Certificates on DCs being updated too frequently impacting LDAP lookups from other service

T

Tim Cooke UK

We've got an issue with one of our services (VPN) that uses LDAP lookups to DCs. That system has the thumbprints of the DC certificates on it that require updating whenever the certificates on the DC renew. Certificates have a two year expiry on them, but are getting renewed much more frequently and therefore causing issues with service availability, especially if they renew on multiple DCs at the same time, in part because we are restricted on when we can push policies on the firewall for the VPN.We've not been able to identify what might be causing the certificates to be renewed so frequentl

Continue reading...
 
Back
Top Bottom