Directory email replication certificate.

Raul Guchinife 140 Reputation points
2023-08-21T07:29:37.7166667+00:00

I am going to remove a CA Enterprise server to install a new one. On this CA server I have several templates in use such as the directory email replication certificate. In order for the DC servers to use this new CA certificate, what do I have to do

Thanks

Windows for business | Windows Server | Devices and deployment | Set up, install, or upgrade
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Anonymous
    2023-09-19T06:01:29.29+00:00

    Hello Raul Guchinife,

    Thank you for posting in Q&A forum.

    Q: I am going to remove a CA Enterprise server to install a new one.
    A: Why are you going to remove a CA Enterprise server to install a new one? Did you want to migrate CA server from lower OS to higher OS? If so, you can migrate CA from old CA server to new server.

    1.Certificate Templates are stored in AD Configuration Partition on Domain Controllers.

    2.Here are migration steps below (similar steps for different CA server versions).
    Step-By-Step: Migrating The Active Directory Certificate Service From Windows Server 2008 R2 to 2019
    https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-migrating-the-active-directory-certificate-service/bc-p/700730#M270%3FWT.mc_id=ITOPSTALK-blog-abartolo

    3.Note: For CA migration, you can use the same host name or different host name, but the CA name must be the same.

    4.After that, reissue new certificate to Domain Controller using Directory email replication certificate template you mentioned with new CA server.

    5.If you need, reissue all the certificates that issued by old CA using new CA server.

    Another method:

    1.You can also have two CA servers (the old one and the new one you will install).

    2.Reissue new certificate to Domain Controller using Directory email replication certificate template you mentioned with new CA server.

    3.If you need, reissue all the certificates that issued by old CA using new CA server.

    4.Decommission old Windows enterprise certification authority, but keep all the certificate templates (because certificate templates are stored in AD Configuration Partition on Domain Controllers).

    How to decommission a Windows enterprise certification authority and remove all related objects

    https://learn.microsoft.com/en-GB/troubleshoot/windows-server/windows-security/decommission-enterprise-certification-authority-and-remove-objects

    Hope the information above is helpful.

    If you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    ==========================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

  2. J2L 0 Reputation points
    2023-12-08T20:52:43.9633333+00:00

    My understanding is that the certificates created from the template "Directory Email Replication Certificate" are useless for a domain controller if you do not use SMTP protocol to replicate AD between domain controllers.

    For me you can disable the template "Directory Email Replication Certificate" if you use RPC as protocol to replicate AD.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.