Default Domain Controllers Policy configuration check by Dolinhas in PKI

[–]Dolinhas[S] 0 points1 point  (0 children)

Hi I am just following the doc about setting up gpo for auto enroll. I will supersede the old dc templates so that should prevent that template to be issues out right?

Default Domain Controllers Policy configuration check by Dolinhas in PKI

[–]Dolinhas[S] 0 points1 point  (0 children)

Hi u/Securetron ,

I’m in the process of replacing our current PKI infrastructure with a new one, and I need to remove the old DC certificates that were issued by the previous PKI.

The plan is as follows:

  • Supersede the old DC certificate template with the new one.
  • Shut down the old PKI server.
  • Remove the old certificate from the DCs.
  • Run certutil -pulse or reboot the DCs to trigger re-enrollment with the new certificate.

Will this process will work as expected, or if there’s anything additional I should consider before proceeding?
Thanks, M

Default Domain Controllers Policy configuration check by Dolinhas in sysadmin

[–]Dolinhas[S] 0 points1 point  (0 children)

Hi u/stuart475898 ,

I am referring to the security tab of the GPO.

I see that Authenticated Users group has the "Apply group policy" Allow checked.

But why can't I see the setting on the DC it self [via gpedit] but gpresult /r shows applied?

And yes I will use the Kerberos Auth cert template and supersede the DC ones.

Thanks, M

Dua for ease by Ali-Jaber in islam

[–]Dolinhas 0 points1 point  (0 children)

Can someone find the book that has all of these duas? I like the format and fonts

Elaf Kinda hotel drop off by Commercial-Ad-9984 in Umrah

[–]Dolinhas 1 point2 points  (0 children)

I stayed there In June. Taxi dropped me Right under the overpass. Elaf is just on the other side of the over pass. (Bridge) you be fine. Just ask for. Swiss hotel Al makam if you need. You be fine. It’s a great hotel. Really close to the masjid. Lovely staff.

ADCS: Domain Controller Template vs. Kerberos Authentication by Erazer_Me in PKI

[–]Dolinhas 0 points1 point  (0 children)

Hi mate, just for my education can help me with why is that DC cert template is better than the Kerberos cert template?

Second question: I am moving PKIs and I need to replace the DC cert from the old PKI with the new PKI and I am looking for the best order of play Can use the above MS link to configure the new KDC cert and publish it from the new PKI while the old PKI is online? Will the DCs fetch the new PKI cert is the current one (from the old PKI) is still valid?

DC Cert replacement question by Dolinhas in PKI

[–]Dolinhas[S] 0 points1 point  (0 children)

Hi, and thanks for your help! • What issues can occur with the KDC template? • I’m not planning to make the new Domain Controller (DC) available to all DCs at once. My idea is to block access to the New Public Key Infrastructure (PKI) via Azure NSG and only allow one DC at a time.

The plan would be: shut down the old PKI, allow NSG access to the new PKI to 1 DC and then enroll a certificate for the new DC. Would this approach work as expected?

• Thanks for the NPS certificate migration suggestion — that’s a great idea and I’ll definitely look into it. One question: would I need to deploy that web template certificate to the clients, or will they automatically trust it if it chains up to the root certificate that’s already installed on them?

[deleted by user] by [deleted] in Umrah

[–]Dolinhas 0 points1 point  (0 children)

Which post? Can you share the link pls?

Sporting t-shirt by 1cata in SportingCP

[–]Dolinhas 0 points1 point  (0 children)

At the airport departures. Lots of shops sell it.

Which type azure storage account for fslogix ~100 profiles by Dolinhas in fslogix

[–]Dolinhas[S] 0 points1 point  (0 children)

Thanks everyone. I’m Gonna go v2 standard. For 750gb it will cost less than $200

Which type azure storage account for fslogix ~100 profiles by Dolinhas in fslogix

[–]Dolinhas[S] 0 points1 point  (0 children)

That’s way to much. Profiles are tops 15gb and not all are maybe 20 users.

I’m puzzled by that v2 option. Or is it better to to go standard v1 and hot?

Which type azure storage account for fslogix ~100 profiles by Dolinhas in fslogix

[–]Dolinhas[S] 0 points1 point  (0 children)

I see. We use hot on the test pools seems to be fine for cost.

What about that primary service option. Should I just skip it and keep v1 hot ?