Re: Move 2000 Certificate server to 2003 on new hardware



The certificate of the CA needs to be in the trusted CA store on the
computer that is trying use a certificate that the CA issued. You can see
the contents of such via the mmc snapin for certificates for user or
computer and looking in the folder for Trusted Root Certificate Authorities.
An Enterprise Ca would automatically be added for domain computers, you can
specify other certificates to add via Group Policy "computer"
configuration/Windows settings/security settings/public key policy settings,
and you can distribute the .cer file for the Certificate Authority to users
that need it and clicking it will start the certificate import wizard. You
can create a .cer file by selecting the certificate from a folder in the mmc
snapin for certificates and selecting all tasks - export. If you are using
Web Enrollment for certificate requests the CA certificate/chain can be
downloaded that way also. -- Steve


"thawkz" <thawkz@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:546BD917-DA41-454A-A8C8-6EA13D28D765@xxxxxxxxxxxxxxxx
Thanks for your response. Yes, I have no problem reissuing new
certificates.
Yes, the document you referenced is indeed the MS article I was referring
to, and I agree that the process would not be difficult, however our
situation is not that straightforward....we are moving from windows 2000
to
windows 2003 and the existing hardware does not support an upgrade to
windows
2003.
You mentioned that I would need to make sure all the computers involved
"trust the new CA". What steps do I need to take to ensure and verify this
trust?

Thanks again.....

"Steven L Umbach" wrote:

If you have not problem reissuing new certificates wherever needed then
go
for it. Your proposal is basically destroying your old PKI and building a
new one rather than maintain the current one on the new server which
really
is not that difficult to do per the instructions in the KB article below
which maybe you were referring to. You will also need to make sure that
all
computers involved trust the new CA. --- Steve

http://support.microsoft.com/?id=298138

"thawkz" <thawkz@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:AC0758CC-3C31-4EE1-BBC8-3C80C77F0CA6@xxxxxxxxxxxxxxxx
Currently using Windows 2000 stand-alone certificate server (member
server)
for OWA and a couple of other internal (non-critical) apps that require
SSL
certificate.
Plan is to retire this hardware and install certificate server on new
hardware using Windows Server 2003.
I have reviewed the microsoft article regarding migrating certificate
services, but we really do not need to perform a migration--we are
perfectly
fine with issuing new certificates to the few apps that use it (plus
the
hardware currently being used would not support Windows 2003)..... My
plan
is
to:
1) uninstall certificate services from current server.
2) install certificate services on new server.
3) Reissue certificates to the non-critical apps and OWA.
Are there any problems with this approach? Is there a more "graceful"
recommended approach to removal of the current certificate services
server,
before installing the new certificate services server?
Thanks.





.



Relevant Pages

  • Re: Need help configuring Wireless Connection profile
    ... and I can only use the intel OR windows utility, not both at the same time. ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless WPA2 ... SMALL BUSINESS SERVER: ... STEP #1 Install Certificate Services ...
    (microsoft.public.windowsxp.general)
  • Cannot sync Windows mobile with sbs2003 server
    ... Windows Mobile OS to the SBS2003 server at work so that he can read e-mails. ... What certificate do Microsoft recommend here, and where can this be bought? ...
    (microsoft.public.pocketpc)
  • Re: Web Certificate for IIS Server on SBS Domain
    ... Before your reply, I actually ran across rapidssl myself, and have ordered and installed the free 30-day certificate on my site. ... I explained what you'd told me about putting my existing configuration at risk by installing Cert Services, and he said he didn't know that. ... Again, if you're just needing a cert to install on your web server to provide SSL connectivity for remote users, go with an external third-party provider. ... When you add Certificate Services on an internal network, lots of internal communications will start using pieces provided by the Cert Server instead of the defaults from Server 2003, and when things blow up, they can blow up gloriously. ...
    (microsoft.public.windows.server.sbs)
  • Re: Need help configuring Wireless Connection profile
    ... Now life is good in the Windows wireless world. ... now have a secure wireless setup within my small business server environment. ... "point" the info of the Radius authentication to your current Radius server. ... STEP #1 Install Certificate Services ...
    (microsoft.public.windowsxp.general)
  • Re: Questions
    ... deployment tool and certificate services. ... we do have more convenient means to create server /client certificate ...
    (microsoft.public.dotnet.framework.webservices)