Move to new CA

Ivarious 1 Reputation point
2021-10-14T06:05:45.52+00:00

Hi,

We have a Certificate Authority that we would like to migrate. Current OS: Windows Server 2012R2
Would like to migrate the CA to the new VM with Windows Server 2019. But with the export of the CA we have following error: 'Windows cannot back up one or more private keys because the CSP does niet support key export".

The certs are only issued to clients and servers. (Computer (machine), Domain Controller Authentication, Kerberos Authentication)

  • I installed the CA role on the new Server 2019 machine and configured a new root CA.
  • I removed the certificate templates from the old CA server.

I see that new clients are getting the certs from the new CA server. Is there a way where we can force the clients with certs from the old CA to renew this so they receive also a new cert from the new CA? Or do we simply need to wait when the old certs are expired?

Would like to know when we can fully uninstall the old cert server.

Thanks in advance!

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,732 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 39,396 Reputation points
    2021-10-15T09:39:16.173+00:00

    Hi there,

    If clients are using v2 or newer templates, this can be done at the template level. But doing this will trigger all clients to renew early. In the GPO setting where you enabled Auto-Enrollment, did you also check the optional box "Upgrade certificates that use templates"? If so, then in the certtmpl.msc interface, right-click the template you want clients to renew, and select "Reenroll all existing certificate holders".

    Make sure the template is only available on the new CA (removed from the old) otherwise the enrollment will randomly choose the CAs to use.

    You can also follow the steps as per the thread https://social.technet.microsoft.com/Forums/en-US/23a990ed-6c07-4948-acf1-54aaca82e2d1/force-windows-machines-to-reenroll?forum=winserversecurity


    If the reply is helpful, please Upvote and Accept it as an answer