Deleting expired certificates in Trusted Root Certificate Authorities - Microsoft Q&A (2024)

Table of Contents
3 additional answers Your answer

Share via

Deleting expired certificates in Trusted Root Certificate Authorities - Microsoft Q&A (1)

Rifka Khairani 40Reputation points

2023-01-24T03:39:24.9966667+00:00

Hi, I have three expired certificates installed in the Trusted Root Certificate Authorities/Certificates:

  • utn-userfirst-object
  • addtrust external ca root
  • quovadis root certification authority

but those three certificates are part of Microsoft Trusted Root Program with NotBefore status (certificate status: [https://ccadb-public.secure.force.com/microsoft/IncludedCACertificateReportForMSFT). There are no applications that use those certificates.

My question: Are those certificates safe to be deleted?

Thank you

Windows Server

Windows Server

A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.

12,916 questions

Sign in to follow

0 commentsNo comments

0{count} votes

    Sign in to comment

    Accepted answer

    1. Deleting expired certificates in Trusted Root Certificate Authorities - Microsoft Q&A (2)

      Thameur-BOURBITA 32,831Reputation points

      2023-01-24T07:56:29.5233333+00:00

      Hi @Rifka Khairani

      If those expired certificates aren't revoked , they can still be used to validate anything signed before their expiration. If not you can delete them

      Please don't forget to mark helpful answer as accepted

      0 commentsNo comments

        Sign in to comment

      3 additional answers

      Sort by: Most helpful

      Most helpful Newest Oldest

      1. Deleting expired certificates in Trusted Root Certificate Authorities - Microsoft Q&A (3)

        Jermain Dettons 10Reputation points

        2023-08-09T10:48:37.89+00:00

        Elaborating the original question

        • WHAT IS THIS CERTIFICATE?
        • IF IT'S REVOKED THEN WHY IS IT IN THE TRUSTED ROOT CERTIFICATION AUTHORITIES?
        • MINE SHOWS THAT IT STILL HAS: TIME STAMPING, CODE SIGNING & SYSTEM FILE ENCRYPTION - PURPOSES

        So yea it sounds like this certificate is still active, SO AGAIN WHAT THE HELL IS IT?

        I think we get that expired certificates are for backwards compatibility, and while everyone seems to say "it can only effect anything before expiration date." Do we know this to be absolutely true?

        This Microsoft forum NEEDS to do a better job of informing the user instead of saying. uhhhh yea don't delete that or follow this link for information. THE URL SAYS "LEARN.MICROSOFT.COM so teach, by informing........

        1. Who it is
        2. what it is
        3. What it does
        4. Where it came from
        5. Whether it's malicious or not
        6. How to verify it is in-fact safe and needed

        THANK YOU!

        1. Deleting expired certificates in Trusted Root Certificate Authorities - Microsoft Q&A (4)

          Tomek Grabowski 31Reputation points

          2023-11-14T15:03:41.3766667+00:00

          Only sensible reply here. Shame nobody from MS cared to answer.

        Sign in to comment

      2. Deleting expired certificates in Trusted Root Certificate Authorities - Microsoft Q&A (5)

        Limitless Technology 44,221Reputation points

        2023-01-25T10:03:46.8566667+00:00

        Hello there,

        Once the certificate expires it is no longer valid. Therefore, once a certificate expires you can safely remove it from the CA database. The one exception to this is if have Key Archival configured on the CA. If you are archiving private keys, you may not want to remove expired CA certificates from the CA database.

        Note: Backup the CA including the database and log files prior to deleting any certificates from the database.

        For more information ,you can refer to the following link:

        https://learn.microsoft.com/en-us/archive/blogs/xdot509/operating-a-windows-pki-removing-expired-certificates-from-the-ca-database

        Following script for your reference: https://gallery.technet.microsoft.com/scriptcenter/Script-to-delete-expired-8fcfcf48

        Hope this resolves your Query !!

        --If the reply is helpful, please Upvote and Accept it as an answer--

        0 commentsNo comments

          Sign in to comment

        1. Deleting expired certificates in Trusted Root Certificate Authorities - Microsoft Q&A (6)

          Limitless Technology 44,221Reputation points

          2023-01-25T10:03:34.7866667+00:00

          Hello there,

          Once the certificate expires it is no longer valid. Therefore, once a certificate expires you can safely remove it from the CA database. The one exception to this is if have Key Archival configured on the CA. If you are archiving private keys, you may not want to remove expired CA certificates from the CA database.

