Several Enterprise Certification Authority queries
Posted on 2008-06-11
I have 2 Enterprise CAs running on my domain however I'm uncertain which of these is the Root and which is the Subordinate. How can determine this?
Secondly, I'm wanting to create a new Enterprise Root CA on a different server to take over from from my current Root CA (once I find out which one it is). The new CA host will have a different name to the old one. Additionally, the old box will continue to act as a server once CA services are removed i.e. it's not being decommissioned.
I've read the MS article detailing how to migrate a CA to a box with the same name, but this does not apply in my case.
Any advice on how to proceed would be appreciated.
Finally, if I kick-off the CA services installation wizard on the server I intend to be the new Root CA I have to option to choose to create <either> a Root CA or Subordinate CA - I was expecting the former option to be greyed out, as a Root CA already exists on my network. I haven't taken the wizard any further as I want to be better aware of the implications. I've since read confilcting information on the web as to whether multiple Root CAs can exist in the same domain.
Can someone clarify?