Solved

Certificates & Domain Controllers

Posted on 2004-08-06
1
239 Views
Last Modified: 2013-12-04
I'm currently trying to demote a DC that is running Certificate Services.

The CA has automatically issued certificates to all of our other domain controllers here at our primary office and at our remote sites, each of which have a DC.  The uses of the certs are listed as "Proves your identity to a remote computer" and "Ensures the identity of a remote computer."  In removing this CA from our network (and I will subsequently be recreating it on another DC), what effect would this have on those our domain (file replication, authentication, etc.)?

Additionally, what would I need to do to mitigate those potentially bad consequences?

The environment is a Windows 2000 Domain in Mixed Mode with an Enterprise CA.  Clients all W2k or XP.

Thanks!
0
Comment
Question by:titan6400
1 Comment
 
LVL 7

Accepted Solution

by:
msice earned 500 total points
ID: 11756000
Is the DC an Enterprise CA or a Enterprise Subordinate CA? If it is an Enterprise CA you should be able to save the certificates and reinstall on another server but you will then need to update the other subordinates to look at the new Enterprise CA as the trusted source of the new certs. You can have more than one Enterprise CA in a domain so you might want to add the new one before removing the old one, but I would do all of this in a test environment first if I were you.
This doc might help you:
http://www.microsoft.com/technet/prodtechnol/windows2000serv/howto/casetup.mspx 
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Security, hackers 10 128
default domain policy in AD exemptions 3 79
Removing local Admin rights from users 8 79
Sweet32 Vulnerability in Microsoft IIS7.5 6 945
Recently, a new law in my state forced us to get a top-to-bottom analysis of all of our contract client's networks. While we have documentation, it was spotty at best for some - and in any event it needed to be checked against reality. That was m…
Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

840 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question