Re: Certificate Services help



=?Utf-8?B?TmV0IEFkbWlu?= <NetAdmin@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
news:10AAEAD6-44AF-4CE3-B970-7EAC070ACF99@xxxxxxxxxxxxx:

I have a server (a DC) in my 2003 forest that has certificate services
installed. I would like to move the whole service over to another
server with a different name. Is that possible? All articles I've read
state that the new server must use the same name as the old one but I
want to keep the old server online. I don't even know what we need
this service for because we don't use certificates in our forest. Do
DCs need certificates to talk to each other?
Our web server uses a 3rd party CA.
The only certificates listed under "Issued Certificates" are Domain
Controllers, and not all DCs are listed.
Thanks in advance for any help with this.



This is a pretty complex issue, because the first thing you need to know is
why someone installed the CA in the first place. If you are not using
certificates for any reason, there is no reason to have a CA; so IF you
aren't using certs, you should revoke all certificates and then uninstall
Certificate Services without installing it on a different server. (When you
install Cert Svcs it automatically issues certs to DCs and installs its
cert in the Trusted Root Certification Authorities store on all domain
member computers.)

But the first step is to find out for sure what you are using the CA for
(email certs, remote access with EAP or PEAP, code signing...???), if
anything.

--
James McIllece, Microsoft

Please do not send email directly to this alias. This is my online account
name for newsgroup participation only.

This posting is provided "AS IS" with no warranties, and confers no rights.
.



Relevant Pages

  • Re: Using Certificates for 802.1x and VPN accecss
    ... The cert on the IAS server must contain the server authentication EKU and ... The machine certificates can by provisioned using auto-enrolment. ... login script that will provision the certs. ... How do I distribute the certificate to my clients? ...
    (microsoft.public.security)
  • Re: wireless lan & computer certificates
    ... certificates (ie a direct user cert to user account map) rather than ... Can you definately do this with computer certs? ... (bearing in mind the ssl server is in our dmz - and not a member ...
    (microsoft.public.security)
  • Re: Certificate Services
    ... > Authority is well secured meaning physically and that administrator access ... > to the server is closely controlled. ... > users/computers can obtain certificates by configuring security permissions ... If so what are the best steps of precaution when installing ...
    (microsoft.public.security)
  • Re: Multiple certificates
    ... Is this just for when your Sendmail instance is acting as a server ... The problem is how do we create the certificates so that both organsiations ... The client and server certs that your Sendmail uses need to be signed by ...
    (comp.mail.sendmail)
  • Re: Certificate Server s Versign, Thawte Certificates
    ... Verisign certs, like $120 / year [even though Entrust is now owned by ... Verisign, and the certs are linked / trusted up the chain to Verisign]. ... Using a Microsoft cert server could probably save you money, ... > generate certificates in-house instead of constantly ...
    (microsoft.public.inetserver.iis.security)