Domain Controller Certificate Expired
Restart the domain controller.
Domain controller certificate expired. This is one of the few cases where windows will auto enroll for a certificate without auto. For a fully automated renewal of certificates you should distribute. The domain controller certificate has expired. See the following section to learn how to renew certificates only if the existing certificate is about to expire.
Hard coded in this case means it is in the code it is not configured in any local or domain based policy. Domain controller certificates are only issued with the correct request password. All domain controllers are hard coded to automatically enroll for a certificate based on the domain controller template if it is available for enrollment at a certificate authority in the forest. In the certificate properties dialog box the intended purpose displayed is server authentication.
A new certificate should exist in the personal store. This certificate is issued to the computer s fully qualified host name. If your valid domain controller certificate has expired you may renew the domain controller certificate but this process is more complex and typically more difficult than if you request a new domain controller certificate. The above command requests a new dc certificate whether or not there already is a valid certificate.