Re: Moving Enterprise Root CA
- From: Richard Gadsden <richard.gadsden@xxxxxxxxxxxxxx>
- Date: Thu, 29 Mar 2007 14:09:17 +0100
Brian Komar [MVP] wrote:
In article <esFH0jGcHHA.2552@xxxxxxxxxxxxxxxxxxxx>, richard.gadsden@xxxxxxxxxxxxxx says...Ray wrote:You must decommission the old server, build the new server using the new name, recover the CA, and then redeploy the old server using the name that you want."Richard Gadsden" <richard.gadsden@xxxxxxxxxxxxxx> wrote in message news:%23RzqROJbHHA.4888@xxxxxxxxxxxxxxxxxxxxxxx>I have an enterprise root CA on a Windows Server 2003 Standard Edition server.
I have (finally) got the budget to put Windows Server 2003 Enterprise Edition in, but it will have to be on another server - and the previous server cannot be taken out of service or renamed.
I'm trying to think through my options to migrate it. What seems to make sense to me is:
1. Export the Root CA certificate
2. Set up a Stand-Alone Root CA using the exported certificate - on a server that can then be taken offline (probably a virtual one, unless someone has a good reason that a root CA can't be on a virtual server).
3. Create a new Subordinate Enterprise CA on the new Enterprise Edition server, subordinated from the new Root CA
4. Take the new Root CA off-line
5. Remove the old Enterprise Root CA and tell the domain to use the new Subordinate Enterprise CA
Does that make sense, and are there any tricks I'm missing?Everything should be OK if you keep the name of new server same as that of old serverI can't rename the old server, so the new server will have to have a different name.
Sorry, Brian, I can't do that. (fx: turns off HAL voice).
Really, I can't. Is this really impossible?
The old server is my primary file server, which I stuck the CA on as an afterthought. If this really is impossible, then can I just decomission the CA and build a completely new one? I guess that would invalidate all the certificates, but I could live with that.
--
Richard Gadsden richard.gadsden@xxxxxxxxxxxxxx
Nothing in this message is, or should be taken to be, representative
of the views of Cobbetts LLP
.
- Follow-Ups:
- Re: Moving Enterprise Root CA
- From: Brian Komar [MVP]
- Re: Moving Enterprise Root CA
- References:
- Moving Enterprise Root CA
- From: Richard Gadsden
- Re: Moving Enterprise Root CA
- From: Ray
- Re: Moving Enterprise Root CA
- From: Richard Gadsden
- Re: Moving Enterprise Root CA
- From: Brian Komar [MVP]
- Moving Enterprise Root CA
- Prev by Date: Error 0x800704b8 when applying policy with Security Configuration Wizard
- Next by Date: Re: Moving Enterprise Root CA
- Previous by thread: Re: Moving Enterprise Root CA
- Next by thread: Re: Moving Enterprise Root CA
- Index(es):
Relevant Pages
|