CA Migration Questions


i posted here plans upgrade our existing 2003 enterprise pki 2008. first part of migration 'upgrade' 2003 ent root ca 2008 (r1). completed ok, , ca online , seems working ok. remember, in place upgrade, existing settings have been inherited upgrade.

second phase backup , restore ca config old subordinate 2003 ca new 2008 (r2) ca keep same ip , hostname. questions involve following;

1. i've noticed when trying manually requesting new user or computer cert using mmc/certificates snapin xp (sp3) clients (using advanced options), you no longer option of selecting upgraded rootca. can still see 2003 subordinate, 2008 ca not listed (it available before upgrade). can tell though, still issuing certs xp clients via autoenrollment. xp clients can access 'old' web enrollment gui user certs. there reason this. role of online responder? 'upgrade', i've established hashalgorithm , provider details still running @ compatabile (legacy) levels.

2. i'm guessing 'upgrade' 2008 ca going need bit more work. the manual cert request process on 7 clients requires uri. there document on how go (assume post-upgrade 2008)

3. 2008r2 ca restore ca config backed 2003 (non-r2) ca? docs i've seen imply either need export 2003, import 2003 upgrade 2008, or upgrade 2003 ca server 2008, export ca config, restore onto 2008 host. can go direct though?

hi,

#1. don't have install online responder. mentioned in previous post, please open adsiedit.msc , check if upgraded rootca displayed in "cn=enrollment services,cn=public key services,cn=services,cn=configuration,dc="

in addition, please checking connectivity between windows xp client machine , rootca running certutil -ping -configure machine\caname on windows xp machine. 

#2. speaking, we need create enrollment policy when use certificate enrollment web service. since service not being used in environment, don't need set uri. request certificate selecting the active directory enrollment policy, default active directory domain controller uri.

#3. yes. far know, have have %systemroot% same on windows 2000 & windows 2008, c:\winnt\system32\certsrv.

 


this posting provided "as is" no warranties, , confers no rights. please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.


Windows Server  >  Security



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file