Spliting Root CA from Subordinate CA


hi,

new in forum , please bare me if information mising.

have inherited domain root ca ,  subordiante ca both installed on dc windows 2008 sp2.
want change situation , have root ca installed on win 2012 r2 offline server, subordiante ca in windows 2102 r2 datacenter domain member server.

there handfull of issued certificates in ca.
2 "domain controller" certificates each dc, few "efs basic" certificates , few "web service" certificates

looking @ 2 ways :
1. start new pki infrastructure scratch.
uninstall old server , install new ones. not sure happens "domain controller" certificates and 
if approach create me problems. 
2. split root ca subordiante ca , migrate windows 2012 r2
not sure how split these roles in 2 servers , if approach worthy in case

apprechiate suggestions

on mon, 1 dec 2014 16:26:21 +0000, alpes wrote:

i have inherited domain root ca ,  subordiante ca both installed on dc windows 2008 sp2.

to begin with, impossible, can't have multiple instances of
certificate services running on same server.


paul adare - fim cm mvp
"i'm not sure if or bad thing. bad thing;
things bad things." -- nile evil bastard



Windows Server  >  Security



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file