Domain Rename CA Installed on the Domain Controller

Posted on 2006-04-10
Last Modified: 2008-02-01
Hi Experts,

I have to do a Domain Rename of a Windows 2003 Domain.
I have the Experiance and i did the before.

Now the Problem is that I have a Windows 2003 Domain Controller on which Stand Alone CA is Installed,
I have to retain the Certificates because its serving the VPN clients.

What is the best and safe procedure to go..???
How can i still retain the Certificates after the Domain Rename(I dont mind going the server down for a day).
I also have a few Windows 2003 member servers too.

Thanks in Advance for the suggessions.

Question by:r_naren22atyahoo
    LVL 2

    Expert Comment

    I dont think your certificates will ever work properly again, since the name of the server will have changed, and its hard-coded into the cert. If you had the foresight to just use the name without the domain in your CA, then your certs should be fine.

    you will need to back them up, how-to is listed here:

    LVL 12

    Author Comment


    I have this link that helps to move the CA to another server.

    I think there should be a work around, COZ there is a section on page 25 in Microsoft Domain Rename Documentation.
    They say we can manage to Retain the CA However it should be on the DC, but mine is on DC.

    LVL 12

    Author Comment

    >>>>They say we can manage to Retain the CA However it should NOT be on the DC,but mine is on DC.
    LVL 12

    Author Comment

    Problem Solved.

    Using this artical
    Backup the CA Configuration,
    Uninstall the CA,
    Do the Domain Rename,
    Install the CA,
    Restore the CA Configuration.

    Successfully Tested.

    LVL 12

    Author Comment

    It works for stand alone CA

    Accepted Solution

    Closed, 500 points refunded.
    The Experts Exchange
    Community Support Moderator of all Ages

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Highfive Gives IT Their Time Back

    Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

    So you have two Windows Servers and you have a directory/folder/files on one that you'd like to mirror to the other?  You don't really want to deal with DFS or a 3rd party solution like Doubletake. You can use Robocopy from the Windows Server 200…
    This may not be a text book method to resolve VSS backup issues but it seemed to have worked on few of the Windows 2003 servers we had issues while performing a Volume Shadow Copy backup. If you have issues while performing a shadow copy backup usin…
    It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
    This video is in connection to the article "The case of a missing mobile phone (". It will help one to understand clearly the steps to track a lost android phone.

    761 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    11 Experts available now in Live!

    Get 1:1 Help Now