Help Properly moving Certificate Authority

Dwight Crane
Dwight Crane used Ask the Experts™
on
I have an AD Domain with 3 DCs  (2 running R2.. the 3rd I'm trying to remove not R2), 13 servers (Servers all running 2003, 1 Exchange 2003), 76 PCs (XP 32 & 64 Bit, 3 vistas), 3 Linux boxes.

DC 1& 2 I built have been running smooth, the 3rd I inherited and is about to die. Before it has completely died from Hardware failures, I have xfer all FSMO role to DC1 and removed the Printer server/DHCP/DNS to the other DCs.

I would like to remove DC3 from being a Domain controller, however it has Certificate Authority on it that needs to be removed before I can dcpromo it out of the AD. I am unfamiliar with CA and have some questions.

1) is a CA even really necessary to run a standard single domain?  As I look at the CA on DC3 I am not convinced it was properly setup and everything in the domain has been fine. If I look in the "Failed Requests" folder of the CA server, there are litterally 1000's of entries with status code of "The revocation function was unable to check revocation  because the revocation server was offlin" and Disposition Message of "error Verifying Request Signature or Signing Certificate".

If none of these have been processing and everything on the network seems to be running.. I come by back to the question... Is the CA Necessary?

If it is, what are the steps to remove this CA on the DC3 that is being decommissioned  and creating a proper one that works?
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
A CA is not a necessity for a multi DC domain, even although certain functionality only exists with it, so without CA, OSC, Exchange etc will have limited functionality, although selfsigned certs may suffice..

Certificate migration information:
http://technet.microsoft.com/en-us/library/cc722147(WS.10).aspx
IT Director
Commented:
Could I just remove Current CA and Create a new one on a different box?  Would this effect Exchange? If so, what do I have to do to the exchange to register with new CA?

That EFS link didn't really seem to pertain.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial