Configure root certificate clean up

This policy setting allows you to manage the clean up behavior of root certificates. If you enable this policy setting then root certificate cleanup will occur according to the option selected. If you disable or do not configure this setting then root certificate clean up will occur on log off.

Supported on: At least Windows Vista

Root certificate clean up options


  1. No cleanup
    Registry HiveHKEY_LOCAL_MACHINE
    Registry PathSOFTWARE\Policies\Microsoft\Windows\CertProp
    Value NameRootCertificateCleanupOption
    Value TypeREG_DWORD
    Value0
  2. Clean up certificates on smart card removal
    Registry HiveHKEY_LOCAL_MACHINE
    Registry PathSOFTWARE\Policies\Microsoft\Windows\CertProp
    Value NameRootCertificateCleanupOption
    Value TypeREG_DWORD
    Value1
  3. Clean up certificates on log off
    Registry HiveHKEY_LOCAL_MACHINE
    Registry PathSOFTWARE\Policies\Microsoft\Windows\CertProp
    Value NameRootCertificateCleanupOption
    Value TypeREG_DWORD
    Value2


smartcard.admx

Administrative Templates (Computers)

Administrative Templates (Users)