0AA8 DC47 CB63 AE3F C739 6BF9 9AB4 1EF6 5AA5 BCDF
Photo Gallery: <http://www.flickr.com/photos/mikeleonephotos>

On Thu, Jul 16, 2026 at 4:13 PM Sean Rector <sean...@gmail.com> wrote:
Done this many times. You're on the right track.


I decided to re-issue certs for all my DCs (5). This time I added a SAN to each cert, in the name of a DNS alias "ldap". Some applications seem to require a specific hostname for LDAP, instead of the MS method of going by AD domain  name. So now I can standardize on that salad for all applications, and as long as I keep the alias up to date with all the IP addresses of the DCs, and make sure all DC certs have that SAN, I should be good. Abstracting out the LDAP, as it were.

Reply all
Reply to author
Forward
0 new messages