About the impact of stopping the AD CS server.

QX0232176 41 Reputation points
2021-07-28T10:24:17.737+00:00

I want to migrate my AD CS server to another environment.

There is only one AD CS server. (Enterprise CA)
AD CS functionality is not on the AD server.
(The AD server and AD CS server are separate environments. )

The AD CS server will be stopped during the migration, so I would like to confirm the impact of that.
Is it okay to recognize that client PCs and servers that already have the certificate installed will not be affected if the AD CS server is down?

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,836 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Hannah Xiong 6,276 Reputation points
    2021-07-29T02:33:37.55+00:00

    Hello @QX0232176 ,

    Thank you so much for posting here.

    During the migration of CA, it is important to remove the CA role service from the source server after completing backup procedures and before installing the CA role service on the destination server. If you choose not to remove the CA role service from the source server before installing the CA role service on the destination server, it is important that you disable the Active Directory Certificate Services service (Certsvc) and shut down the source server before installing the CA role service on the destination server.

    I am not sure but based on my experience, there will be some impact if we do the migration during the working time. It is suggested that the migration should be done during the non-working time to reduce or avoid any impact.

    Reference: https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/ee126140(v=ws.10)#BKMK_GrantPermsAIA

    Best regards,
    Hannah Xiong

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.