Offline root CA misplaced, no backup
recently in unrelated troubleshooting effort 1 of colleagues , noticed number of certificate services errors in event logs on workstation. went , checked several others, same errors. tracked down , breaks down 2 tier pki implemented before arrived. part of turnover, never made aware of pki or 1 being used anything. fast forward year , half certificate errors in event logs on workstations , tracks root ca issuing certificate being expired. well, went root ca. hunted through virtual environment powered off machine ca, , remembered in meeting server 2012 r2 had been installed on laptop root ca , when done initial deployment, powered down , put in closet. no backup, no export of certs , keys, nothing recover with. root ca offline no way recover it. finding quite bit on technet , internet replacing cas , migrating cas, virtually nothing pertains situation. think http://social.technet.microsoft.com/wiki/contents/articles/3527.how-to-decommission-a-windows-enterprise-certification-authority-and-how-to-remove-all-related-objects.aspx apply once able figure out how handle initial situation of not having root ca. hoping has insight on how approached. appreciated. in advance.
best regards, keith mernovage
hi,
as mentioned former ca’s certificate expired, indicates certificates issued expired , invalid, too.
in case, so suggest follow article above remove ca objects active directory.
best regards,
amy
please remember mark replies answers if , unmark them if provide no help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.
Windows Server > Security
Comments
Post a Comment