Re: Impact of removing only CA



Hi
- Okay, first of all, is your policy alllowing EFS? Do you have KRAs defined?
- EFS can be problematic... There is no back door into EFS; if you lose the key(s) to it, you lose your data unless you've KRAs.
- If you remove the old CA the certs will stop working in their expire date. Some problems or errors that you migh see are related with CRLs and AIA. If you remove the public CA key from trusted root CAs the certs will not be trusted and will stop working as well.
- Removing a CA from a domain is something that you may need to consider carefuly before proceed.
- The additional options are: Migrate the CA to a new server (if possible a dedicated server that is not a DC), then stop issuing certs untill the expiration date comes, by doing that you'll have a CA to get those certs if needed and if you've a KRA defined.

--
I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MVP Directory Services
"Chris" <Chris@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:B8AE095B-F576-420B-A11E-08AD70D57443@xxxxxxxxxxxxxxxx
I did read through the online version of that document. I see that you can
migrate (keeping the CA name). But it doesn't discuss removing the old CA
entirely and what the impact would be. I also did not see any info about
transitiioning to an entirely new server with a new CA name. Let me know if
you think I missed something.

Chris

"Jorge Silva" wrote:

Hi
Read this
http://www.microsoft.com/downloads/details.aspx?FamilyID=C70BD7CD-9F03-484B-8C4B-279BC29A3413&displaylang=en

--
I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MVP Directory Services
"Chris" <Chris@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:1A850FDB-F48A-461D-A5E1-4AE4BA876096@xxxxxxxxxxxxxxxx
>I currently have my CA installed on my Windows 2003 x86 Domain >Controller.
>I
> want to migrate my current DC to new hardware running Windows 2008 x64.
> At
> the same time I want to migrate my CA to a different server with > Windows
> 2008
> x64. We are not concerned with any certificates that we’ve manually
> issued
> for internal websites. We haven’t done much/any manual certificate
> publishing. But, we are concerned about clients that may have
> auto-enrolled
> with certificates.
>
> If we remove the CA and all certs residing on our current DC and then
> build
> a new CA server with a different name and “start over” with certificate
> services – should we be concerned about clients experiencing issues? I
> noticed that several EFS certificates show up as being published in the
> console, what happens for the users using those certificates?


.



Relevant Pages

  • Re: EFS mixed clients and shared folders
    ... One thing to check is that the server is trusted for delegation in it's ... the server with the share that will contain the users certificate and EFS ... EFS certificates that exist for a user or RA on a computer. ... > FolderA is shared as FolderA with Domain Admins having Full Control both ...
    (microsoft.public.win2000.security)
  • Re: EFS/DRA
    ... In AD U/C I am able to see certificates in the "Published Certificates" Tab. ... would be better to go with Roaming Profiles. ... If you do not have roaming profiles, and you want to roam EFS credentials, I ... To make things easier, let's say that the file is stored on a "server", ...
    (microsoft.public.security)
  • Re: Using Certificates for 802.1x and VPN accecss
    ... The cert on the IAS server must contain the server authentication EKU and ... The machine certificates can by provisioned using auto-enrolment. ... login script that will provision the certs. ... How do I distribute the certificate to my clients? ...
    (microsoft.public.security)
  • Re: Certificate Services help
    ... server with a different name. ... DCs need certificates to talk to each other? ... aren't using certs, you should revoke all certificates and then uninstall ... Certificate Services without installing it on a different server. ...
    (microsoft.public.windows.server.general)
  • Re: wireless lan & computer certificates
    ... certificates (ie a direct user cert to user account map) rather than ... Can you definately do this with computer certs? ... (bearing in mind the ssl server is in our dmz - and not a member ...
    (microsoft.public.security)

Loading