Migrate Ent Root CA to Stand Alone w/ Subordinate - Steps?
a few questions around process. didn't seem find in migration documentation.
i have enterprise root ca i'd migrate stand alone offline root ca. there i'd publish crl's, enable web enrollment, , issue certs online subordinate ca.
this how see being done:
- backup root ca database, , registry
- export ca root cert
- import ca root cert on offline ca
- remove adcs root ca
- install adcs on stand alone offline ca
- modify default domain policy include root cert in trusted ca's
- issue subca cert , export
- install adcs on subca, , import cert
- restore db/registry settings subordinate ca
do these steps correct? want ensure devices can still auto-enroll certs, , know go them , crl's. i'm not of correct migration steps this. in advance assistance!
my weblog: http://en-us.sysadmins.lv
powershell pki module: http://pspki.codeplex.com
windows pki reference: on technet wiki
Windows Server > Security
Comments
Post a Comment