Migrating a two tier PKI with Offline Root CA and a subordinte CA from 2012R2 to 2019

Jose R 1 Reputation point
2020-12-21T01:36:21.737+00:00

I need to migrate our older PKI infrastructure to keep with updated OS.
Removing the whole PKI, building a new one and reissuing all CERT will require an unacceptable maintenance window.
I found several Blogs an articles on how to do it with a single tier and/or with same computer name and IP, but it's not my case.

We do have a Offline Root CA and Subordinate CA (Enterprise).
Both are published "CA Name" different from computer names (NetBIOS or FQDN).
CDP and AIA use a DNS alias in the http location.

We need to move de Enterprise SubCA to a LAN accesible VM on Azure. So no in-place upgrade possible.

  • CA name will be the same
  • IP address of the CA server will be different
  • Hostname of the CA server will be different.

Does the method like the link below would be valid for SubCAs too?
Step-By-Step: Migrating The Active Directory Certificate Service From Windows Server 2008 R2 to 2019

Also read that if the new server has a different ComputerName the registry backup of the CA branch should be edited to reflect the new one before merging.
Like:
Moving Certificate Services To Another Server

Thanks in advance,
Jose

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,720 questions
Windows Server Migration
Windows Server Migration
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Migration: The process of making existing applications and data work on a different computer or operating system.
408 questions
{count} votes

5 answers

Sort by: Most helpful
  1. Fan Fan 15,291 Reputation points Microsoft Vendor
    2020-12-21T03:45:51.017+00:00

    Hi,

    Based on my understanding , it should be ok .
    When migrate the CA, we just need to keep the CA name the same as the old one.
    The Hostname and the IP of the CA can be different from the old one.
    This guide can be used to migrate a CA from a source server that is also a domain controller to a destination server with a different name. Following link for your reference:
    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn486797(v=ws.11)

    Best Regards,

    0 comments No comments

  2. Thameur-BOURBITA 32,501 Reputation points
    2020-12-21T10:40:51.107+00:00

    Hi,

    Does the method like the link below would be valid for SubCAs too?

    Yes it still valid, because you will keep the same certificate with private key and same CA Name.

    If you will change IP and VLAN , you have to check that you have all required network flows opened like old IP.

    Please Don't forget to mark this reply as answer if it help you to fix your issue

    0 comments No comments

  3. Jose R 1 Reputation point
    2020-12-21T12:51:22.37+00:00

    Thanks. I'll see how it goes and let you know.

    Jose

    0 comments No comments

  4. Jose R 1 Reputation point
    2020-12-21T13:44:49.753+00:00

    Reviewing the process, I found that on my current SubCA, the AIA URL points to:

    http://corp-ca.mydomain.local/pki/<ServerDNSName>_<CaName><CertificateName>.crt

    Although, the FQDN part would be the same changing the CNAME target to the new server.
    The "ServerDNSName" part of the file name would be different.

    How should I cope with that?
    Should I add a new file and http location with the ServerDNSName part "static" using the "old" server DNS name until all certs issued by that server expires?

    Jose

    0 comments No comments

  5. Thameur-BOURBITA 32,501 Reputation points
    2020-12-23T00:02:21.253+00:00

    Hi,

    I think the best way is to keep the same name.

    You can duplicate manually the certificate of subca on web server where the old AIA URL points, rename it to respect the name of old AIA URL.

    Please don't forget to mark this reply as answer if it help you to fix your issue

    0 comments No comments