new certification authority

Posted on 2009-12-22
Last Modified: 2012-05-08
I need to move our CA from an old 2003 server to a new 2008 server.  i read the articles saying i need to move the ca to a new 03 server then upgrade to 08.  the new server, will also have a new name.  is there any easy way to do this?  without having to build a new server with the same name then run ridiculous, time consuming upgrades?
Question by:jhaff
    LVL 13

    Expert Comment


    Author Comment

    i've also read articles about AD and DC cleanup, if i am moving the CA (not destroying it) do i need to go through the AD and DC cleanup?
    LVL 31

    Accepted Solution

    If you need to rename the CA then you will need to reissue the CA cert.  Although there are ways of doing this, it generally isn't worth it.  My advice is to set up the new CA and start migrating to it gracefully - you can have more than one CA in AD just fine.  Once you're all set, then decom the old box.  If you need to reclaim or get rid of the hardware, post back and I can show you a couple tricks to maintain the old certificates while migrating to the new box (but not issue from the old one).  If you need advice on setting up your new PKI I have a couple articles you can find from my profile.

    If you were planning on going from 32 to 64 bit also, that just doesn't work.  If 32 to 32 or 64 to 64 then that could work if you keep the same keyset and such.

    How to decom a CA server properly from AD:
    LVL 31

    Assisted Solution

    If you do just go through and move it, you need to keep the names the same and then do the upgrade, yes.  No, you don't need to do the cleanup - that would be a bad thing since it would be valid...
    LVL 24

    Expert Comment


    Featured Post

    Do You Know the 4 Main Threat Actor Types?

    Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

    Join & Write a Comment

    Learn about cloud computing and its benefits for small business owners.
    ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
    This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
    This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…

    734 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    22 Experts available now in Live!

    Get 1:1 Help Now