Click here to get back home

Remove Certificate services (Root CA)

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Remove Certificate services (Root CA) scubaal 11-01-2007
Posted by scubaal on November 1, 2007, 1:38 am
Please log in for more thread options
I have an old Win2k3 server running Cert Services as Root CA and ADC
on a v. small network.
Just installed a new SBS2003 server and made this a DC. Migrated all
the Ex2k3 stuff to the new server and copied the user data across.
Now want to dcpromo the old server to take it out, but cant while
cert
services is installed.
Note: The Cert services has very limited use and in fact as *only*
been used to generate certifcates for the DCs (old and new)
themselves.

Question: I know I cant move the cert server from old to new becuase
the servers have different names. So I will have to uninstall CS.
When
I do this the root CA becomes invalid and by defination all
certifcates issued by it.


As I have nothing encrypted with the old Root CA will this cause any
problems?
Do DCs *have* to have a certificate issued? Should I install CS on
the
new (SBS) server and create a new Root CA for my DCs?


If a DC had a cert...and then doesnt....what happens?
Just trying to get a heads up before I do something stupid ;)


Al.


Posted by S. Pidgorny on November 12, 2007, 2:43 am
Please log in for more thread options
DCs don't have to have certificates issued and coontinue to function
normally unless used by applications.

Proper decommissioning process and further info:

http://support.microsoft.com/kb/889250

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

>I have an old Win2k3 server running Cert Services as Root CA and ADC
> on a v. small network.
> Just installed a new SBS2003 server and made this a DC. Migrated all
> the Ex2k3 stuff to the new server and copied the user data across.
> Now want to dcpromo the old server to take it out, but cant while
> cert
> services is installed.
> Note: The Cert services has very limited use and in fact as *only*
> been used to generate certifcates for the DCs (old and new)
> themselves.
>
> Question: I know I cant move the cert server from old to new becuase
> the servers have different names. So I will have to uninstall CS.
> When
> I do this the root CA becomes invalid and by defination all
> certifcates issued by it.
>
>
> As I have nothing encrypted with the old Root CA will this cause any
> problems?
> Do DCs *have* to have a certificate issued? Should I install CS on
> the
> new (SBS) server and create a new Root CA for my DCs?
>
>
> If a DC had a cert...and then doesnt....what happens?
> Just trying to get a heads up before I do something stupid ;)
>
>
> Al.
>



Similar ThreadsPosted
Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ? March 26, 2008, 6:20 am
Root Certificate Authority October 22, 2006, 6:35 am
How to re-issue root CA certificate February 5, 2007, 8:50 pm
CDP in root certificate when renewed July 25, 2008, 5:34 am
How to tell if Certificate Authority is root, stand-alone or? February 8, 2007, 10:27 am
Offline CA Root certificate invisble in AD March 21, 2007, 3:48 pm
Certificate Services August 3, 2005, 12:22 pm
Certificate Services August 6, 2007, 2:10 am
Certificate chain issue with Ent Sub Ca & stand alone Root CA April 27, 2006, 5:24 pm
Certificate Services Question September 16, 2005, 1:16 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap