+ Post New Thread
Results 1 to 3 of 3
Windows Thread, Windows CA in Technical; Hi We have a CA here and its our PDC as well. I know you cant export/import the CA unless ...
  1. #1

    ZeroHour's Avatar
    Join Date
    Dec 2005
    Location
    Edinburgh, Scotland
    Posts
    5,697
    Thank Post
    950
    Thanked 1,355 Times in 828 Posts
    Blog Entries
    1
    Rep Power
    451

    Windows CA

    Hi
    We have a CA here and its our PDC as well. I know you cant export/import the CA unless you keep the same server name but I was wondering if I created and set a new CA how would I ensure the clients get the new certificate other then rejoining them all?
    We dont actually use the cert/CA for much but I would like the clients to get a new cert when they boot ideally.

    Thoughts?

  2. #2
    azrael78's Avatar
    Join Date
    Sep 2007
    Location
    Devon
    Posts
    383
    Thank Post
    47
    Thanked 37 Times in 33 Posts
    Rep Power
    21
    Funny you mention this - I've had to move a CA before now.

    All you need do is export the certs you want to keep from the old CA (not the root cert) - put a new CA on another server.

    Have the new CA make a new root cert - then via Group Policies it (by default) will import root CA's, I think there's a setting somewhere that tells it where to import the master CA from - but right now I can't find it.

    Be sure to decomission (remove) your old CA though once your new CA is working okay - or better still... just switch your old CA off (if you can).

    Hope this helps - thanks for kicking FastHosts into line

    Az

  3. Thanks to azrael78 from:

    ZeroHour (16th July 2008)

  4. #3

    ZeroHour's Avatar
    Join Date
    Dec 2005
    Location
    Edinburgh, Scotland
    Posts
    5,697
    Thank Post
    950
    Thanked 1,355 Times in 828 Posts
    Blog Entries
    1
    Rep Power
    451
    Thanks we are finally almost at 100% restored now.

    We will be just switching off the old CA. When you made your new CA I take it you had a different server name?
    What happens to clients that have a cert issued from the old CA which you dont export?

SHARE:
+ Post New Thread

Similar Threads

  1. Install Windows Server 2003 admin pack on Windows Vista
    By FN-GM in forum Wiki Announcements
    Replies: 0
    Last Post: 27th March 2008, 04:19 PM
  2. Replies: 12
    Last Post: 22nd August 2007, 07:23 AM
  3. Server Core, Windows without Windows
    By simongrahamuk in forum Windows
    Replies: 7
    Last Post: 30th October 2006, 08:42 PM
  4. Windows Xp vs Windows Vista
    By tosca925 in forum Windows Vista
    Replies: 12
    Last Post: 3rd May 2006, 07:27 PM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •