Move certificate authority

From: Ben Woskje (verukins_at_hotmail.com)
Date: 09/23/04


Date: 22 Sep 2004 18:43:05 -0700

Hi,
   I wish to move a windows 2003 enterprise based CA from one server
to another, and i just want to verify the process with some of you
knowledgable type people.

Certificate usage
- Provides certificates to web servers that are accesable to the
outside world

1. Install new enterprise root CA on new server
2. Create and issue new certificates to the appropriate web sites from
new server
3. Revoke all certificates on the old server
4. Un-install the CA on the old server

Questions
1. Are there any issues with having two root CA's in the forest?
2. Can i issue certificates with the same name from a different CA
without any issues?
3. Any other stuff that someone who has done this can pass on?
4. Anything else i should do to "clean up"

Thanks.



Relevant Pages

  • Re: Secure VPN access
    ... with it's security option for the client. ... After getting the VPN connection I check the Ip settings and found the ... point to the head ISP's DNS server. ... > Computer certificates for L2TP/IPSec VPN connections ...
    (microsoft.public.windows.server.sbs)
  • RE: L2TP/IPSEC site-to-site question
    ... seems more difficult on Windows and Isa 2000 mix, ... If I want to use certificates what type I have to use? ... > site-to-site VPN connection. ... > Site-to-Site VPN in ISA Server 2004 ...
    (microsoft.public.isa)
  • Re: Vista wireless using IAS and WPA-Enterprise
    ... certificates, which may be more than the limit that the IAS server can send ... on a Web site or if you use IAS in Windows Server 2003 ... Vista wireless using IAS and WPA-Enterprise ...
    (microsoft.public.windows.server.networking)
  • RE: L2TP/IPSEC site-to-site question
    ... Microsoft Internet Security and Acceleration (ISA) Server 2004 ... >site-to-site vpn connection. ... >My concerns are about the certificates part. ...
    (microsoft.public.isa)
  • Re: IAS EAP (PEAP)
    ... > IAS is registered with AD so I am okay there. ... If you create the server cert using the information below, ... Use this procedure to configure IAS server certificates for use with PEAP ...
    (microsoft.public.internet.radius)