Re: Rendom and certificate authority on DC

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Jorge Silva wrote:
Hi
There is much more than that check:
"CA Requirements" in
http://technet2.microsoft.com/windowsserver/en/library/4d0c3b6e-e6f5-4ab3-9d81-106ae3a715491033.mspx?mfr=true



Jorge Silva
MCSE, MVP Directory Services
"LSR" <nospam@xxxxxxxxxx> wrote in message
news:5cl55cF2vcm28U1@xxxxxxxxxxxxxxxxxxxxx
We have a simple Windows Server 2003 domain, at 2003 functional
level, with two DCs.There are some other 2003 member servers and XP
workstations. We want to rename the domain as the company is
rebranding. Unfortunately one of the DCs is also our Certificate
Authority, so (I
think!) that means the rendom process won't work.

Could I just remove the domain controller role from the CA server,
rename the domain, then promote it back?

(I know it's not ideal to have a DC as a CA ...)

--
LSR

Yes I've seen that and the docs at fwlink 5585. All it really says that is
relevent is:
====
Management of enterprise certificates can continue during a domain rename
procedure when the following requirements are in effect before domain
rename:
. The CAs are not installed on domain controllers.


====
- hence my question. We only use certificates internally for IIS (SourceSafe
and WSUS authentication) so I can reissue them later if necessary.


--
LSR


.



Relevant Pages

  • Re: Rendom and certificate authority on DC
    ... We want to rename the domain as the company is ... Could I just remove the domain controller role from the CA server, ... Management of enterprise certificates can continue during a domain rename ...
    (microsoft.public.windows.server.active_directory)
  • correction for Gary
    ... Renaming a Domain Controller issues. ... If you wish to rename a DC, ... To rename a domain controller, use the Netdom tool command-line utility, the ... domain functional level must be set to Windows Server 2003 as well. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain controller name -rename issue
    ... Make sure you have at least a system state backup before starting the rename of the production one. ... The DNS host names of domain controllers in a renamed domain are not ... Windows NT 4.0 primary domain controller to Windows 2000 ... it with dcpromo /forceremoval to member server. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain controller name -rename issue
    ... After I decommission the DC I will only have one domain controller. ... The DNS host names of domain controllers in a renamed domain are not ... the domain rename operation is complete. ... with dcpromo /forceremoval to member server. ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to replace single domain controller in domain with a singl
    ... Although you can use System Properties to rename a domain controller, Active Directory and DNS replication latency might temporarily prevent clients from locating or authenticating to the renamed domain controller. ... export of DHCP database for 2008 choose ... demote the old DC to member server, reboot and rename it, reboot ...
    (microsoft.public.windows.server.active_directory)