Offline root CA misplaced, no backup


recently in unrelated troubleshooting effort 1 of colleagues , noticed number of certificate services errors in event logs on workstation.  went , checked several others, same errors.  tracked down , breaks down 2 tier pki implemented before arrived.  part of turnover, never made aware of pki or 1 being used anything.  fast forward year , half certificate errors in event logs on workstations , tracks root ca issuing certificate being expired.  well, went root ca.  hunted through virtual environment powered off machine ca, , remembered in meeting server 2012 r2 had been installed on laptop root ca , when done initial deployment, powered down , put in closet.  no backup, no export of certs , keys, nothing recover with.  root ca offline no way recover it.  finding quite bit on technet , internet replacing cas , migrating cas, virtually nothing pertains situation.  think http://social.technet.microsoft.com/wiki/contents/articles/3527.how-to-decommission-a-windows-enterprise-certification-authority-and-how-to-remove-all-related-objects.aspx apply once able figure out how handle initial situation of not having root ca.  hoping has insight on how approached.  appreciated.  in advance.

best regards, keith mernovage

hi,

as mentioned former ca’s certificate expired, indicates certificates issued expired , invalid, too.

in case,  so suggest follow article above remove ca objects active directory.

best regards,

amy


please remember mark replies answers if , unmark them if provide no help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2