Active Directory Exchange Certificate

Hi experts exchange,

My name is Hoang, I have 2 question :

1. Can I convert the physical machine run MS exchange with AD certificate service to VMware ?

2. If I can convert it, how can I move the Active Directory certificate service to other AD Domain for demote ADDS on that Server ?

note: I user Window Server 2012 R2 to run ADDS , Window Server 2012 to run MS Exchange 2013 and ADDS

sorry because my English is bad,
Please help me, thank you so much.
Gohan2703Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

David Johnson, CD, MVPOwnerCommented:
the server that has Exchange doesn't need to be a Domain Controller.
Yes you can create a new VM or use an existing VM and add ADDS (Active Directory Doman Services) and after you have confirmed that replication is complete you can demote the existing domain Server and remove ADDS. You will have to change any machine that is using a static ip in the domain server area to add the new server and remove the demoted one.

You mentioned Certificate Authority.. are you sure you are using it? ADCS It can run on a member server.
Gohan2703Author Commented:
Hi David,

When I remove the ADDS run Exchange, it said "you must remove the Active Directory Certificate Service first" or something like that.  

I don't know when I remove the ADCS, What is come to the Exchange server ?
David Johnson, CD, MVPOwnerCommented:
you can backup and restore the Certificate Authority https://technet.microsoft.com/en-us/library/Cc755153%28v=WS.10%29.aspx
the CA can exist on a member server not a Domain Controller but if installed on a DC it must be removed before demoting that server from a DC to a member server.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Gohan2703Author Commented:
Can I convert direct to the VMware (with the ADCS and ADDS ) ? Have the problem with that way ?

Thank You so much David (y) !
David Johnson, CD, MVPOwnerCommented:
yes use the vmware converter
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Exchange

From novice to tech pro — start learning today.