Solved

Removing Certificate Services

Posted on 2004-08-25
2
362 Views
Last Modified: 2013-12-04
We currently have 2 Windows 2000 Domain controllers and a member server which runs Certificate Services (Enterprise Root CA).  

The certificate server is old and will be decommissioned.  We will eventually put a new server in place and use that for issuing certificates.  The only reason I think this Certificate server exists currently is for EFS, and there doesn't seem to be many users, if any at all who actually encrypt files.  My question is can I safely uninstall Certificate services from this server.

I realise we wouldn't have a valid recovery agent but that wouldn't be an issue if there aren't any users encrypting files.  The thing is both our Domain controllers have acquired a certificate from the certificate server and what I want to know is will uninstalling certificate services bring any detremental effects on the Domain controllers.  What process / procedure do I need to follow to uninstall certificate services?

I cannot find anything in Group policy to suggest certificates are being used except as a recovery agent.

0
Comment
Question by:p_tippett
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 34

Accepted Solution

by:
Dave_Dietz earned 250 total points
ID: 11899156
I don't believe that removing Certificate Services will cause any problem.

What I would suggest is backing up the CA Certificate and Private Key then set the service to disabled and stop it.

Watch for problems.

If there are none you shouldn't need to worry.

If you do finsd down the road that there is a problem you can install Certificate services and use the backed up Cert and Private Key for the CA so that it is effetively the original CA.

Dave Dietz
0
 

Author Comment

by:p_tippett
ID: 12049034
OK, but would you recommend revoking the DC certificates after backing up the CA Certificate and Private key (but before stopping the service)?

My theory is if I revoke the certificates and remove the EFS agent in the GPO then stop the service and then monitor I believe if there is no Cert server the DC's cannot obtain a certificate - does that sound reasonable?  Then I should be in a position to remove Cert services.  Presumably I wouldn't have any problems then installing Cert services on a different server in a few months???
0

Featured Post

Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Many companies are looking to get out of the datacenter business and to services like Microsoft Azure to provide Infrastructure as a Service (IaaS) solutions for legacy client server workloads, rather than continuing to make capital investments in h…
Since pre-biblical times, humans have sought ways to keep secrets, and share the secrets selectively.  This article explores the ways PHP can be used to hide and encrypt information.
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question