In short, you cannot.
You have to rebuild the CA and reissue all certs
For the migration guidance, refer to https://isinghblog.wordpress.com/2008/06/03/migrating-microsoft-enterprise-root-ca-to-an-offline-root-ca-hierarchy/
hth
Marcin
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hello all,
Can you convert a root CA Enterprise server to a standalone offline root CA or do you have to build another PKI server in parallel and do it that way? If the latter applies, can you provide a quick summary of steps to ensure no outage?
Thanks in advance
In short, you cannot.
You have to rebuild the CA and reissue all certs
For the migration guidance, refer to https://isinghblog.wordpress.com/2008/06/03/migrating-microsoft-enterprise-root-ca-to-an-offline-root-ca-hierarchy/
hth
Marcin
Hi @AnnaG •
Unfortunately it's not possible .You have to rebuild new one and be sure that you recreate from new CA all certificates generated by the old CAR before decommission it. You should start by make a audit to identify all certificates generated by old CA.
Please don't forget to accept helpful answer