migrate adcs from 2012 to 2019

eg1995 1,156 Reputation points
2021-01-26T13:10:16.02+00:00

dears,

ill need your advise on how to proceed with migrating my adcs from 2012 to 2019.
i found many blogs explaining that it will be done using backuo/restore.
but i have 2 questions:

the first one: what should i change if i want ti change the server name of the new adcs after demoting the first one
the second one: i can see that after we backup the db, we are uninstalling the role before installing it on the new server. during this time we wont have a downtime? aw we will be running currently without and adcs? can you advise on this point and we can do to increase the duration time of the certiifcate?

thank you in advance

Windows for business | Windows Server | Devices and deployment | Configure application groups
{count} votes

3 answers

Sort by: Most helpful
  1. eg1995 1,156 Reputation points
    2021-01-26T13:58:57.137+00:00

    thanks for the answer
    but the question is related to adcs ( certificate services) and not adds

    thanks in advance

    0 comments No comments

  2. Vadims Podāns 9,186 Reputation points MVP
    2021-01-26T15:12:28.823+00:00

    You must follow official ADCS Migration Guide. It is the only correct and supported way to do this.

    what should i change if i want ti change the server name of the new adcs after demoting the first one

    migration guide covers changes you need to perform if target server uses different host name.

    during this time we wont have a downtime?

    you will have a downtime. No certificates, nor CRLs can be signed during migration. It is advised to extend CRL validity prior to demoting old CA to allow clients to validate existing certificates. It is recommended to disable Delta CRLs during transition as well. Go to Revoked Certificates node in CA console, select properties, uncheck Delta CRLs, adjust Base CRL validity (make it 1week at least) and then publish CRLs. Then you can start migration process.

    0 comments No comments

  3. Anonymous
    2021-01-27T01:40:17.757+00:00

    Hello,

    Thank you so much for posting here.

    Thanks so much for the provided information.

    For more information about AD CS migration, we could refer to the below article.
    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc742388(v=ws.10)?redirectedfrom=MSDN

    Best regards,
    Hannah Xiong

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.