Demoting a Domain Controller with a CA on it


i inherited network.  servers run 2003 @ 2000 sp2 functional level.

i have domain controller wish demote to a member server.  hosts our sql server backend , there no reason a dc.  

here's problem.  the dc in quiestion hosts certificate authority.  have small network , don't have need certificates.  time i've found use 1 when log onto our firewall; shut down for week , no 1 missed it.

can remove ca, demote dc, , resintall ca?  i've gathered it's better ca's on non dc servers.

thanks.

 

hi,

 

to demote domain controller hosting certificate authority, need perform following steps:

 

1.    backup ca.

2.    uninstall ca.

3.    demote dc.

4.    install ca backup.

 

i’ve included following articles reference:

 

back certification authority

http://technet.microsoft.com/en-us/library/cc737405.aspx

 

howto: move certificate authority new server running on domain controller.

http://support.microsoft.com/kb/555012

 

how move certification authority server

http://support.microsoft.com/?id=298138

 

performing upgrade or migration

http://technet.microsoft.com/en-us/library/cc742388.aspx



Windows Server  >  Setup Deployment



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group