Old CA Certificate and Old CA server

Namless Shelter 216 Reputation points
2021-10-22T03:48:45.907+00:00

Hi There,

Just need help on this.

I have joined this organisation three years ago.

Last school holiday, we upgraded CA server successfully. Now on windows machine, I noticed that there are two enterprise CA certificates existed on MMC. One is the current "CA01-CA", which will expire on 2040. Also, I noticed there is another certificate "EX02-CA", which expire 25 Nov. With certificate template attribute, it is labelled as "Root Certificate Authority"..I am really confused as ex02 was our old Exchange 2010 server, which were powered off last year....If we use this CA, devices wont be able to authenticate successfully...Should I worry about this Ex02-CA certificate, which will expire soon??

also, I checked, under Active Directory Sites and Services, there are two certificate authorities CA01 and Ex02, two CDPs, two enrolment services, etc..

Thanks a lot for help
ML

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,730 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Vadims Podāns 9,111 Reputation points MVP
    2021-10-22T09:17:33.017+00:00

    You need to decommission old CA as per this guide: https://social.technet.microsoft.com/wiki/contents/articles/3527.how-to-decommission-a-windows-enterprise-certification-authority-and-how-to-remove-all-related-objects.aspx

    Since server is no longer presented on a network, you can skip steps 1-5 and complete only steps 6 and 7. Most likely, you don't need to complete other steps.