Error: migrating root ca to new server

Error: migrating root ca to new server

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Error: migrating root ca to new server micra 03-18-2007
Posted by =?Utf-8?B?bWljcmE=?= on March 18, 2007, 7:00 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

there is an organisation with one enterprise root ca and one enterprise
subordinate ca. I have a task to move this root ca to new server (virtual
machine) and make it a offline root ca. In this case I have backuped root ca,
export configuration from registry - just like in KB298138. But after that
steps I can't do new installation with backuped certificate with key of root
ca (it's not my first CA moving, but first with error). Operating system:
Windows 2000 Server with SP4.

I have of course certificate and pair of keys - public and private, but in
the moment of try of new installation I receive message, that "This
certificate is selfsigned". Hmm, I know about this - it's certificate of root
ca. I searched Technet, Internet, news groups and I can't find any similar
described situations. I have tried to import this certificate on new server
(on virtual machine) in containers: Trusted Root CA, Third-Party Root CA and
others and it's without any results during install.

But I have next bad message: after backup of ca and backup of configuration
I removed old root ca machine account from domain and add new account (same
name but of course with sid)... I have no way to return.

Old root ca must be refreshed before September and I think maybe the best
solution in this case will be fresh installation of whole PKI infrastructure
- old infrastructure were installed without any configuration. It is possible
to have two disjoined (disconnected) PKI infrastructures in one AD Tree or
Forest?

Questions:
1. What I can do in the case of message, that certificate is selfsigned?
2. It is possible to have two disjoined PKI infrastructures in one AD?

Similar ThreadsPosted
Migrating from single enterprise root CA to different root CA May 11, 2007, 6:43 am
Exchange server not reachable via VPN after migrating accounts December 22, 2006, 3:48 am
Enterprise Root/Web Cert error October 17, 2006, 9:53 am
Add a Root Certificate Server October 12, 2005, 11:08 am
Remove Certificate Server (root CA) October 31, 2007, 10:56 pm
Problem Migrating SUS to WSUS March 21, 2007, 5:43 pm
NTFS permission change when migrating to new Domain September 29, 2008, 12:16 pm
Possible conflicting info:Help file states that Offline Root CA canot be member server of domain? January 23, 2007, 5:27 pm
Certificate Error on 2003 server November 14, 2005, 2:23 pm
0x80072ee2 error message in Windows 2003 server August 10, 2005, 6:10 am

The site map in XML format XML site map

Contact Us | Privacy Policy