Demote Root CA to subordinate - lose existing certs?



With my limited understanding of Certificate Services (until now - hopefully
I'm learning!), I realize that sometime in the past I have created multiple
Enterprise Root CAs in the organisation. I have now read that this is OK,
but not desirable.

I'd like now to demote one rootCA back to an Ent Subordinate CA and retain a
single RootCA, and I'm guessing this is going to involve uninstalling CertSvc
and reinstalling on the machine being "demoted".

My big concern is the existing certs that have already been issued by that
CA - apart from it's own, it has issued Dom Controller certs for another 4
DCs.

How best can I handle this?
Can I uninstall/reinstall CertSvc without affecting the DCs who have certs
issued by this machine?

Any help would be much appreciated,
Cam
.



Relevant Pages

  • RE: Move Ent. Certificate Authority from DC and keep certs
    ... I did not clearly state in my last post that we have two DCs in this forest. ... sounds like we will need to demote DC1 before taking it offline and bringing ... Certificate Authority from DC and keep certs ... > rebuild the hardware for different production server roles. ...
    (microsoft.public.windows.server.migration)
  • Re: Demote Root CA to subordinate - lose existing certs?
    ... What's the correct sequence to follow? ... Reinstall CS on same machine, selecting as an EntSubCA, then ... You should publish the Domain Controller and Domain Controller Authentication certs at the subCA only. ... > DCs. ...
    (microsoft.public.windows.server.security)
  • RE: First Enterprise Root CA - [WP]
    ... I think the Default GPO for DCs has the option under computer config -> ... certs automatically is selected. ... update certs ..... ... deployed my first Enterprise Root CA running on a member ...
    (microsoft.public.security)
  • First Enterprise Root CA - [WP]
    ... deployed my first Enterprise Root CA running on a member ... I have noticed that it has automatically assigned certs to all the DCs in ... The certs are valid for 1 year. ... make sure that these certs automatically renew after 1 year on the DCs??? ...
    (microsoft.public.security)