Re: Enterprise CA

From: S. Pidgorny (slavickp_at_yahoo.com)
Date: 12/27/04

  • Next message: Burtsev Dmitry: "Re: Enterprise CA"
    Date: Mon, 27 Dec 2004 23:03:03 +1100
    
    

    First, look into the following KB articles:

    How to move a certification authority to another server
    (http://support.microsoft.com/?id=298138)

    How to move a certificate authority to a new server running on a domain
    controller (http://support.microsoft.com/?id=555012)

    The trivial way of moving a CA that you can't restore to another server
    would be revoking all issued certificates and creating new CA.

    -- 
    Svyatoslav Pidgorny, MVP, MCSE
    -= F1 is the key =-
    "Burtsev Dmitry" <burtsev@removethispart.km.ru> wrote in message
    news:uTeKyQA7EHA.2676@TK2MSFTNGP12.phx.gbl...
    > Hello.
    > In my network i have Enterprise CA placed on Windows 2000 DC.  A few days
    > ago the server was crashed.
    > Today I cannot rstore it (but I try).
    > Have any suggustions how to move CA and DC to another server?
    > I can replace DC, but how to move CA to another server without backup I
    > don't know.
    > I have all data from disk (keys, logs, registry).
    >
    >
    >
    > -- 
    > Dmitry Burtsev [burtsev@removethis.km.ru]
    >
    >
    >
    >
    

  • Next message: Burtsev Dmitry: "Re: Enterprise CA"

    Relevant Pages

    • Re: Removing CA Objects from AD
      ... Fore detailed information, see "How to decommission a Windows enterprise ... Server 2003 and from Windows 2000 Server" - ... >>> Automatic enrollment against the certification authority 'myservername' ...
      (microsoft.public.windows.server.security)
    • Re: IPSec for ODBC connection?
      ... I created an IPSec policy on the server with a Block All filter and an ... ODBC Filter allowing 1433 incoming with an Authentication Method of ... Certification Authority only and a certificate I created on the ... the client cannot connect on ODBC ...
      (microsoft.public.win2000.security)
    • Re: Possible conflicting info:Help file states that Offline Root CA canot be member server of domain
      ... As Paul stated in another of your threads, an offline CA is *never* a member of a domain. ... see outlined on the second step below that the ".Set up a server that runs ... Windows that you will use for the root certification authority. ...
      (microsoft.public.security)
    • Possible conflicting info:Help file states that Offline Root CA canot be member server of domain?
      ... see outlined on the second step below that the ".Set up a server that runs ... Windows that you will use for the root certification authority. ... Log on to the server as the administrator and install Certificate ...
      (microsoft.public.security)
    • Re: Remove CA from Forest DC
      ... How to decommission a Windows enterprise certification authority and how to remove all related objects from Windows Server 2003 and from Windows 2000 Server ... Move a certificate authority to a new server running on a domain controller. ...
      (microsoft.public.windows.server.active_directory)