Migrating CA but CA role was already on new server. Whats the worst that can happen?

Here's a little background for this migration.
Old environment was SBS 2008. Everything baked into one server.
New environment we are migrating to is Server 2012 R2. Will have 8 different 2012 r2 VMs varied by roles. Since this is a small network we are putting the CA on the DC (Called NewDC1).
NewDC1 was configured to mirror the old servers Active Directory, etc. BUT NewDC1 when installed was given the AD CS role as well. From everything I've read it says to backup all settings on the old CA, decommission the old server then install the ADCS
role on the new one and restore the backed up files.
BUT since we already have the ADCS role on the new DC. Should I go ahead and uninstall it. Proceed with the steps to backup and uninstall the exchange server role on the old(not decommission the server since we still need it up to decommission the dc correctly).
Then re-install the role on the new server? Also what issue would you run into with the server not being the same name since that's not even a option?

Is the role installed and ADCS configured as a CA on the new server? In 2012, the role install and configuration process are broken into two separate phases. So if its just installed and not configured, then there's no issue. If however its already been
configured as a CA and it has issued certificates, then anything you have issued from it will be invalidated after the migration.
For the migration itself, since you are renaming the computer that the CA is running on you DEFINITELY want to review the migration process - http://technet.microsoft.com/en-us/library/ee126170(v=WS.10).aspx. There are several steps you will need to
perform otherwise the CA will not work properly on the destination server.
Lastly, it is NEVER recommended to put the CA on a DC. Too hard to migrate or manage the domain, let alone security issues. I would recommend putting it on a dedicated member server, or if you must, at least one that isnt a DC.
Mark B. Cooper, President and Founder of PKI Solutions Inc., former Microsoft Senior Engineer and subject matter expert for Microsoft Active Directory Certificate Services (ADCS). Known as “The PKI Guy” at Microsoft for 10 years.

Similar Messages

Maybe you are looking for