Solved

upgrading Server 2003 to Server 2008 R2

Posted on 2011-02-15
5
322 Views
Last Modified: 2012-05-11
We are switching our servers to 2008 R2 and I need to move the certificates from a 2003 32-bit server to a 2008 R2 64-bit server.  I am actually building a new 2008 R2 DC and I was planning on moving the certs to that and decommissioning the 2003 DC.  What is the best way to go about doing this?

Thanks,
Jon
0
Comment
Question by:Tim Lewis
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
5 Comments
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 34898806
0
 
LVL 10

Expert Comment

by:kgreeneit
ID: 34898844
Hi there the best way to do this would be as follows:

build your 2008 R2 dc

update the AD schema as required

install Certificate Services on the 2008 R2 DC

export all of the relevant certificates from the Windows 2003 server ensuring you export the 'Private Key' with them

Import these certificates into the new Windows 2008 R2 DC's CA store

Uninstall the CA from the Windows 2003 DC

Backup any important files on the Windows 2003 DC

DCPROMO the Windows 2003 DC to remove it from the domain as a DC

Remove the old Windows 2003 DC from the domain

Power down the old Windows 2003 DC

This should do the job for you then!
0
 

Author Comment

by:Tim Lewis
ID: 34910209
We moved the CA but now it is not handing out certificates.  Please help.

Thanks,
Jon
0
 

Accepted Solution

by:
Tim Lewis earned 0 total points
ID: 34917235
found solution:


Paranormastic:
Confirm that the domain controllers group for this domain is a member of the CERTSRV_DCOM_ACCESS group - this is a local group on the CA server unless the CA is on a DC, then is an AD group.

Run these, in order:
certutil -dcinfo deletebad
certutil -pulse
gpupdate /force

Reboot the DC.

If still giving you problems look into DNS and firewall issues.
0
 

Author Closing Comment

by:Tim Lewis
ID: 34949695
found answer
0

Featured Post

Online Training Solution

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action. Forget about retraining and skyrocket knowledge retention rates.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
A procedure for exporting installed hotfix details of remote computers using powershell
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Suggested Courses

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question