19 January 2017

Install the Microsoft Exchange 2013 Management Tools prerequisites on Windows 10 with PowerShell

Install the Microsoft Exchange 2013 Management Tools prerequisites on Windows 10:

Enable-WindowsOptionalFeature -Online -FeatureName IIS-WebServerRole
Enable-WindowsOptionalFeature -Online -FeatureName IIS-WebServerManagementTools
Enable-WindowsOptionalFeature -Online -FeatureName IIS-IIS6ManagementCompatibility
Enable-WindowsOptionalFeature -Online -FeatureName IIS-Metabase
Enable-WindowsOptionalFeature -Online -FeatureName IIS-LegacySnapIn
.NET 3.5:
Write-Host "Installing .Net Framework 3.5, do not close this prompt..."
DISM /Online /Enable-Feature /FeatureName:NetFx3 /All /LimitAccess /Source:$LocalSource | Out-Null
$Result = Dism /online /Get-featureinfo /featurename:NetFx3
If($Result -contains "State : Enabled")
Write-Host "Install .Net Framework 3.5 successfully."
Write-Host "Failed to install Install .Net Framework 3.5,please make sure the local source is correct." 
In case the above doesn't work, you can try:
DISM /Online /Enable-Feature /FeatureName:NetFx3

10 January 2017

Cleaning up the CA database after renewing your Issuing-CA certificate

After renewing your Issuing-CA certificate it's important to clean up your CA internal database.
It can grow quite large, depending on the number of issued certificates of course, but still to keep it as clean and clear as possible works a lot quicker and reduces the chance of errors.

So to clean the CA database we use Certutil.

Clean up the Failed and Pending requests from before 31 January 2016:
Certutil -Deleterow 31/12/2016 Request

Mind the date notation, this might be different on your system, since i'm in the Netherlands the notation is dd/mm/yyyy, for US it's mm/dd/yyyy.

Clean up the Expired and revoked certificates from before 31 January 2016
Certutil -Deleterow 31/12/2016 Cert

This may take some time as it goes thru all certificates and adds them to the CRL.

05 January 2017

AIA and CDP Variable Definitions - What does the % sign stand for

AIA and CDP Variable Definitions


The CA computer’s Domain Name System (DNS) name


The CA computer’s NetBIOS name
CA Name
The CA’s logical name

The name of the CA’s certificate file

Domain DN
Not used in the Windows Server 2003 PKI

The Lightweight Directory Access Protocol (LDAP) path of the forest’s configuration naming context for the forest

The CA’s “sanitized” name

The CRL’s renewal extension

Indicates whether delta CRLs are supported by the CA

Indicates that the object is a CDP object in AD DS

Indicates that the object is a CA certificate object in AD DS