Can you convert a root CA Enterprise server to a standalone offline root CA?

AnnaG 161 Reputation points
2024-03-14T09:47:46.0866667+00:00

Hello all,

Can you convert a root CA Enterprise server to a standalone offline root CA or do you have to build another PKI server in parallel and do it that way? If the latter applies, can you provide a quick summary of steps to ensure no outage?

Thanks in advance

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,726 questions
0 comments No comments
{count} votes

Accepted answer
  1. Marcin Policht 39,685 Reputation points MVP
    2024-03-14T10:05:28.0966667+00:00

    In short, you cannot.

    You have to rebuild the CA and reissue all certs

    For the migration guidance, refer to https://isinghblog.wordpress.com/2008/06/03/migrating-microsoft-enterprise-root-ca-to-an-offline-root-ca-hierarchy/


    hth

    Marcin

    1 person found this answer helpful.
    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Thameur-BOURBITA 36,226 Reputation points
    2024-03-14T10:37:57.3+00:00

    Hi @AnnaG

    Unfortunately it's not possible .You have to rebuild new one and be sure that you recreate from new CA all certificates generated by the old CAR before decommission it. You should start by make a audit to identify all certificates generated by old CA.

    Please don't forget to accept helpful answer

    0 comments No comments

  2. AnnaG 161 Reputation points
    2024-03-15T23:16:00.81+00:00

    Thank you both!

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.