Deleting Archived Certificates from Users' My store on Workstations

B

BillL

Hi,

We have a piece of software that only checks for the existence of a
certificate not whether it has been revoked or not. For this reason
we would like to remove all of the archived certificates from the user
My Store on workstations in the environment. The certs all had
encryption set as a purpose so they have been archived and not
deleted.

I know that I can use a "certutil -delstore -user MY 999999999999999"
command to remove individual certificates but I'm looking for a way to
manage this across 5000 workstations. Is there an easy way that I am
missing?

Thanks,
Bill
 
B

Brian Komar \(MVP\)

ummmm, do you have any encrypted data on those 5000 workstations.
You goal appears to be to get 5000 angry users calling you that they can no
longer open their encrypted files/emails from a few years ago.
Brian

"BillL" <wlawn@yahoo.com> wrote in message
news:731094ef-2176-4dd4-99cd-acf81e553818@c58g2000hsc.googlegroups.com...
> Hi,
>
> We have a piece of software that only checks for the existence of a
> certificate not whether it has been revoked or not. For this reason
> we would like to remove all of the archived certificates from the user
> My Store on workstations in the environment. The certs all had
> encryption set as a purpose so they have been archived and not
> deleted.
>
> I know that I can use a "certutil -delstore -user MY 999999999999999"
> command to remove individual certificates but I'm looking for a way to
> manage this across 5000 workstations. Is there an easy way that I am
> missing?
>
> Thanks,
> Bill
 
D

David H. Lipman

From: "BillL" <wlawn@yahoo.com>

| Hi,

| We have a piece of software that only checks for the existence of a
| certificate not whether it has been revoked or not. For this reason
| we would like to remove all of the archived certificates from the user
| My Store on workstations in the environment. The certs all had
| encryption set as a purpose so they have been archived and not
| deleted.

| I know that I can use a "certutil -delstore -user MY 999999999999999"
| command to remove individual certificates but I'm looking for a way to
| manage this across 5000 workstations. Is there an easy way that I am
| missing?

| Thanks,
| Bill

Look into Tumbleweed.
http://www.tumbleweed.com/solutions/identity_validation.html

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
 
Back
Top Bottom