2012R2 server AD Certificate Services

Hi Experts,

We have a 2012R2 DC which has AD Certificate Services installed on it. The certificates that have been issued seem only to be to Domain Controllers. We are trying to decom this server and wanted to see if uninstalling Certificate Services on that server would break anything?

Thanks
abhijitm00Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Rich WeisslerProfessional Troublemaker^h^h^h^h^hshooterCommented:
Do you have a new Certificate Server that you have already stood up to replace the existing?
Have you set the Certificate server to not have any templates for which it is issuing certificates?
Have you set the anticipated life-span for it's Certificate Revocation List to be longer than the expiration date of it's current CA certificate?
Hmm, seems to me I saw a decent CA retirement checklist on Microsoft's site somewhat recently.  I'll see if I can dig that up for you.
(How to decommission a Windows enterprise certification authority and remove all related objects)
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Dariusz TykaICT Infrastructure Specialist Senior Commented:
You can uninstall active directory certificate  services but you should follow the procedure for decommissioning CA.  See link below which describes in details all steps necessary to remove AD certificate service:
https://technet.microsoft.com/en-us/library/cc771494(v=ws.11).aspx
0
abhijitm00Author Commented:
Great. Thank you both, I will review these articles
0
Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

abhijitm00Author Commented:
Would you know the process to migrate cert services to 2016? Thanks
0
Rich WeisslerProfessional Troublemaker^h^h^h^h^hshooterCommented:
Unfortunately I haven't done a lot with 2016 yet, and don't have ADCS up on 2016 either.  I would assume the migration would be materially equivalent to migrating to 2012 R2...
0
abhijitm00Author Commented:
Thanks Rich. Have you come across a scenario where the ADCS server was removed or crashed and it has affected AD adversely?
0
Rich WeisslerProfessional Troublemaker^h^h^h^h^hshooterCommented:
> Have you come across a scenario where the ADCS server was removed or crashed and it has affected AD adversely?
I have not.  (I'm uncertain whether to say, 'Fortunately', or 'Unfortunately'.  I'm leaning toward the former.)  I've had three production environments, and half a dozen or so test/lab environments, and haven't run into a problem...  If the ADCS server is unavailable for whatever reason, I wouldn't expect the first problems to appear until the CRL expires, and I've found that more software doesn't check the CRL than checks it.   Most of the time, after that, things will warn that the certificate will expire, but automated processes whcih can't respond to the warning, fail.  (And when stuff does check... it seems most of the time it just times out silently and continues if it can't find a CRL.)  That said, I certainly wouldn't take my experience as necessarily typical.
0
abhijitm00Author Commented:
Uninstalled Certificate Services from server
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2012

From novice to tech pro — start learning today.