Solved

2003 AD - lots of CAs but none are running can I delete?

Posted on 2011-03-24
2
373 Views
Last Modified: 2012-05-11
Hello!


2003 functional domain.   there are like 10 CA servers listed in sites and services.  None of those servers exist any longer.  Can I just delete them all?  I found this:

http://support.microsoft.com/kb/889250

Can I just follow this, blow out all the CAs and have none?
0
Comment
Question by:BBQSTEAK
2 Comments
 
LVL 49

Accepted Solution

by:
Akhater earned 400 total points
ID: 35211309
if the CAs doesn't exist anymore and none of the certificates they have once issues are still in use then yes you can delete them wihtout issue
0
 
LVL 13

Assisted Solution

by:Kini pradeep
Kini pradeep earned 100 total points
ID: 35213811
we had a similar problem, with our domain. when I took over the setup we had three certificate authorities setup by three of the past administrator, each CA as a standalone enterprise CA.

We deleted all of them and came across a problem, the CA is not necessary as long as the certificate is valid, the problem occurs when it expires and comes for a renewal. I would recommend the following option if possible.

1. Backup the Certificate authority & its private keys.
http://support.microsoft.com/kb/298138

2. If you use a virtualization in your environment ( Vmware/ hyper-v etc) convert the CA from Physical-virtual and shutdown the virtual machines. if need you can always start them again -- second option being the most easiest
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
Read this checklist to learn more about the 15 things you should never include in an email signature.
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now