Old KDC cert still used

Mel Perez 0 Reputation points
2026-09-28T14:53:36.12+00:00

2016 DC the old cert is still being presented for authentication. The new KDC cert is installed on all 2016 servers however only a few servers are using it. I did check the enumeration on the DCs that are affected and the older cert is listed as #1, while the newer KDC cert is listed as 3. Based on what I read the KDC cert works off this cryptoapi enumeration system using the #1 listed KDC cert above all the others, I have tried certutil-pulse, restarted the KDC service and rebooted the server- nothing has changed. Will this enumeration update without any user intervention when the old cert expires and start using the new cert?

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
0 comments No comments

2 answers

Sort by: Most helpful
  1. Mel Perez 0 Reputation points
    2026-09-28T15:32:28.2033333+00:00

    Thanks, Abinesh, but all this has been confirmed and compared, and it all checks out.

    Confirm both certificates are in Local Computer → Personal → Certificates.

    Verify the new certificate has the required private key.

    Compare EKUs, especially KDC Authentication / Server Authentication, depending on the certificate template being used.

    Check the Subject/SAN values and validity period.

    Verify the certificate chain and revocation status.

    Confirm the new certificate was issued from the intended domain-controller/Kerberos certificate template.

    Also compare the old and new certificate's EKU, SAN, Key Usage, validity dates, and private-key presence.

    When running certutil -dcinfo this also checks out as well

    Both certs are using the same template/subject/issuer.

    Cert Hash is also generated on each one.

    Appreciate the feedback.

    Was this answer helpful?

    0 comments No comments

  2. Abinesh Magudeeswaran 230 Reputation points Student Ambassador
    2026-09-28T15:05:16.2666667+00:00

    Hello Mel,

    The fact that the newer KDC certificate is installed but appears lower in the enumeration does not by itself mean that the KDC will permanently continue using the older certificate.

    However, I would not rely on the old certificate simply expiring as the mechanism for switching to the new certificate. The KDC needs a valid certificate that meets the requirements for domain controller/Kerberos authentication, and Windows certificate selection is based on the certificates available in the computer certificate store and their properties. Microsoft documents multiple certificate types that can be used by a domain controller for KDC authentication.

    Since you have already restarted KDC and rebooted the affected DCs, I would compare the old and new certificates rather than focusing only on their enumeration numbers:

    Confirm both certificates are in Local Computer → Personal → Certificates.

    Verify the new certificate has the required private key.

    Compare EKUs, especially KDC Authentication / Server Authentication, depending on the certificate template being used.

    Check the Subject/SAN values and validity period.

    Verify the certificate chain and revocation status.

    Confirm the new certificate was issued from the intended domain-controller/Kerberos certificate template.

    You can use certutil to inspect the certificates and verify their properties/chains; Microsoft documents certutil as a tool for viewing and verifying certificates and their chains.

    I would also avoid manually changing or deleting certificate-store entries just to force the enumeration order. First determine why the newer certificate is not being selected.

    If you can provide the output of the following from one affected DC (with names/identifiers redacted), it would help identify the selection issue:

    certutil -store My
    certutil -dcinfo
    

    Also compare the old and new certificate's EKU, SAN, Key Usage, validity dates, and private-key presence.

    So, in short: the new certificate should become usable when it satisfies the KDC certificate-selection requirements, but I would not treat expiration of the old certificate as a guaranteed or recommended way to trigger the change. The safer approach is to establish why the new certificate is currently not being selected before the old one expires.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.