Solved

Migrate or Remove CA Services when decommissioning last 2003 DC

Posted on 2014-03-27
5
224 Views
Last Modified: 2014-04-02
We have two 2008 R2 DC's and one 2003 R2 DC.  I am ready to demote and remove the 2003 DC from the domain but can't perform a DCPROMO because CA services are installed.    When I open Certification Authority|Issued Certificates, there are only 3 Certs that haven't expired and the Requester Name is "Domain\DC$".  Even all of the expired Certs have the same Requester Name.  I also followed these steps to backup the CA info:

http://technet.microsoft.com/en-us/library/ee126140(v=ws.10).aspx#BKMK_BackUpDB
http://technet.microsoft.com/en-us/library/ee126140(v=ws.10).aspx#BKMK_BackUpReg

Based on this info, would it be better to migrate the CA to one of my 2008 DC's or just remove it?  Would this have any impact on Directory Services?

Thanks in advance,
0
Comment
Question by:RHNOC
  • 3
  • 2
5 Comments
 
LVL 10

Expert Comment

by:0xSaPx0
Comment Utility
First off, what are the certs used for? If you demote that server it can't be a CA anymore so you need to reissue them anyway.

If you don't use the certs for anything then its a non issue anyway.

Finally, It makes sense to move to 2008 CA Server anyway if you plan to issue certificates in the future as they will eventually expire.
0
 

Author Comment

by:RHNOC
Comment Utility
To be honest, i'm not sure what those Certs are for and that's why I posted this.  They appear to be automatically created by the DC's and new ones are issued for each DC when the old ones expire.

Migrating to the 2008 DC seems safer than removing the CA altogether but I also would rather not migrate something that isn't being used.  I was hoping with some help, to identify the purpose of these Certs and if migrating the CA was necessary.
0
 
LVL 10

Accepted Solution

by:
0xSaPx0 earned 500 total points
Comment Utility
Sounds like they are the auto generated root certificates created when you install certificate services. If you haven't generated any manual certificates and used them for SSL or other services you don't need these for anything.
0
 

Author Comment

by:RHNOC
Comment Utility
So if I wanted to proceed with removing the CA.  Since I have made the necessary backups required to migrate, I could uninstall the CA.  Wait a few days to see if there are any issues or fallout from it.  If so, just migrate it to one of the 2008 DC's right?
0
 
LVL 10

Expert Comment

by:0xSaPx0
Comment Utility
You could stop services and see. That said, most certificates once issued are no longer dependent on the root CA anyway.

For example if you issue a web server certificate you can disable the CA and not run into any issues until the certificate expires and you need to renew it. Even then it would only generate a browser warning saying its expired.
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

INTRODUCTION The purpose of this document is to demonstrate the Installation and configuration of the Data Protection Manager product. Note that this demonstration was prepared on the basis of Windows OS is 2008 R2 and DPM 2010. DATA PROTECTI…
Synchronize a new Active Directory domain with an existing Office 365 tenant
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now