Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Moving a Windows 2003 Standalone CA?

Thread Tools
 
Search this Thread
 
Old 30 July 2008, 08:50 PM
  #1  
Andy Tang
Scooby Regular
Thread Starter
iTrader: (3)
 
Andy Tang's Avatar
 
Join Date: Dec 1999
Location: UK
Posts: 13,274
Likes: 0
Received 0 Likes on 0 Posts
Default Moving a Windows 2003 Standalone CA?

I know people say you can't or shouldn't, but I'm stuck with a job where this needs to be done.

There is this Microsoft article: How to move a certification authority to another server, but does anyone have any real world experience of this.

The original server is a standalone CA on a Windows 2003 Standard Edition server, which was a member of the domain, but located in the DMZ with access back to the LAN.

The replacement server will be a standalone CA on a Windows 2003 R2 Standard Edition server, which will be a member of the domain on the LAN.

We have tried to move it already, but the existing certificates which have already been issued and have not expired or been revoked, are unable to be recognised by the new server. There seems to be an issue with the key that is generating the new certificates, which seems to be different.

Does anyone have any bright ideas (other than retry the article again and hope it was a glitch, which will be doen first thing tomorrow)?

Cheers
Andy
Old 30 July 2008, 09:38 PM
  #2  
Hanley
Scooby Regular
 
Hanley's Avatar
 
Join Date: May 2002
Location: Liverpool
Posts: 3,229
Likes: 0
Received 0 Likes on 0 Posts
Default

Wouldn't you be better decommissioning your existing CA - MS doc here and then installing your new CA??
Old 30 July 2008, 09:43 PM
  #3  
Andy Tang
Scooby Regular
Thread Starter
iTrader: (3)
 
Andy Tang's Avatar
 
Join Date: Dec 1999
Location: UK
Posts: 13,274
Likes: 0
Received 0 Likes on 0 Posts
Default

Thanks for digging that out Hanley!

We have been told catergorically that we can not reissue or revoke any certificates, as the general user population is not IT-savvy.

I'll suggest it, but I suspect I already know the answer
Old 30 July 2008, 09:48 PM
  #4  
Hanley
Scooby Regular
 
Hanley's Avatar
 
Join Date: May 2002
Location: Liverpool
Posts: 3,229
Likes: 0
Received 0 Likes on 0 Posts
Default

In that case I'd suggest following the guide again.....possibly raising a PSS with MS if it contiues to fail.

Good luck.

Old 30 July 2008, 10:19 PM
  #5  
Andy Tang
Scooby Regular
Thread Starter
iTrader: (3)
 
Andy Tang's Avatar
 
Join Date: Dec 1999
Location: UK
Posts: 13,274
Likes: 0
Received 0 Likes on 0 Posts
Default

Cheers!
Old 31 July 2008, 08:39 PM
  #6  
Andy Tang
Scooby Regular
Thread Starter
iTrader: (3)
 
Andy Tang's Avatar
 
Join Date: Dec 1999
Location: UK
Posts: 13,274
Likes: 0
Received 0 Likes on 0 Posts
Default

We tried it again today and it was spot on!

Only issue is that certificates being issued would work on XP, but not on Vista, as the web enrolment tool keeps saying loading activex

We have since found this: How to use Certificate Services Web enrollment pages together with Windows Vista or Windows Server 2008 which resolved that issue.

We then had issues with certificates issued to Vista machines would not work (even though on XP machine with the same process, it would work) It turns out that the CA is issuing 1024 bit certificates (which work on XP, but not Vista). The root certificate is correct, and the certificates are installed correctly on both XP and Vista in the same locations.

Using the advanced features within the web enrolment tool and selecting 2048 bit certificates for the Vista machines, and it works fine!

It was a long day today, but I have learnt so much!!!
Old 31 July 2008, 09:28 PM
  #7  
Hanley
Scooby Regular
 
Hanley's Avatar
 
Join Date: May 2002
Location: Liverpool
Posts: 3,229
Likes: 0
Received 0 Likes on 0 Posts
Default

Cool, we're evaluating Vista and 2008 now so I better read that doc

Glad you got it sorted though

Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
KAS35RSTI
Subaru
27
04 November 2021 07:12 PM
hardcoreimpreza
Computer & Technology Related
21
11 October 2015 03:40 PM
FuZzBoM
Wheels, Tyres & Brakes
16
04 October 2015 09:49 PM
Ganz1983
Subaru
5
02 October 2015 09:22 AM
shorty87
Other Marques
0
25 September 2015 08:52 PM



Quick Reply: Moving a Windows 2003 Standalone CA?



All times are GMT +1. The time now is 04:28 AM.