• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 863
  • Last Modified:

certificate issue when running dcpromo

A number of months ago i added a new Windows 2008 domain controller to an existing Windows 2003 domain, (the domain consists of only 1 windows 2003 DC) everything went fine, i transferred FSMO roles / GC and was prepared to dcpromo the windows 2003 DC, at the time i was having issues with printers and decided to keep the old win 2003 dc as a print server until i resolved all driver issues,

i would now like to dcpromo teh win 2003 dc, i'm getting the following message "before you can install or remove active directory you must remove certificate services", looking at issued certificates i can only see a domain controller certificate for the win 2003 and new win 2008 dc that are still valid

do i need to migrate these certs, what are the domain controllers certs providing to AD, is a migration supported when a different dc name,
3 Solutions
If you don't have configured your enviornment to require SSL when connecting to domain controller then you might be able to uninstall the services.

I suggest you backup the certificate services, uninstall, rename the server and promote as DC so if in case you need to bulid the CA again you can build new server with old name and restore CA from backup. This link shows how to move CA to new server http://support.microsoft.com/kb/298138
Krzysztof PytkoSenior Active Directory EngineerCommented:
When you install CA role on Domain Controller you cannot decommission it until you will not remove CA. That's why it is not recommended doing DC your CA server :)
You may see similar thread at Technet

Just do CA backup, remove it from DC. Decommission DC and set up it again as on domain member server. Should work fine

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now