Migration Certification Templates

hi folks

   Recently was created a new server for change type of certificate (from SHA1 to SHA2). I need migrate certificate template from old CA to new CA and find which certificate template are still used and disable old CA. Both CA's are same domain.  Which are  steps for to do this task?
Leonardo MendesNetwork AnalystAsked:
Who is Participating?
 
Leonardo MendesNetwork AnalystAuthor Commented:
Hi Jakob

    A few days ago i found two article about migration CA infrastructure from SHA1 to SHA2. This:

https://blogs.technet.microsoft.com/askds/2015/10/26/sha1-key-migration-to-sha256-for-a-two-tier-pki-hierarchy/

and this

https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/dn771627(v=ws.11)

              And I create an Lab for test migration CA and renew certificates. So far everythink works fine

Thanks
0
 
Jakob DigranesSenior ConsultantCommented:
templates are stored in active directory - you add templates you want to use to the certificate server. If you need an overview over templates in user;
1. check which templates are added to SHA1 server
2. check with issued certificates which templates they're based on

for controlling template issuance, look at certificate template security and take a look at enroll and autoenroll permissions
0
 
Jakob DigranesSenior ConsultantCommented:
I've used the first article myself - it works fine
0
 
Leonardo MendesNetwork AnalystAuthor Commented:
Thanks Jakob
0
 
Seth SimmonsSr. Systems AdministratorCommented:
No comment has been added to this question in more than 21 days, so it is now classified as abandoned.

I have recommended this question be closed as follows:

Accept: Leonardo Mendes (https:#a42440140)

If you feel this question should be closed differently, post an objection and the moderators will review all objections and close it as they feel fit. If no one objects, this question will be closed automatically the way described above.

seth2740
Experts-Exchange Cleanup Volunteer
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.