Migrating a broken 2003 Server to 2008 .. Need advice

Roles are all moved, but when trying to remove the domain controller using 'dcpromo' we get error saying that that domain controller cannot be removed because Certificate Authority Services are running on the server .  Two major Issues.

1.  That service will not start.
2.  Following Article..


But the issue is service isn't started and wont start .. and when you go into Admin Tools / Cert Authority, you cant follow thru with removing certs because the service must be started and when you try starting in you key a Keyset Error that led me to Article:


But I have been unsuccessful at repairing the keyset.

Add/Remove Windows components throws up errors and wont load.  Its an old broke server I just want to get out of active directory so I can raise the doimain functional level on the domain using my new DC.  

I am running fine with that server just turned off.  DHCP / DNS / Authentication.. all working fine.

I think this server is just too seriously boinked to screw around with.

Is it possible to get that 2003 DC out of the Sites and Services Manually?

I mean.. what if the server had been run over by a truck.  Isnt there some process for eacsily saying good by to that 2003 box so that I can remove its presence and raise the domain functional level?


Joe UeberrothApplication EngineerAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Trent SmithCommented:
You can manually remove it.  Here is the Microsoft information on doing a manual cleanup of AD.

Joe UeberrothApplication EngineerAuthor Commented:
Thx Trent:

Just found this article also.


So.. if Im understanding.

Step1.  Do Metadata Cleanup on the new 2008 DC to remove the older 2003 DC's
Step2.  Manually delete them from Sites and Services while IN AD Site and Services on 2008 DC
Step3.  Cleanup DNS after that?
Step4.  Raise Functional Level.

Everything is fine, I just cant elevate Domain Functional level.
Trent SmithCommented:
Sounds like you are on track.  You would have to remove the defunct server from the Metadata in order to be able to promote the new server.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Seth SimmonsSr. Systems AdministratorCommented:
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.