Jump to content

Recommended Posts

Posted

We currently have AD Certificate services set up on our domain, but it is in a bit of a mess and we are getting a new wireless solution in a couple of weeks so I am trying to build one from scratch.

 

Old servers are 2008 R2 CERT1-MASTER (root, offline) and CERT1-ISSUING (intermediate, online)

 

New servers are 2016 CERT2-MASTER (root, offline) and CERT2-ISSUING (intermediate, online) plus perhaps CERT2-WEB (Distribution point)

 

My question is, how can I keep the existing setup online and working whilst gradually introducing the new one? I've read so many articles online but this is one subject area which totally blows my mind!

 

Don't need to worry about external services as we use GoDaddy or similar for such purposes, just going to be used internally to issue User/Computer certificates to authenticate for wireless.

Posted
Just remove all the certificate templates on your existing CA to prevent it serving any new certs, you can keep it running while you make sure everything is pulling from your new CA (Add required templates so it'll start issuing certs). Then once happy you can go through the process of remove the old CA completely.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...