Article ID: 2531138 - View products that this article applies to.
Consider the following scenario:
Log Name: System
Additionally, if you have these enrolled certificates automatically published to Active Directory, the size of the Active Directory database will increase significantly because of the constant re-enrollment of the certificate. And, the Active Directory replication may pause and report the following Warning event:
Event Type: Warning
The underlying cause of this behavior is related to the RDS component and to a mismatch within the certificate template. Specifically, if the template name and template display name are different, the RDS service does not match the existing certificate to the template, and the RDS service periodically enrolls a new certificate.
To resolve this problem, you must set the certificate template's attribute's template display name and template name to the same value, such as RemoteDesktopComputer. This procedure is suggested in the following Microsoft TechNet article:
Then, you must update the GPO setting Computer Configuration\Policies\Administrative Templates\Windows Components\Terminal Services\Terminal Server\Security\Server Authentication Certificate Template based on the new template name, such as RemoteDesktopComputer. After the server receives the new GPO setting during the processing of the background GPO redraw, the certificates are no longer renewed on a twice-daily basis.
Important: You must set the certificate template’s attributes Template Display Name and Template Name to the same value.
Article ID: 2531138 - Last Review: October 19, 2011 - Revision: 4.2