Decommission / migrate root forest Certificate Authority.

What are the best steps to decommission / migrate an enterprise CA, its installed on a domain controller, its the last 2003 DC in the environment so I'd like to decommission the so we can raise domain function level.

It only has 16 Domain Controller Certificates Issued, so isn't doing much since migrating off Lync etc, all the old expired web server certs have been revoked.

Once complete we will bring in a 2012R2 CA for general use (on a member server not a DC I know).

So can we uninstall the CA and build a new one or migrate some how?

thanks
RCoTeamAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

David FavorLinux/LXD/WordPress/Hosting SavantCommented:
This is very easy.

Just do nothing.

Applications using CAs - browsers, email, etc... - access many CAs, so when you add a private/custom CA, you're just adding another CA to a list.

Just create your new CA + add it to your application's CA list.

Or better, use https://LetsEncrypt.org which has been offering free SSL certs for years.

Using LE, means you skip the entire private CA generation step, as the LE issuer chain is baked into all SSL aware tools at this point.
1
MaheshArchitectCommented:
steps
backup old CA along with database and certificate - MS documentation is available for same
uninstall CA authority from 2003 CA (DC)
decommission 2003 DC after CA removal
now raise your functional levels and you have two options now
either restore above backup on new 2012 server as restored CA with same name as old 2003 OR
you can ignore old unused CA and create brand new enterprise CA
1

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
RCoTeamAuthor Commented:
thanks Mahesh, I thought as much.   That's what I've now done, looks good.
0
MaheshArchitectCommented:
Help close
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.