Decommisioning 2003 with Directory Services/Exchange/Certificate Authority


i have server 2003 sp2 standard server used physical box. it's running exchange 2003, directory services , certificate authority. used fsmo role holder.

two server 2012 servers installed , both configured domain controllers. 1 of these took on fsmo roles.

the 2003 server virtualized p2v. then, because of snapshot rollback, server fell usn rollback state. since time, have raised it's priority level unlikely handle authentication requests logon attempts.  also, have installed new server 2003 virtual machine that's running exchange 2003 , migrated mailboxes it. have yet decommission old exchange server because i'm not sure of step take next gracefully decommission it. plan on migrating office 365, sooner better.

i want remove certificate authority , demote can turned off good.this server has been headache since inherited network year ago.

my questions are:

do need remove exchange before start messing ca?

can install new server 2012 ca or have migrate ca 2003 2012?

if can install new server 2012 ca without touching ca on 2003, have worry corruption when demote 2003 server?

vr//

brian mc

both exchange , ca must removed before allow demote properly. 1 of reasons exchange, ca or sql or other major app/service, should not installed on dc.

to remove exchange, must install exchange server in organization move mailboxes, public , system/hidden folders (which include org guid).

however, if dc exchange on won't communicate due usn rollback, new member server exchange installed, other option export ca config, export certificates, export mailboxes , public folders pst files, dump box , run metadata cleanup. way can install ca on new member server, , exchange on member server, , import mailboxes.

exchange:

you can use exmerge export in exchange 2003:
http://www.microsoft.com/downloads/details.aspx?familyid=429163ec-dcdf-47dc-96da-1c12d67327d5&displaylang=en

how use exmerge tool upgrade exchange 2000 server or exchange server 2003
http://support.microsoft.com/kb/327304

-

ca:

how manually remove enterprise windows certificate authority windows 2000/2003 domain
http://support.microsoft.com/kb/555151

how decommission windows enterprise certification authority , how remove related objects windows server 2003 , windows server 2000
http://support.microsoft.com/?id=889250

howto: move certificate authority new server running on 2003 or 2008 ca, standard or enterprise (same windows 2008 r2 , 2012)
http://directoryservicesconsulting.ca/index.php/2009/04/17/howto-move-a-certificate-authority-to-a-new-server-running-on-a-domain-controller/


ace fekay
mvp, mct, mcitp/ea, mcts windows 2008/r2 & exchange 2007, exchange 2010 ea, mcse & mcsa 2003/2000, mcsa messaging 2003
microsoft certified trainer
microsoft mvp - directory services
technical blogs & videos: http://www.delawarecountycomputerconsulting.com/

this post provided as-is no warranties or guarantees , confers no rights.

facebooktwitterlinkedin




Windows Server  >  Directory Services



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group