Jump to content

Recommended Posts

Posted (edited)

I'm after some advice from anyone with experience of moving the Certificate Authority in Windows Server to a new server, as I'm about to do so on my network.

 

Right now I am most of the way through scrapping our RM CC3 system in favour of a vanilla Server 2008 R2/Windows 7 system. The time has almost come to switch off the last RM server; the last two things I need to do are to transfer the Operations Master role (which seems easy peasy) and the slightly more daunting task of moving the Certificate Authority.

 

I've read this quick guide as well as the not so quick Active Directory Certificate Services Migration Guide on TechNet, which frankly makes the process seem more complicated than finding the Higgs boson.

 

An alternate option I have seen proposed is to set up a new CA and run it in parallel with the old one while I switch all the machines that currently use certificates to the new CA. Given that 99% of the existing certificates are computer auto-enrolment certificates, this doesn't seem like a bad idea.

 

Has anyone here done this before and can offer any words of wisdom?

Edited by AngryTechnician
Posted

I'm planning to nuke ours from orbit and rebuild/reimport existing certs into AD as trusted as a stopgap. It's on a DC that's also being decommissioned which makes it doubly annoying to work on. I also read those while I was researching and concluded it would be faster for me to just rebuild from scratch.

 

However, our only certs are for Wireless Auth, Radius for a couple of things and a handful of internal certs for things like EFS decryption. If you're using user certs as well, that may not be an option.

Posted
I think mine is used for even less than yours, since we have no wireless at present. Aside from a couple of internal web server and DC certificates, I don't think the computer certificates are even used for anything.
Posted
Having just setup a new CA (rather than reuse the existing one that I'd previously setup) for our SCCM install (gahhh!) I'd say that it's probably just easier to setup a new CA and issue new certificates manually for the few that may need that :)
Posted
Well, I've decided to go down the new CA route; have installed a new Enterprise CA into Active Directory this morning and am now going through removing computer certificates on the servers and allowing them to pick up a new one via auto-enrolment. Seems to be going fairly smoothly so far...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...