Directory email replication certificate.

Raul Guchinife 100 Reputation points
2023-08-21T07:29:37.7166667+00:00

I am going to remove a CA Enterprise server to install a new one. On this CA server I have several templates in use such as the directory email replication certificate. In order for the DC servers to use this new CA certificate, what do I have to do

Thanks

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,501 questions
Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,400 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,272 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,745 questions
Windows Server Infrastructure
Windows Server Infrastructure
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Infrastructure: A Microsoft solution area focused on providing organizations with a cloud solution that supports their real-world needs and meets evolving regulatory requirements.
518 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Daisy Zhou 19,196 Reputation points Microsoft Vendor
    2023-09-19T06:01:29.29+00:00

    Hello Raul Guchinife,

    Thank you for posting in Q&A forum.

    Q: I am going to remove a CA Enterprise server to install a new one.
    A: Why are you going to remove a CA Enterprise server to install a new one? Did you want to migrate CA server from lower OS to higher OS? If so, you can migrate CA from old CA server to new server.

    1.Certificate Templates are stored in AD Configuration Partition on Domain Controllers.

    2.Here are migration steps below (similar steps for different CA server versions).
    Step-By-Step: Migrating The Active Directory Certificate Service From Windows Server 2008 R2 to 2019
    https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-migrating-the-active-directory-certificate-service/bc-p/700730#M270%3FWT.mc_id=ITOPSTALK-blog-abartolo

    3.Note: For CA migration, you can use the same host name or different host name, but the CA name must be the same.

    4.After that, reissue new certificate to Domain Controller using Directory email replication certificate template you mentioned with new CA server.

    5.If you need, reissue all the certificates that issued by old CA using new CA server.

    Another method:

    1.You can also have two CA servers (the old one and the new one you will install).

    2.Reissue new certificate to Domain Controller using Directory email replication certificate template you mentioned with new CA server.

    3.If you need, reissue all the certificates that issued by old CA using new CA server.

    4.Decommission old Windows enterprise certification authority, but keep all the certificate templates (because certificate templates are stored in AD Configuration Partition on Domain Controllers).

    How to decommission a Windows enterprise certification authority and remove all related objects

    https://learn.microsoft.com/en-GB/troubleshoot/windows-server/windows-security/decommission-enterprise-certification-authority-and-remove-objects

    Hope the information above is helpful.

    If you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    ==========================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

  2. J2L 0 Reputation points
    2023-12-08T20:52:43.9633333+00:00

    My understanding is that the certificates created from the template "Directory Email Replication Certificate" are useless for a domain controller if you do not use SMTP protocol to replicate AD between domain controllers.

    For me you can disable the template "Directory Email Replication Certificate" if you use RPC as protocol to replicate AD.

    0 comments No comments