Hello @Namless Shelter
the answer for the first question is:
Service migration from 2008 R2 to 2019 but required the new Windows Server 2019 server to have the same name as the previous 2008 R2 server
Regards,
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hi there,
Please help with this.
Basically, we are running CA service (only CA server running ROOT CA Enterprise) on a server 2012 box. Now we need to move CA to 2019 BOX. I had a look in this article: https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-migrating-the-active-directory-certificate-service/ba-p/697674
Got Four simple questions:
Thanks a lot,
ML
Hello @Namless Shelter
the answer for the first question is:
Service migration from 2008 R2 to 2019 but required the new Windows Server 2019 server to have the same name as the previous 2008 R2 server
Regards,
Follow this documents for the migration steps... even if it's 2012, it's the same process
ref: https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn486805(v%3Dws.11)
hth
The CDP / AIA location is where the CRT / CRL are published. By default, an Enterprise CA will published into AD. But you ma have change this value.
You can see this value if you open a certificate that has been issued by your CA.
Look for the 2 settings "Authority Information Access" and "CRL Distribution Point". You should have the location of those files.
On the CA, those settings are registry values under that registry key
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration[CA Name]"
CACertPublicationURLs
CRLPublicationURLs
As i said, if it's published at the default location (AD), you should be good. Just check that the CRL is valid for long enough to complete the migration.
hth
Hi,
There is a documentation on how to decommission an Enterprise CA