Solved

Enterprise Certificate Authority crashed

Posted on 2015-02-18
5
107 Views
Last Modified: 2015-03-03
i have a windows server 2008 Certificate server that crashed and need to know how to introduce an new cert server in the enterprise without causing any problems.  can this be done?
0
Comment
Question by:johnkesoglou
  • 2
  • 2
5 Comments
 
LVL 21

Accepted Solution

by:
Jakob Digranes earned 400 total points
ID: 40618352
0
 
LVL 45

Assisted Solution

by:Craig Beck
Craig Beck earned 100 total points
ID: 40618436
I'm assuming this was an Enterprise Root CA??

Do you want clients to be able to use their existing certs?  If so, you'll need to treat this as a DR exercise.
http://blogs.technet.com/b/pki/archive/2010/04/20/disaster-recovery-procedures-for-the-active-directory-certificate-services-adcs.aspx

If you don't mind having to reinstall certs everywhere (basically starting your PKI from scratch) just install a new CA, as Jakob said.
0
 

Author Comment

by:johnkesoglou
ID: 40621768
thank you guys.  my only concern is when i remove these objects from the AD schema will it create an issue before i stand up another cert server?

thanks
John
0
 
LVL 21

Expert Comment

by:Jakob Digranes
ID: 40623272
not at all..... When migrating from 32-bit Win2003 CA server to new 64-bit 2008/2012 I always have at least 2 different Enterprise CA servers in the domain. Absolutely no issues
0
 

Author Closing Comment

by:johnkesoglou
ID: 40642963
Thank you guys; the information was most helpful
0

Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I was asked if I could set up a fax machine so that incoming faxes were delivered to people's Exchange inboxes and so that they could send faxes from their desktops without needing to print the document first.  I knew it was possible but I had no id…
If you migrate a Terminal Server licenses server inside the 2008 server family, you can takte advantage of the build-in migration tool. If you like to migrate an older 2003 Server (and the installed client CALs) to a 2008 R2 server for example, you …
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question