It is totally ok to have multiple Enterprise CAs. However, you will have to re-issue all existing certificates from new CA. But this is acceptable as well.
Enterprise PKI migration from Windows 2008 server to windows 2012/2016 ?
we are migrating all of our windows servers (windows 2008 & 2012) to new VMware environment but Domain controllers can't be migrated over to new VMware.
This windows 2008 server domain controller is having a role of enterprise PKI for Active Directory certificate services . I can't migrate 2008 DC over to VMware server due to known issues with P2V (VMware conversion tool) as after conversion DC won't be fully functional and therefore I am forced to built a brand new windows 2012/2016 server. Enterprise PKI is used for our wireless and radius authentication. Can I install new PKI on a new 2012 DC, I mean can two Enterprise PKI exist under one AD forest for some time until I retire win 2008 or am I forced to migrate old PKI over to newly built windows 2012/2016 domain controller ?
What's the best approach please ?