Click here to get back home

Domain Controller Certificates and moving to a new server or removing them?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Domain Controller Certificates and moving to a new server or removing them? amanda a 04-23-2007
Posted by amanda a on April 23, 2007, 2:42 pm
Please log in for more thread options
I need to demote & remove a DC from the domain. However, it has
certificate services loaded on it, and it's the cert server for the
Domain Controllers. I've never seen a domain controller need a
certificate before! The server was Windows SBS that was upgraded to
Windows
SBS R2 and then used the transition pack to go to Windows 2003
Standard server.

My questions are
1. What happens to our Domain controllers and our domain if I just
remove the certification services from this old server? Will they
stop
functioning? (I don't want to revoke them, right? Just remove the
certificate services from the server.)
2. Do I need to load certificate services on a different DC? If so,
how can I transfer them to the new server (NOTE: it has a different
name that the old server so I know I can't just move them) or do I
just load cert services, remove it from the old one, and the DC's
will
request and get new certs from the new server with certificate
services automatically?
3. I know from searching this group that DC's are "Hard coded" to ask
for certs, but do they need them? I've had plenty of domains with no
cert authority in them.


Basically, the crux of my questions are
1. How do I remove this certification authority without screwing up
my
domain?
2. Do I need to create a new cert authority on a different DC?


Thank you in advance for any help on this.


Posted by Ollapodrida on May 15, 2007, 8:13 am
Please log in for more thread options
I'm having the same issue; any information would be helpful. Thanks!

Similar ThreadsPosted
Removing CA certificates. December 22, 2005, 3:50 pm
Adding / removing trusted certificates by GPO October 13, 2008, 5:06 am
Automatic certificate enrollment for local system failed after upgrading member server to domain controller August 25, 2005, 6:11 pm
Moving ACLs to new server May 24, 2007, 12:08 am
removing user from domain users group doesn't help June 23, 2006, 4:15 pm
Moving Local Users from one Meber Server to another? April 12, 2007, 12:28 pm
Moving server 2003 CA database file location November 6, 2006, 3:35 pm
Domain Controller That Service a DMZ October 29, 2005, 9:58 pm
Domain Controller Security January 13, 2006, 4:43 pm
Domain Controller Security Policy August 12, 2005, 4:31 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap