?
Solved

2003 AD - lots of CAs but none are running can I delete?

Posted on 2011-03-24
2
Medium Priority
?
379 Views
Last Modified: 2012-05-11
Hello!


2003 functional domain.   there are like 10 CA servers listed in sites and services.  None of those servers exist any longer.  Can I just delete them all?  I found this:

http://support.microsoft.com/kb/889250

Can I just follow this, blow out all the CAs and have none?
0
Comment
Question by:BBQSTEAK
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 49

Accepted Solution

by:
Akhater earned 1600 total points
ID: 35211309
if the CAs doesn't exist anymore and none of the certificates they have once issues are still in use then yes you can delete them wihtout issue
0
 
LVL 13

Assisted Solution

by:Kini pradeep
Kini pradeep earned 400 total points
ID: 35213811
we had a similar problem, with our domain. when I took over the setup we had three certificate authorities setup by three of the past administrator, each CA as a standalone enterprise CA.

We deleted all of them and came across a problem, the CA is not necessary as long as the certificate is valid, the problem occurs when it expires and comes for a renewal. I would recommend the following option if possible.

1. Backup the Certificate authority & its private keys.
http://support.microsoft.com/kb/298138

2. If you use a virtualization in your environment ( Vmware/ hyper-v etc) convert the CA from Physical-virtual and shutdown the virtual machines. if need you can always start them again -- second option being the most easiest
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you troubleshoot Outlook for clients, you may want to know a bit more about the OST file before doing your next job. IMAP can cause a lot of drama if removed in the accounts without backing up.
New style of hardware planning for Microsoft Exchange server.
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Suggested Courses
Course of the Month9 days, 10 hours left to enroll

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question