|
Posted by Paul Bergson [MVP-DS] on September 4, 2008, 4:07 pm
Please log in for more thread options
Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.
show/hide quoted text
> Yeah, thanks I have reviewed that. That is the method I used, but am now
> getting error messages from certificate services. I am thinking its
> because my domain is running at the 2000 level and the Certificate
> authority is 2003. Will running adprep solve this issue?
>> Hello James,
>> See here:
>> http://support.microsoft.com/kb/298138
>> Best regards
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>> We are planning on moving our CA server to Windows 2003. We currently
>>> have
>>> a Windows 2000 based domain.
>>> I have gone ahead and done this in a test environment, and am getting
>>> a
>>> bunch of error messages in event veiewer on the new 2003 CA.
>>> My understanding is that I need to run adprep, and forest prep on our
>>> 2000 domain controller, to bring it up to the 2003 level. Is this
>>> correct? Will this harm anything, if we don't actually upgrade our
>>> domain controllers to windows 2003?
As far as I know you can't run 2003 certificate services in a 2000 domain or
on a Windows 2000 server.
This should have been posted in the security Newsgroup and I have included
them in on this response. The PKI experts are in this NewsGroup.
--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
http://www.pbbergs.com
|
|
Posted by Brian Komar \(MVP\) on September 4, 2008, 11:18 pm
Please log in for more thread options
You can run a Windows Server 2003 PKI in a Windows 2000 domain, as long as
the Schema is updated to the Windows Server 2003 schema (to add the v2
certificate template object and attributes).
We deployed this at several customers circa 2003.
Brian
show/hide quoted text
> Please no e-mails, any questions should be posted in the NewsGroup
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>> Yeah, thanks I have reviewed that. That is the method I used, but am now
>> getting error messages from certificate services. I am thinking its
>> because my domain is running at the 2000 level and the Certificate
>> authority is 2003. Will running adprep solve this issue?
>>> Hello James,
>>> See here:
>>> http://support.microsoft.com/kb/298138
>>> Best regards
>>> Meinolf Weber
>>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>>> confers no rights.
>>> ** Please do NOT email, only reply to Newsgroups
>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>> We are planning on moving our CA server to Windows 2003. We currently
>>>> have
>>>> a Windows 2000 based domain.
>>>> I have gone ahead and done this in a test environment, and am getting
>>>> a
>>>> bunch of error messages in event veiewer on the new 2003 CA.
>>>> My understanding is that I need to run adprep, and forest prep on our
>>>> 2000 domain controller, to bring it up to the 2003 level. Is this
>>>> correct? Will this harm anything, if we don't actually upgrade our
>>>> domain controllers to windows 2003?
> As far as I know you can't run 2003 certificate services in a 2000 domain
> or on a Windows 2000 server.
> This should have been posted in the security Newsgroup and I have included
> them in on this response. The PKI experts are in this NewsGroup.
> --
> Paul Bergson
> MVP - Directory Services
> MCTS, MCT, MCSE, MCSA, Security+, BS CSci
> 2008, 2003, 2000 (Early Achiever), NT4
> http://www.pbbergs.com
>
|
|
Posted by Paul Bergson [MVP-DS] on September 9, 2008, 8:15 am
Please log in for more thread options
Thanks Brian, I knew it best to be posted in the security Newsgroup
--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
http://www.pbbergs.com
Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.
show/hide quoted text
> You can run a Windows Server 2003 PKI in a Windows 2000 domain, as long as
> the Schema is updated to the Windows Server 2003 schema (to add the v2
> certificate template object and attributes).
> We deployed this at several customers circa 2003.
> Brian
>> Please no e-mails, any questions should be posted in the NewsGroup
>> This posting is provided "AS IS" with no warranties, and confers no
>> rights.
>>> Yeah, thanks I have reviewed that. That is the method I used, but am
>>> now getting error messages from certificate services. I am thinking its
>>> because my domain is running at the 2000 level and the Certificate
>>> authority is 2003. Will running adprep solve this issue?
>>>> Hello James,
>>>> See here:
>>>> http://support.microsoft.com/kb/298138
>>>> Best regards
>>>> Meinolf Weber
>>>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>>>> confers no rights.
>>>> ** Please do NOT email, only reply to Newsgroups
>>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>>> We are planning on moving our CA server to Windows 2003. We currently
>>>>> have
>>>>> a Windows 2000 based domain.
>>>>> I have gone ahead and done this in a test environment, and am getting
>>>>> a
>>>>> bunch of error messages in event veiewer on the new 2003 CA.
>>>>> My understanding is that I need to run adprep, and forest prep on our
>>>>> 2000 domain controller, to bring it up to the 2003 level. Is this
>>>>> correct? Will this harm anything, if we don't actually upgrade our
>>>>> domain controllers to windows 2003?
>> As far as I know you can't run 2003 certificate services in a 2000 domain
>> or on a Windows 2000 server.
>> This should have been posted in the security Newsgroup and I have
>> included them in on this response. The PKI experts are in this
>> NewsGroup.
>> --
>> Paul Bergson
>> MVP - Directory Services
>> MCTS, MCT, MCSE, MCSA, Security+, BS CSci
>> 2008, 2003, 2000 (Early Achiever), NT4
>> http://www.pbbergs.com
>
|
| Similar Threads | Posted | | Windows 2000 Domain, Windows 2003 Enterprise CA | July 15, 2005, 2:07 pm |
| windows 2000 server like home permistions on 2003 | November 30, 2006, 1:00 pm |
| Read-only access to AD, 2000, and 2003 server for monitoring? | September 7, 2007, 3:20 pm |
| Power Users & Servers - Windows 2000 & 2003 Differences | December 7, 2006, 9:32 am |
| Open Ports on an Exchange 2000 on Server 2000 | December 26, 2005, 5:27 pm |
| SP-1 to a Windows 2003 Server running SQL Server 2000 with out SP- | July 5, 2005, 5:20 pm |
| creat a domain trust between Windows 2000 server, it show error message:"PRC server is unavailable" | July 3, 2006, 3:59 pm |
| Windows 2003 - Child domain cannot request certificate from root domain | January 11, 2008, 11:41 am |
| Re: Upgrading of 2003 domain to 2008 domain, checklist, questions? | January 1, 2009, 6:43 am |
| Is it possible to use the Windows 2003 user names instead of pre-Windows 2000 user names in Windows Authentication? | September 5, 2006, 9:27 am |
|
> getting error messages from certificate services. I am thinking its
> because my domain is running at the 2000 level and the Certificate
> authority is 2003. Will running adprep solve this issue?
>> Hello James,
>> See here:
>> http://support.microsoft.com/kb/298138
>> Best regards
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>> We are planning on moving our CA server to Windows 2003. We currently
>>> have
>>> a Windows 2000 based domain.
>>> I have gone ahead and done this in a test environment, and am getting
>>> a
>>> bunch of error messages in event veiewer on the new 2003 CA.
>>> My understanding is that I need to run adprep, and forest prep on our
>>> 2000 domain controller, to bring it up to the 2003 level. Is this
>>> correct? Will this harm anything, if we don't actually upgrade our
>>> domain controllers to windows 2003?