Domain Controller Certificates and moving to a new server or removing them?



I need to demote & remove a DC from the domain. However, it has
certificate services loaded on it, and it's the cert server for the
Domain Controllers. I've never seen a domain controller need a
certificate before! The server was Windows SBS that was upgraded to
Windows
SBS R2 and then used the transition pack to go to Windows 2003
Standard server.

My questions are
1. What happens to our Domain controllers and our domain if I just
remove the certification services from this old server? Will they
stop
functioning? (I don't want to revoke them, right? Just remove the
certificate services from the server.)
2. Do I need to load certificate services on a different DC? If so,
how can I transfer them to the new server (NOTE: it has a different
name that the old server so I know I can't just move them) or do I
just load cert services, remove it from the old one, and the DC's
will
request and get new certs from the new server with certificate
services automatically?
3. I know from searching this group that DC's are "Hard coded" to ask
for certs, but do they need them? I've had plenty of domains with no
cert authority in them.


Basically, the crux of my questions are
1. How do I remove this certification authority without screwing up
my
domain?
2. Do I need to create a new cert authority on a different DC?


Thank you in advance for any help on this.

.



Relevant Pages

  • Re: Web Certificate for IIS Server on SBS Domain
    ... Before your reply, I actually ran across rapidssl myself, and have ordered and installed the free 30-day certificate on my site. ... I explained what you'd told me about putting my existing configuration at risk by installing Cert Services, and he said he didn't know that. ... Again, if you're just needing a cert to install on your web server to provide SSL connectivity for remote users, go with an external third-party provider. ... When you add Certificate Services on an internal network, lots of internal communications will start using pieces provided by the Cert Server instead of the defaults from Server 2003, and when things blow up, they can blow up gloriously. ...
    (microsoft.public.windows.server.sbs)
  • Move Enterprise Root CA to new hardware
    ... If you can, have the new server ... >1) Backup the CA (and reg key) ... >2) Install certificate services on the new hardware doing ... >computer with certificate services installed on it. ...
    (microsoft.public.win2000.security)
  • Re: Quick Question...
    ... You need to install a server certificate on your server. ... from any cert authority, but this will probably cost ... yourself a cert. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Web Certificate for IIS Server on SBS Domain
    ... Again, if you're just needing a cert to install on your web server to provide SSL connectivity for remote users, go with an external third-party provider. ... When you add Certificate Services on an internal network, lots of internal communications will start using pieces provided by the Cert Server instead of the defaults from Server 2003, and when things blow up, they can blow up gloriously. ...
    (microsoft.public.windows.server.sbs)
  • Re: Windows Advanced Server 2000 PKI
    ... Also, the server I'm ... planning on installing Certificates Services has the high ... >enrollment via Internet Information Services. ... >> Certificate Services have been setup properly? ...
    (microsoft.public.win2000.security)