          Note: Backup the CA including the database and log files prior to deleting any certificates from the database.

          For more information ,you can refer to the following link:

          https://learn.microsoft.com/en-us/archive/blogs/xdot509/operating-a-windows-pki-removing-expired-certificates-from-the-ca-database

          Following script for your reference: https://gallery.technet.microsoft.com/scriptcenter/Script-to-delete-expired-8fcfcf48

          Hope this resolves your Query !!

          --If the reply is helpful, please Upvote and Accept it as an answer--

          0 commentsNo comments

            Sign in to comment

          Sign in to answer

          Your answer

          Deleting expired certificates in Trusted Root Certificate Authorities - Microsoft Q&A (2024)
          Top Articles
          Stablecoin Mining Calculator - SBC Mining Calculator
          How to connect MetaMask by WalletConnect? | Izood
          Fat Hog Prices Today
          Autobell Car Wash Hickory Reviews
          How to Type German letters ä, ö, ü and the ß on your Keyboard
          Lenscrafters Westchester Mall
          Violent Night Showtimes Near Amc Fashion Valley 18
          William Spencer Funeral Home Portland Indiana
          Mycarolinas Login
          Evangeline Downs Racetrack Entries
          Athens Bucket List: 20 Best Things to Do in Athens, Greece
          Worcester On Craigslist
          Classic Lotto Payout Calculator
          سریال رویای شیرین جوانی قسمت 338
          Quest Beyondtrustcloud.com
          Directions To 401 East Chestnut Street Louisville Kentucky
          979-200-6466
          Keck Healthstream
          Persona 4 Golden Taotie Fusion Calculator
          Craigslist Appomattox Va
          Rural King Credit Card Minimum Credit Score
          Hdmovie2 Sbs
          Iroquois Amphitheater Louisville Ky Seating Chart
          Minnick Funeral Home West Point Nebraska
          About My Father Showtimes Near Copper Creek 9
          Happy Homebodies Breakup
          Horn Rank
          Craigs List Jonesboro Ar
          Violent Night Showtimes Near Johnstown Movieplex
          Villano Antillano Desnuda
          Enduring Word John 15
          Stockton (California) – Travel guide at Wikivoyage
          O'reilly's In Monroe Georgia
          How often should you visit your Barber?
          La Qua Brothers Funeral Home
          Lichen - 1.17.0 - Gemsbok! Antler Windchimes! Shoji Screens!
          How to Watch the X Trilogy Starring Mia Goth in Chronological Order
          The Blackening Showtimes Near Regal Edwards Santa Maria & Rpx
          Space Marine 2 Error Code 4: Connection Lost [Solved]
          Studio 22 Nashville Review
          Pinellas Fire Active Calls
          19 Best Seafood Restaurants in San Antonio - The Texas Tasty
          140000 Kilometers To Miles
          The Listings Project New York
          Other Places to Get Your Steps - Walk Cabarrus
          Shell Gas Stations Prices
          Truck Works Dothan Alabama
          Headlining Hip Hopper Crossword Clue
          Horseneck Beach State Reservation Water Temperature
          Ciara Rose Scalia-Hirschman
          2487872771
          Minecraft Enchantment Calculator - calculattor.com
          Latest Posts
          Article information

          Author: Geoffrey Lueilwitz

          Last Updated:

          Views: 6475

          Rating: 5 / 5 (80 voted)

          Reviews: 95% of readers found this page helpful

          Author information

          Name: Geoffrey Lueilwitz

          Birthday: 1997-03-23

          Address: 74183 Thomas Course, Port Micheal, OK 55446-1529

          Phone: +13408645881558

          Job: Global Representative

          Hobby: Sailing, Vehicle restoration, Rowing, Ghost hunting, Scrapbooking, Rugby, Board sports

          Introduction: My name is Geoffrey Lueilwitz, I am a zealous, encouraging, sparkling, enchanting, graceful, faithful, nice person who loves writing and wants to share my knowledge and understanding with you.