Re: Remove CA from Forest DC

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi
check
To complete remove from forest:
How to decommission a Windows enterprise certification authority and how to remove all related objects from Windows Server 2003 and from Windows 2000 Server
http://support.microsoft.com/kb/889250

To move between servers:
How to move a certification authority to another server
http://support.microsoft.com/kb/298138

To move between servers that are DCs:
HOWTO: Move a certificate authority to a new server running on a domain controller.
http://support.microsoft.com/kb/555012



--
I hope that the information above helps you
Good Luck

Jorge Silva
MCSA
Systems Administrator

"news.microsoft.com" <donotemail> wrote in message news:eXNAhQQ$GHA.4464@xxxxxxxxxxxxxxxxxxxxxxx
We're looking to rebuild our forest level domain controllers with new disks, different RAID arrays, and upgrade to Server 2003 from 2000. One of the DCs is running CA services, for WSUS. However, I see a bunch of certificates have been issued to other domain controllers (we have several domains / single forest). It looks like each domain controller has at least one certificate.

If I follow the steps to decommission the CA and then bring up a new CA (vs. backup/restore), will not having a CA goof up active directory logins/etc.? In other words, are the automatically generated certificates for domain controllers necessary for our directory services to function? I figured that the CA wasn't as I've heard from several other shops that they don't even run a CA.

--
Tim


.



Relevant Pages

  • Site-tosite VPN Issue
    ... Windows Server 2003 domain controller ... Mixture of PCs running Windows 2000 Profressional with SP3 and Windows XP ... the VPN to the Windows Server 2003 domain controller. ... 12.7MB file from the server to the client PC. ...
    (microsoft.public.windows.server.networking)
  • RE: Internet Connection Wizard failing at Firewall Config and Secu
    ... You can use the Dcdiag.exe (Domain Controller Diagnostic Tool) included ... in Windows Support Tools to verify the AD status. ... Windows Server 2003 Active Directory Diagnostics, ...
    (microsoft.public.windows.server.sbs)
  • RE: Provide feedback to DC promotion/replacement
    ... one of the is reffering to a Windows 2000 ... As i sad in the previous posts, to rename a domain controller ... controllers in the domain must be running Windows Server 2003. ... a global catalog. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Pre-authentication failed for Windows 2008 systems
    ... Failure Code: 0x19 ... Client Address: SERVER IP ... Our active directory domain consists of two windows 2003 R2 x64 ... On the domain controller, ...
    (microsoft.public.windows.server.security)
  • Re: Windows 2003 DCPROMO Problem
    ... Controllers and you want to add a Windows Server 2003 Domain Controller. ... "Nejmos Saqeb" wrote in message ...
    (microsoft.public.windows.server.active_directory)