Certificate Authority

Find CA Server

 In AD find the Members of the "Cert Publishers" group

Determine CA Type


Log on to the CA Server and open a command prompt

certutil -dump
Config: 'server.blah.com\blah.com'

based on the output of that command build the next command

certutil -cainfo -config $CONFIG type

certutil -cainfo -config server.blah.com\blah.com type

Uninstall CA

  1. Stop CA service on certificate server and observe the behavior (events, failures on DCs, clients).
  2. If CA service is left started, keep a check on Issued Certificates container on CA server, observe if any additional certificates are issued.


