How to take down old root certificate authority server?

From: Toni Lassila (mpao_at_mc-europe.com)
Date: 05/28/04


Date: 28 May 2004 02:33:01 -0700

We have an old W2K server that previously acted us our main
DC+Exchange server but has now been replaced on almost all tasks. One
of the things that is left is the root certificate authority service
(I know it shouldn't be online but there you go). What I'd like to
accomplish is to move the cert authority to another DC and take down
the old server.

The problem is that all the other DCs were upgraded to Windows 2003 so
before we can move the certificate authority we'd have to upgrade the
old server to Windows 2003. Unfortunately due to technical issues this
is not possible. I'm thinking the only way is to set up a temporary
W2K server, make it a DC and take down the old server. Then transfer
the root certificate authority to the temporary server, upgrade it to
2003 and finally move the cert authority to the actual DC that will
house it.

Since this involves setting up at least one W2K DC server and the
whole 2003 upgrade process, I'm hoping there was some simpler way to
do things. Any ideas?



Relevant Pages

  • Re: Should I install Certificate Authority to solve these problems ?
    ... Implementing a PKI requires some thought, server builds, ... > Management is pushing to get Certificate Authority ... You have told them that this requires a minimum of two machines ... > 1) A server management tool can use certificates when the servers ...
    (microsoft.public.win2000.security)
  • Re: Should I install Certificate Authority to solve these problems ?
    ... team was planning to implement IPSec in our Win2003 domain. ... arguing that somebody can "spoof the system and a rogue server could pretend ... >> Management is pushing to get Certificate Authority ... > You have told them that this requires a minimum of two machines ...
    (microsoft.public.win2000.security)
  • Problem with certificates/L2TP VPN
    ... So we have a Windows 2000 RRAS VPN server which has been serving us ... IKE security association negotiation failed. ... Peer Issuing Certificate Authority ...
    (microsoft.public.windows.server.networking)
  • Re: Exchange 5.5 to 2003
    ... You say to use a temporary server and introduce it as an NT4 BDC, ... Then you say to introduce the new exchange server. ... Once I upgrade the temporary server to 2003, ...
    (microsoft.public.exchange.setup)
  • Re: Setting up OWA SSL on a non-standard web port.
    ... > advanced server, I setup the win2k server as a ... > certificate authority so that I could run SSL for the ... > enable SSL is there a way to setup the SSL authentication ...
    (microsoft.public.exchange.setup)