Migrate Ent Root CA to Stand Alone w/ Subordinate - Steps?


a few questions around process.  didn't seem find in migration documentation.

i have enterprise root ca i'd migrate stand alone offline root ca.  there i'd publish crl's, enable web enrollment, , issue certs online subordinate ca.

this how see being done:

  1. backup root ca database, , registry
  2. export ca root cert
  3. import ca root cert on offline ca
  4. remove adcs root ca
  5. install adcs on stand alone offline ca
  6. modify default domain policy include root cert in trusted ca's
  7. issue subca cert , export
  8. install adcs on subca, , import cert
  9. restore db/registry settings subordinate ca

do these steps correct?  want ensure devices can still auto-enroll certs, , know go them , crl's.  i'm not of correct migration steps this.  in advance assistance!

looks correct. have reconfigure cdp extension (crl files must published locally , moved target locations manually) , crl publication intervals. recommended disable delta crls @ all.

my weblog: http://en-us.sysadmins.lv
powershell pki module: http://pspki.codeplex.com
windows pki reference: on technet wiki



Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group