Can you convert a root CA Enterprise server to a standalone offline root CA?

AnnaG 166 Reputation points
2024-03-14T09:47:46.0866667+00:00

Hello all,

Can you convert a root CA Enterprise server to a standalone offline root CA or do you have to build another PKI server in parallel and do it that way? If the latter applies, can you provide a quick summary of steps to ensure no outage?

Thanks in advance

Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

Accepted answer
  1. Marcin Policht 51,370 Reputation points MVP Volunteer Moderator
    2024-03-14T10:05:28.0966667+00:00

    In short, you cannot.

    You have to rebuild the CA and reissue all certs

    For the migration guidance, refer to https://isinghblog.wordpress.com/2008/06/03/migrating-microsoft-enterprise-root-ca-to-an-offline-root-ca-hierarchy/


    hth

    Marcin

    1 person found this answer helpful.
    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Thameur-BOURBITA 36,266 Reputation points Moderator
    2024-03-14T10:37:57.3+00:00

    Hi @AnnaG

    Unfortunately it's not possible .You have to rebuild new one and be sure that you recreate from new CA all certificates generated by the old CAR before decommission it. You should start by make a audit to identify all certificates generated by old CA.

    Please don't forget to accept helpful answer

    0 comments No comments

  2. AnnaG 166 Reputation points
    2024-03-15T23:16:00.81+00:00

    Thank you both!

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.