New Root CA server cannot deploy root certificate to domain client

Chong 846 Reputation points
2022-05-19T08:50:11.367+00:00

Hi,

We have a old Win 2008 CA server and we just setup a new Windows 2019 root CA server (standalone, domain joint) and found new root CA cannot deploy root certificate to domain client automatically.

After some checking, seems AD only can auto deploy the root certificate from Win2008 CA, but the new Win2019 CA cannot. Do the AD recognize the old Win2008 CA is the "primary CA", so the other root CA cannot auto deploy their root certificate?

I know we can use GPO to deploy root certificate. But as we will remove that Win2008 CA later, how to change the "Primary CA" to the new CA?

Thanks

Best Regards
Chong

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,200 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Gary Reynolds 9,391 Reputation points
    2022-05-19T11:18:14.13+00:00

    Hi @Chong

    You have used two contradicting terms to define your new CA, it can be a standalone or domain (enterprise), but not both. If it's a standalone root CA, then you will need to publish the root certificate in the AD using the certutil -dspublish command.

    Gary.