Decommissioning CA - will removing role delete Trusted Root Certificate and Trusted Intermediate Certificates?

Gregg Hughes 291 Reputation points
2021-04-02T14:35:57.52+00:00

Good morning, all!

I'm nearing the end of decommissioning an old Enterprise CA in favor of a new two-tier infrastructure. Question: if I uninstall the role from the old CA server, does that automagically delete the old CA certificates from Trusted Root Certificates and Trusted Intermediate Certificates in all domain certificate stores? Or will I still have the old certs in the Trusted stores to clean up as needed?

The autoenroll certificates have already been replaced, will manually-enrolled certificates remain in the Personal store after decommissioning the CA that issued them?

Thanks!

Windows for business | Windows Server | Devices and deployment | Configure application groups
{count} votes

Accepted answer
  1. Anonymous
    2021-04-06T06:39:27.55+00:00

    Hi,
    I completed the remove operation.
    As you mentioned the root certificate on the DC in both the Trusted Root Certificate and Trusted Intermediate Certificates will be removed.

    The root certificates on the domain member in the Trusted Intermediate Certificates will be removed too, but certificate in the Trusted Root Certificate will be kept.(Only the first CA certificate will be kept, if you renewed the ca and have some renewed CA certificates , they will be removed.)

    Best Regards,


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.