Uninstall AD Certificate Services, then immediately reinstall AD CS same server?

Starlessblack 1 Reputation point
2020-08-29T17:18:23.23+00:00

Hi, folks. We have a domain controller with AD Certificate Services installed as our root CA, and I'd like to demote it from being a DC which requires first uninstalling AD CS.

Can we backup CA private key and database, uninstall AD CS role, demote as DC, then turn right around and reinstall AD CS, restore CA from backup key/database with no ill effects? Does uninstalling the role automatically revoke certs issues by this CA, or is that untouched, and so none should be the wiser?
Before uninstalling AD CS role should we first lengthen the CRL publish time and increase certificate expiry or anything?

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,774 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Hannah Xiong 6,256 Reputation points
    2020-08-31T02:11:26.887+00:00

    Hello,

    Thank you so much for posting here.

    Q1: Can we backup CA private key and database, uninstall AD CS role, demote as DC, then turn right around and reinstall AD CS, restore CA from backup key/database with no ill effects?

    A1: There will be two options, one is to migrate the CA to a new host and the second is to keep the CA on the original host and move the domain controller. For more information about the steps, we could refer to:
    https://video2.skills-academy.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc742388(v=ws.10)?redirectedfrom=MSDN

    Q2: Does uninstalling the role automatically revoke certs issues by this CA, or is that untouched, and so none should be the wiser?

    A2: No, uninstalling the role will not automatically revoke certs. After the re-installation or migration, we will verify whether everything works fine. Besides, it is suggested doing this during the downtime.

    Q3: Before uninstalling AD CS role should we first lengthen the CRL publish time and increase certificate expiry or anything?

    A3: Yes, it is recommended to publish a CRL with a long validity period. We could also refer to the provided document about this, which describes the performance in details.

    For any question, please feel free to contact us.

    Best regards,
    Hannah Xiong