Jump to content

Recommended Posts

Posted

We currently have a single Enterprise Root CA, which is also a domain controller on our domain. We have one more domain controller, plus another one due to be setup. We're wanting to decommission this domain controller and would also like to remove the Certificate Authority at the same time.

 

Currently, all the CA appears to now be doing is issuing Domain Controller Authentication, Kerberos Authentication & Directory Email Replication certificates to all the domain controllers. It was also used for SCCM but we no longer have this in use. So those issued certificates should be save to ignore. All other certificates have expired.

 

I've found the following guide, but what I'm struggling to confirm is if this guide also covers any effects removing the only CA on a domain, from the domain. IE does this process have any affects on the function of the domain?

Decommission a Windows enterprise CA - Windows Server | Microsoft Learn

 

Has anyone done this process that can provide some feedback on how it went, tips etc.

 

Thanks,

Rob

Posted

Radius, VPN, internal SSL for intranet, server auth certificates…

Best thing to do is a rundown, server by server, of what you use. Look at the certs local store on each one via the cert management snap-in. You can even try deleting one (they’re easy enough to put back) to test the effects.

 

i imagine some schools have progressed enough that their CA does nothing now. I know if I turned ours off I’d quickly be up a creak with no propulsion.

Posted

Currently it's used for nothing (But AD it would seem, based on the templates / certificates still being issued).

 

The only thing we might use it for in the future would be Radius. However, ideally we want to support Entra ID only devices as well as domain devices, my understanding is NPS Radius doesn't support Entra ID (Only) devices. We currently use Smoothwall for our radius which doesn't support VLAN IDs, but does authenticate to AD. So it 'Kind of' works for what we need.

 

No VPN or internal services (Not covered by public certificates).

Posted

This gap is one of the reasons I don't see our DCs going anywhere soon.  We use our internal CA for code signing and device certs for NPS backed 802.1x.

 

There is a new Cloud CA offer from microsoft which if you are pure Intune can be used for 802.1x.. But not for any devices that are not intune managed (like say legacy on prem servers)... and you still need either on prem Radius (typically NPS) or a paid 3rd party product to actually do the authentication.

 

Its such a strange gap for them to have left, makes me wonder if  there are some influential customers who need there not to be  functional parity between Entra/Intune and on prem Server/AD/NPS etc.

 

 

Posted (edited)

a long long time ago when i can still remember.......   our Cert server sat on a DC that was bare metal and i wanted to get rid of... my Cert server is now a VM (started being called CERTSRV2016) now runs 2022  still called CERTSRV2016 i should have just called it certsrv or something like that... - i needed the certificates for wifi computers 802.1x radius atuh via NPS.... all i remember is i was super scared of decommission the DC and bringing the new Cert Authority online... i had worries about  DCs talking to each other etc... but everything went really smoothly i think from memory (9 years ago ish) i brought the new CA on did all the GP changes so it started issuing new certs to all the clients (computer certificates DC certs) and when we came to decommission the DC we had already moved the Wifi gpos relating 802.1x over to point to the new CA and everything just continued to work...

 

that is all we now use the CA for 802.1x computer certs for wifi and issuing internal certs for web servers but they are becoming less now that more and more services are cloud based... i think most of the internal certs are for our webmin management of Linux servers or our papercut for printer topup.

 

Now its not on a DC and separate its been in placed upgraded from 2016 to 19 to 22...  The guidance was always never install a CA on a DC but back in the day i didn't see it and ended up with that in play.. some of the info from memory about moving the CA instead of replacing it was to do with CRL which made it bad to move the CA off the DC... 

Edited by k-strider

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...