Demote first DC in a Windows 2003 domain. What happens to the certs?



(It was recommend that I post this questions to this group. It was
originally posted in the AD group.)

We have three DC's, all running Windows Server 2003 w/SP2. DC1 is unstable,
and needs to be demoted before there is a serious hardware failure. DC2 and
DC3 have been brought online, and all of the FSMO roles have been moved to
them. The one remaining issue is that DC1 issued the Domain Controller
certs to DC2 and DC3. No other certs in our environment where created by
DC1, just the Domain Controller certs for DC2 and DC3. What needs to be
done in order to allow the demotion of DC1 out of AD without affecting the
certs? This server will be salvaged after the demotion.

Thank you,

-Christian



.



Relevant Pages

  • Certs for Domain Controllers-Trying to Prevent an Issue
    ... all running Windows Server 2003 w/SP2. ... DC3 have been brought online, and all of the FSMO roles have been moved to ... The one remaining issue is that DC1 issued the Domain Controller ... No other certs in our environment where created by ...
    (microsoft.public.windows.server.security)
  • Re: Certs for Domain Controllers-Trying to Prevent an Issue
    ... I'm reading your w2k3 PKi book right now and like it very much. ... You can use certutil -dcinfo deleteALL to replace the certs after the new PKI is deployed ... DC3 have been brought online, and all of the FSMO roles have been moved to ... The one remaining issue is that DC1 issued the Domain Controller ...
    (microsoft.public.windows.server.security)
  • Re: Certs for Domain Controllers-Trying to Prevent an Issue
    ... Easiest would be to deploy a proper PKI ... You can use certutil -dcinfo deleteALL to replace the certs after the new PKI is deployed ... DC3 have been brought online, and all of the FSMO roles have been moved to ... The one remaining issue is that DC1 issued the Domain Controller ...
    (microsoft.public.windows.server.security)
  • Re: Certs for Domain Controllers-Trying to Prevent an Issue
    ... "Jorge de Almeida Pinto [MVP - DS]" wrote in message ... You can use certutil -dcinfo deleteALL to replace the certs after the new PKI is deployed ... The one remaining issue is that DC1 issued the Domain Controller ...
    (microsoft.public.windows.server.security)