Share via

Can you convert a root CA Enterprise server to a standalone offline root CA?

AnnaG 166 Reputation points
2024-03-14T09:47:46.0866667+00:00

Hello all,

Can you convert a root CA Enterprise server to a standalone offline root CA or do you have to build another PKI server in parallel and do it that way? If the latter applies, can you provide a quick summary of steps to ensure no outage?

Thanks in advance

Windows for business | Windows Server | User experience | Other
0 comments No comments

Answer accepted by question author

Marcin Policht 90,315 Reputation points MVP Volunteer Moderator
2024-03-14T10:05:28.0966667+00:00

In short, you cannot.

You have to rebuild the CA and reissue all certs

For the migration guidance, refer to https://isinghblog.wordpress.com/2008/06/03/migrating-microsoft-enterprise-root-ca-to-an-offline-root-ca-hierarchy/


hth

Marcin

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Thameur-BOURBITA 36,526 Reputation points Moderator
    2024-03-14T10:37:57.3+00:00

    Hi @AnnaG

    Unfortunately it's not possible .You have to rebuild new one and be sure that you recreate from new CA all certificates generated by the old CAR before decommission it. You should start by make a audit to identify all certificates generated by old CA.

    Please don't forget to accept helpful answer

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

  2. AnnaG 166 Reputation points
    2024-03-15T23:16:00.81+00:00

    Thank you both!

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.