Migrate Enterprise CA fallback

Ming Cheung 421 Reputation points
2023-03-21T06:06:28.3533333+00:00

I read some documents if the migration gets the error, I want to fallback to the original CA server,

  1. Just delete the original CA computer object in AD, it is easy to join the computer back to AD if fallback and the original CA can recover the service easily
  2. Uninstall service to clear the original CA object in AD, but when migration gets the error, it has to install back the service to recover the original CA some document suggests 2. for migration, but no good in fallback, is 1. also OK?
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,720 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 43,931 Reputation points
    2023-03-21T15:39:25.15+00:00

    Hello there,

    As one of the first steps check the integrity of the Active Directory database file ntds.dit and see if there are any corruption.

    You cannot migrate CA to another server without valid backup of all CA keys so i would suggest you to back up before the migration.

    I would double-check what certificates are stored in PFX. For example, by running certutil -dump and specify the path to a PFX file.

    Hope this resolves your Query !!

    --If the reply is helpful, please Upvote and Accept it as an answer--