Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 64 Source: Microsoft-Windows-CertificateServicesCli

Level
Description
Certificate for local system with Thumbprint <thumbprint> is about to expire or already expired.
Comments
 
If you are a www.eventid.net subscriber you can download a utility that we developed that can identify the certificate using its thumbprint (as recorded in the event description). See the Downloads link below for more information.
This was caused by an expired code signing certificate. We used the Certificates MMC snap-in to identify the problem certificate (check Properties, Thumbprint - it should match the one in the event description) and then delete it from the same interface.
According to T774595, this can be fixed by renewing the CA certificate. The article provide information on how to do this.
From a support forum:
1) Determine what is the certificate template that is nearing expiration
2) Check the permissions on the certificate template to ensure that a group containing the computer account is assigned the Read, Enroll, and Autoenroll permissions
3) Ensure that the certificate template is available for enrollment by being included in the Certificate Templates container of an enterprise issuing CA running on Enterprise Edition of either Windows Server 2003 or Windows Server 2008
From a support forum:
If the certificate is expired, you can use remove-exchangecertificate command to remove them from the certificate store on the exchange server (see TA997569)

To disable the cetificate on services, you can use: Enable-ExchangeCertificate -services None

See TA997231 for details.


Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...