Decommissioning a CA




Hi,

Not sure if this is the right place but will ask it here

I have a Windows 2000 Server which is a DC and also the CA for a domain. It
is time to decommission 2000 server and convert it to a 2003 bigger/better
box.

I cannot un-dcpromo the 2000 box because the CA is there.

The CA was originally installed to give out computer certs when we thought
that we were going to deploy an 802.1x cert based wireless system. That did
not happen but the CA stayed in place. Now the CA has given out lots of
computer certs but it has not been used for anything else.

What are the implications of removing the CA? I understand that the certs
will no longer be valid but will anything break? How can I check? Anything
special to do before killing the CA?

Thanks
Goran
.



Relevant Pages

  • Re: Decommissioning a CA
    ... Marc [MCSE, MCTS, MVP] ... [Blog: http://www.marc-antho-etc.net/blog/] ... I have a Windows 2000 Server which is a DC and also the CA for a domain. ... The CA was originally installed to give out computer certs when we thought ...
    (microsoft.public.windows.server.general)
  • How to migrate CA to New DC
    ... I have a very similar situation to the other poster, ... I am decomissioning the server that one of our issuing CA's resides on. ... We use the computer certs for 802.1X ... so I don't want any interruption in service, etc. SERVERA is a Windows ...
    (microsoft.public.windows.server.migration)
  • RE: How to migrate CA to New DC
    ... a CA from a server that is running Windows 2000 Server to a server that is ... >>I am decomissioning the server that one of our issuing CA's resides on. ... We use the computer certs for 802.1X ...
    (microsoft.public.windows.server.migration)
  • Evolution POP - deleting messages when emptying trash.
    ... this is stopping me from killing my windows PC for good. ... I am trying to use evolution, but I have POP mail only from several sources. ... I can leave mail on server ...
    (Fedora)
  • Re: Automatic enrollment of user certificates
    ... > Windows 2000 AD. ... > user certificates on a client machine. ... > possible to do this for computer certs via a GPO. ...
    (microsoft.public.win2000.security)