Jump to content

Recommended Posts

Posted

Having inherited an old network, i'm removing the oldest DC running windows server 2008 R2! New 2016 DC's have already been setup and all dns/dhcp roles etc have been migrated.

 

However, I cannot DCPROMO the 2008 r2 server as it is running AD CS.

 

I'm aware that a direct migration of AD CS cannot happy from 2008 r2 to 2016 due to changes, however I've looked within Certification Authority on the server and the only certificates that haven't expired are those of the existing Domain controllers.

 

Whats the best way moving forward with this so i can demote the 2008 R2? Is there a best step by step guide link someone could supply please?

 

Do I assume it is safe to just remove/delete the CA from 2008 r2 and setup a new CA on the 2016 AD Server as the new root? There are a few certificate with usernames against them for BASIC EFS (EFS) but they have all got expired dates, and nothing else if using the certification authority.

 

Or is there a more preferred way/steps of doing this?

 

Thanks.

Posted (edited)

I’ve done this from 2016 to 2019 using a guide I found on PeteNetLve. I’m pretty sure it said the same procedure should work back to 2008R2. I’ll try and find the link to the PeteNetLive article when I’m back at my PC, but it’s probably searchable.

 

If memory serves, it’s basically backup the AD CS config using the built in backup option in the AD CS management MMC, export the certsvr regkey (something like HKLM System CurrentControlSet Services CertSvr). Modify the server name value in the .reg file to the name of the new CS server. Remove the role from the old server. Add the AD CS role to the new server, and restore from the backup. Stop the service, merge the .reg file and restart the service.

 

 

As I say this worked for me going from 2016 to 2019 and I’m pretty sure the article said it should be much the same process for 2008R2 as well.

 

I did this recently and haven’t seen any problems so far. It all seems to have worked.

Edited by MrLudwig
Posted
I’ve done this from 2016 to 2019 using a guide I found on PeteNetLve. I’m pretty sure it said the same procedure should work back to 2008R2. I’ll try and find the link to the PeteNetLive article when I’m back at my PC, but it’s probably searchable.

 

If memory serves, it’s basically backup the AD CS config using the built in backup option in the AD CS management MMC, export the certsvr regkey (something like HKLM System CurrentControlSet Services CertSvr). Modify the server name value in the .reg file to the name of the new CS server. Remove the role from the old server. Add the AD CS role to the new server, and restore from the backup. Stop the service, merge the .reg file and restart the service.

 

 

As I say this worked for me going from 2016 to 2019 and I’m pretty sure the article said it should be much the same process for 2008R2 as well.

 

I did this recently and haven’t seen any problems so far. It all seems to have worked.

Thank you - all seems to have gone ok!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...