CA server in-place upgrade from server to server 2019.

Namless Shelter 216 Reputation points
2021-07-19T02:33:24.483+00:00

Hi There,

Just need some helps on our CA server.

Currently we are running only CA on a 2012 server box. Now we are thinking to in-place upgrade to server 2016. I know we can migrate CA to a new server 2019. But we just want it done in an easy way.

How feasible it is to upgrade CA server from 2012 to 2016? Any potential issues we might have?

Thanks a lot,
ML

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,721 questions
{count} votes

Accepted answer
  1. Hannah Xiong 6,231 Reputation points
    2021-07-30T04:31:38.31+00:00

    Hello @Namless Shelter ,

    You are welcome. Thank you so much for your kindly reply.

    If the status of snapshot is fine, we could restore it from the snapshot and everything will be fine.

    If the in-place upgrade failed, we could check the log files for further analysis to find out the cause and solution.
    Reference: https://support.microsoft.com/en-us/topic/log-files-that-are-created-when-you-upgrade-to-a-new-version-of-windows-9ec8aa31-0cc1-a0b2-2d98-e9c6714349b9

    As mentioned, in-place upgrade is not recommended. It is suggested to do the migration of CA server.

    For any question, please feel free to contact us.

    Best regards,
    Hannah Xiong

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.


3 additional answers

Sort by: Most helpful
  1. Hannah Xiong 6,231 Reputation points
    2021-07-19T04:35:48.97+00:00

    Hello @Namless Shelter ,

    Thank you so much for posting here.

    Based on my experience, it is easy to migrate the CA directly from the server running Windows Server 2012 to the new server 2016. It is suggested that we could choose to migrate the CA to the new server.

    As for the in-place upgrade, we have not experienced this operation before. For more information, we could refer to:
    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc742466(v=ws.10)

    Besides, a complete server backup of the CA computer is highly recommended before the upgrade or migration. If we choose to do the in-place upgrade, please make such upgrade in test environment firstly.

    The similar discussion here: https://social.technet.microsoft.com/Forums/en-US/22443b56-0845-459a-b1cf-339b684f8f90/2008-r2-certificate-authority-in-place-upgrade-to-2012-r2

    For any question, please feel free to contact us.

    Best regards,
    Hannah Xiong


  2. Dane Winkler 1 Reputation point
    2022-11-15T15:14:44.437+00:00

    I upgraded from 2016 to 2022 and could not issue a new cert. Even after restoring a backed up DB.
    I reverted to a snapshot to get the CA going again.
    I will be doing a fresh build / migration in the future. Thanks for the public support.
    Is it better to migrate from 2016 to 2019 or 2022?

    0 comments No comments

  3. Dane Winkler 1 Reputation point
    2022-11-15T16:30:55.41+00:00

    @Hannah Xiong
    One of the issues I'm finding on my server is that there is no CApolicy.inf file. But I do have a CApolicy.inf.old file.
    The server is functioning properly as a CA, currently.
    What does the CApolicy file do?