Hi,
Thank you for posting the question to the Q&A forum.
First yes it's possible and it should work without any problem about how to proceed this is a really good guide about it : https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-migrating-active-directory-certificate-service-from/ba-p/2328766
Additional I would share this link also with you: https://social.technet.microsoft.com/Forums/en-US/22443b56-0845-459a-b1cf-339b684f8f90/2008-r2-certificate-authority-in-place-upgrade-to-2012-r2?forum=winserversecurity
I hope the above information can help you.
****If the ANSWER is helpful, please click "Accept Answer" and upvote it. Thanks****
i don't understand, the order is: 1. upgrade the ad from 2008 to 2012 2. inplace upgrade windows server 2008 to 2012 where the CA? right?