pantscat Posted September 13, 2011 Posted September 13, 2011 I've recently noticed that there are two CA's on my network - one that my predecessor setup on a rather obscure server (which obviously was fantastically documented along the wealth of information that was left about everything else... ). Obviously I want to remove the older CA... but I notice that there are some certificates issued to my DCs using the "Domain Controller" certificate template. My question is this... what happens if I remove the old CA? Are these certificates of importance? or will my DCs just automatically sort themselves out? Or (!) will everything go horribly wrong? (Night becoming day, up is down, white is black, existence is nothingness... that sort of thing.) Cheers, Ant
SYNACK Posted September 13, 2011 Posted September 13, 2011 (edited) Long story short it is doable but a pain How to decommission a Windows enterprise certification authority and how to remove all related objects from Windows Server 2003 and from Windows Server 2000 plus: answers to above question: http://www.mombu.com/microsoft/security-crypto/t-questiosn-about-domain-controller-certificates-and-removing-them-815681.html Edited September 13, 2011 by SYNACK 1
pantscat Posted September 14, 2011 Author Posted September 14, 2011 Thanks Synack - that second link is just what I was looking for!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now