How do I move Certificate Authority from a 2003 DC to a replacement 2008 DC?

Posted on 2008-11-20
Last Modified: 2012-05-05
We are looking to replace our Existing DC, running Server 2003 R2 STD, with a new server running 2008 STD.

I have found the procedure for moving from one 2003 DC to another (here: but will this work when moving to Server 2008?
Question by:hainsworth
    LVL 10

    Expert Comment

    Hi Hainsworth,

    Provide URL is useful for the W2k3 to W2k3.
    FYI In Microsoft technet provided the details about the Backing up and restoring a certification authority. ( It will helpful for your migration.

    Let me know it works for you :)

    Abdul Hakim

    Author Comment

    But can I move directly from 2003 to 2008 or would i have to temporarily upgrade the original server first?
    LVL 10

    Accepted Solution

    for more information regarding move CA W2k3 to W2k8 CA
    Step by Step details in MS technet:

    Abdul Hakim T

    Author Comment

    Oh ok, sorry i jumped in very quick then... So I'll need to upgrade, thanks.

    Expert Comment

    Does this work if I am migrating from a 32-bit 2003 CA to 2008 R2? (Being that it's 32-bit to x64.)

    Thanks for your advice!
    LVL 31

    Expert Comment

    You cannot upgrade from 32 to 64 bit - it just isn't allowed and won't work.  My advice is install a new CA on the 64 bit and start reissuing certs from that, when you are done then decom the old CA from AD.

    How to decom a CA server properly from AD:

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    What Security Threats Are You Missing?

    Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

    You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
    ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
    This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
    This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

    759 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    9 Experts available now in Live!

    Get 1:1 Help Now