Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

AD cleanup after CA host name move/change

$
0
0

Active Directory cleanup after Certificate Authority host name move/change

Hopefully I am in the right forum.  I cannot find a Certificate Services forum.  Move this if it is better suited somewhere else.

So I just followed the "Host name change" steps in http://technet.microsoft.com/en-us/library/cc742388.aspx to remove the CA from a DC and move it to another newly installed server while changing the name.  My old CA was on the domain controller, LAB-DC01. My new CA is called, LAB-CAROOT.  I completed the move and certs are issuing and verifying. 

When completing the section toward the bottom titled, "Active Directory permissions for the CA", I was unclear when checking the"LAB.LOCAL/Configuration/Services/Public Key Services/CDP" container what to do with the old server container in here.  Both servers are shown in ADSIEdit/Active Directory Sites and Services as well as when viewing the"Manage AD Containers" in PKIview.msc.  Screen shots below.

CA ADSS CDP containerPKIview CDP Container

So my questions are...

  1. Can I delete the CDP information relating to LAB-DC01?
  2. Will this affect any of the CRL checking?

I thought it would be OK since the CA was migrated, not running another along side.  Any thoughts or input is welcomed.  Thanks!


Find this post helpful? Does this post answer your question? Be sure to mark it appropriately to help others find answers to their searches.


Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>