Re: Enterprise Root CA change

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 02/03/05


Date: Wed, 2 Feb 2005 22:50:04 -0600

If you want to replace your existing Enterprise CA to a new computer you can
not have them both on the network at the same time. There is way to move the
CA to a new computer by backing up the existing CA keys, certificate
database, and registry configuration to restore to the new computer after
taking the original CA offline but you can certainly have more then one
Enterprise CA in the domain, usually by creating "subordinate CA's" that
chain the root Enterprise CA you already have. The link below explains a way
to move a CA to another computer. For an Enterprise CA I would also
recommend that you name the new computer the same as the old computer [after
taking the old one offline] and then join it to the domain before doing the
move procedure. --- Steve

http://support.microsoft.com/?id=298138 --- how to move Windows Certificate
Authority.

"RJ" <RJ@discussions.microsoft.com> wrote in message
news:ACEE0004-D61F-4474-9CFF-9A478D5798A4@microsoft.com...
>I am running a Win2k enterprise root CA without subordinates CAs with a few
> certificates issued. I would like to setup a new Win2k3 enterprise root
> CA
> in the same Win2k3 Active directory domain.
>
> Can I run these in parallel in the same domain?
>
> Do I need to decomission the Win2k CA first before I install the new
> Win2k3
> CA since it will start a new certificate chain?
>
> Thanks,



Relevant Pages

  • RE: Upgrade Standard CA to an Enterprise CA
    ... Do you mean you want to migrate the stand-alone CA to Enterprise CA? ... Back up the certificate database, the CA certificate, and the CA private ... 8.Select Preserve existing certificate database to use the old database. ...
    (microsoft.public.security)
  • Re: Difference between Certificate Authorities
    ... If my Enterprise Root is crashed then certificate issue by Enterprise root ... Root CAs Vs Subordinate Vs Issuing CAs. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Isolation of the Root CA
    ... If you want to put your Enterprise CA behind a firewall, ... practice article on that? ... >> An Enterprise CA can not be an offline CA. ... >> standalone root CA and use it to issue a certificate for an Enterprise CA ...
    (microsoft.public.win2000.security)
  • Re: EFS and Certificate Services
    ... > I created a Enterprise Root CA with a Enterprise Subordinate CA for issuing ... An Enterprise Root CA computer cannot be offline. ... I check the thumbprint of the file and the certificate which matched. ... The best practice is to issue the certificates *before* any encryption ...
    (microsoft.public.win2000.security)
  • Re: W2K3 3-tier CA Implementation
    ... No matter what environment you are in, install a standalone ROOT CA. ... based on the standalone subordinate CA. ... I agree with issuing CAs being enterprise CAs. ... You do not use a certificate tempalte for the ...
    (microsoft.public.security)