Hello Tommy Az,
Thank you for posting in Q&A forum.
We cannot migrate AD Certificate Services from Windows Server 2008 to Windows Server 2016, because the JET database engine changed so much between the two versions that if we restore the backup we get a JET version error at startup and the CA won't start. So we cannot migrate ADCS from Windows Server 2016 to Windows Server 2008.
If you cannot migrate AD CS from 2016 to 2012 R2 in your lab or in your production environment, maybe it is.
https://social.technet.microsoft.com/wiki/contents/articles/37373.migrating-ad-certificate-services-from-windows-server-2008-to-windows-server-2016.aspx
We all migrate AD CS from lower version to higher version, but why did you want to Migrate AD CS to an older version from higher version?
Check if you select SHA1 (or SHA256) during migration on both lower version and higher version.
Check if you select CSP (or KSP) during migration on both lower version and higher version.
https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/dn771627(v=ws.11)?redirectedfrom=MSDN
If you have any question or concern, please feel free to let us know.
Best Regards,
Daisy Zhou