rename-old-2008r2-dc-and-give-new-2016-dc-the-old-ones-name-certificate

Daisy Zhou 25,296 Reputation points Microsoft Vendor
2020-07-15T05:34:25.96+00:00

Hello,
I am planning to upgrade a domain that has DCs running 2008R2 to 2016 this weekend. One of the DCs has an TLS /SSL certificate and I want to keep using this cert that has the FQDN of the old DC on one of the new 2016 DCs. My plan is to rename the old DC from DC1 to DC1_OLD (using netdom, as outlined in the link below) and rename the 2016 machine to DC1 and promote it, and then install the certificate I exported. My question is if I use this process with I have problems with duplicate SPNs or any other things, because I am reusing the old name on a new machine. So in summary:

1.) export DC1 cert on 2008R2 machine
2.) rename the 2008R2 DC from DC1 to DC1_OLD
3.) rename new server to DC1 & Promote it to be a DC
4.) install exported cert on the new 2016 DC1

https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc816601(v=ws.10)?redirectedfrom=MSDN

Source link:
https://social.technet.microsoft.com/Forums/windowsserver/en-US/846d1f8f-97ee-45f7-be92-fe38cae41579/rename-old-2008r2-dc-and-give-new-2016-dc-the-old-ones-name-amp-certificate?forum=winserverDS

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,655 questions
0 comments No comments
{count} votes

Accepted answer
  1. Fan Fan 15,341 Reputation points Microsoft Vendor
    2020-07-15T05:47:54.847+00:00

    Hello,
    Thank you for posting here.

    Q: My question is if I use this process with I have problems with duplicate SPNs or any other things, because I am reusing the old name on a new machine.
    A: Yes, we can do as you described.

    In our case, we can try the rename ad DC according to the following article.

    Rename a Domain Controller Using Netdom
    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc816601(v=ws.10)?redirectedfrom=MSDN

    But because we need to reuse the old name on a new machine. We can see the message from the above link.

    12325-7156.png

    We also need to update the FRS or DFS replication member object according to the following link.

    Update the FRS or DFS Replication Member Object
    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc794759%28v%3dws.10%29

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.