Moving enterprise CA off of domain controller


when first setup our active directory environment (after migrating novell) few years ago, installed enterprise certificate authority on 1 of our domain controllers running windows 2008 standard.  i'm in process of setting internet based management sccm , have run roadblock.  a certificate authority on windows 2008 standard not support version 2 , 3 certificate templates.  seeing need create custom templates , setup auto-enrollment workstations on our domain must find solution.  it appears windows 2008 r2 standard , above supports functionality.  i've read can migrate certificate authorities 1 server long keep ca name intact, if destination server has different hostname source server?  the domain controller not being decommissioned cannot spin-up new server same hostname ca.  are there ramifications of moving ca server different hostname?  i've read various articles , support posts , i'm confused issues, if any, cause.  i appreciate can provide, can finish rolling out our sccm solution.  thank you...

i suspect ca not installed using best practices , not ready server internet clients. recommend not try migration, enough complex. instead, recommend start clean installation. 1 example: https://technet.microsoft.com/en-us/library/hh831348.aspx

few notes:

1) not assign certificate policies in root ca certificate

2) use article plan cdp , aia extensions: http://en-us.sysadmins.lv/lists/posts/post.aspx?id=103


vadims podāns, aka powershell cryptoguy
weblog: en-us.sysadmins.lv
powershell pki module: pspki.codeplex.com
powershell cmdlet editor pscmdlethelpeditor.codeplex.com
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2