Can you convert a root CA Enterprise server to a standalone offline root CA?

AnnaG 111 Reputation points
2024-03-14T09:47:46.0866667+00:00

Hello all,

Can you convert a root CA Enterprise server to a standalone offline root CA or do you have to build another PKI server in parallel and do it that way? If the latter applies, can you provide a quick summary of steps to ensure no outage?

Thanks in advance

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,092 questions
0 comments No comments
{count} votes

2 additional answers

Sort by: Most helpful
  1. Thameur-BOURBITA 32,496 Reputation points
    2024-03-14T10:37:57.3+00:00

    Hi @AnnaG

    Unfortunately it's not possible .You have to rebuild new one and be sure that you recreate from new CA all certificates generated by the old CAR before decommission it. You should start by make a audit to identify all certificates generated by old CA.

    Please don't forget to accept helpful answer

    0 comments No comments

  2. AnnaG 111 Reputation points
    2024-03-15T23:16:00.81+00:00

    Thank you both!

    0 comments No comments