ADCS Migration from 2008R2 to 2019

Niven Peter 86 Reputation points
2020-08-11T04:42:08.957+00:00

Hi experts,

I would like to ask the following on the topic migrating ADCS from 2008R2 to 2019. I have run couple of articles like the one as below:-

https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-migrating-the-active-directory-certificate-service/ba-p/697674

Let me briefly explain on the current structure in the environment of ours

  1. 1 Root CA which is not joined domain - Windows 2008R2
  2. 4 Issuing suboordinate CA - Windows 2008R2

The final result of the ADCS structure will be as below:-

  1. Root CA and the issuing subordinate CA will be migrated to Windows 2019
  2. Since they are many clients are relying to the certificates which was rolled out. Are we able to migrate all the servers from Windows 2008 R2 to Windows 2019 without the need to reissue the cert to the clients? As there are tons of web apps and services which are relying on the certificates.

I would like to have this deployment in order so that there will not issues of certificate where the chains will be broken. The objectives are as below:-

  1. CA name will be the same
  2. IP address of the CA server will be different
  3. Hostname of the CA server will be different.

I was advised to perform the root CA migration first then followed by the 4 suboordinate issuing CA. Is that a good idea?

Another question is since the root CA server name and the IP address will be different, how are we going to tell the issuing CA that the root CA server name and IP address is being changed? Also when we migrate the subordinate issuing CA, how are we going to tell the other suboordinate CA and root CA that this issuing CA server name and ip address is being changed. What are the configuration that is to take place

Thank you

Peter

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,774 questions
0 comments No comments
{count} votes

Accepted answer
  1. Leon Laude 85,716 Reputation points
    2020-08-11T06:41:51.453+00:00

    Hi,

    You have posted in the general Windows 10 forum, since your issue is related to Active Directory Certificate Services (ADCS) on WIndows Server I suggest you ask over at the dedicated Windows Server Security forum over here:
    https://video2.skills-academy.com/en-us/answers/topics/windows-server-security.html

    ----------

    (If the reply was helpful please don't forget to accept as answer, thank you)

    Best regards,
    Leon

    0 comments No comments

0 additional answers

Sort by: Most helpful