Hi,
We have today one CA server, and that role is installed on the domain controller :(, its running windows server 2012 r2 datacenter.
Its used for user, computer and nps certificate, mainly used for Wifi and VPN.
We have installed a new virtual machine that is windows server 2022 standard and we would like to move the CA role over to this machine.
The new machine will not have the same IP or hostname, guess that should not be a problem ?
I have looked at some guides, for example
https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-migrating-the-active-directory-certificate-service/ba-p/697674
https://www.petenetlive.com/KB/Article/0001473
One thing here is that both of them uninstall the old CA, what I would like to do is to stop the CA service, and if the migration fails, then roll back to start the service again. Is that possible, or would that cause problems ? If I see the new CA server is running fine, I will offcourse uninstall the CA role on the old server.
I guess I could also do a snapshot, but since the CA role is on the domain controller, I would not like to revert back, or restore any backup.
Is there any known issues importing the private key from old CA - windows server 2012 r2 to CA - windows server 2022 ?
Is there any known issues importing the database or registry key from old CA - windows server 2012 r2 to CA - windows server 2022 ?
Is the Windows Server 2012 R2 CA database is compatible with Windows Server 2022 CA ?
I also see that we need to Reissue Certificate Templates, does this mean that every machine will need to get new certificates ? Please explain a bit around this
On other thing, the CA certificate .....The Signature hash algorithm say sha256, but the thumbprint algorithm say sha1 will this be an issue ?
Comments?
Thanks for any reply, have not done a CA migration before so any comments are good :)
/R
Andy