question

Eduards-6654 avatar image
0 Votes"
Eduards-6654 asked LimitlessTechnology-2700 answered

Windows Server 2008R2 CA in-place upgrade to Windows Server 2019

Hello,

I need to upgrade Certificate Authority from WS2008R2 till WS2019. WS2008R2 have only AD CS role installed.

Is there need to remove AD CS role from server? Or all I need is to backup registry, CA templates etc. and to 2 in-place upgrade :
1. Windows Server 2008R2 to Windows Server 2012 R2.
2. Windows Server 2012R2 to Windows Server 2019.

And is there some task to be done after in-place upgrade is finished?

There is also AD DC servers which are running on WS2008R2. Could I upgrade CA first and then AD DC servers or AD DC servers should be upgraded first?

windows-server-security
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

cthivierge avatar image
0 Votes"
cthivierge answered cthivierge commented

AD CS and AD DS are 2 different roles and there is no relation between them. I mean, you could upgrade the DC's to Windows 2019 first and then upgrade AD CS second or vice versa.

For the question about in-place upgrade, it's not my first choice but it should work.

There is no specific tasks to do after the upgrade except to validate that the CA can still issue certificates and publish the CRL

https://social.technet.microsoft.com/Forums/en-US/22443b56-0845-459a-b1cf-339b684f8f90/2008-r2-certificate-authority-in-place-upgrade-to-2012-r2?forum=winserversecurity

hth

· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hello @cthivierge

My plan is to start with AD CS server upgrade it till Windows Server 2019.

After AD CS upgrade I will upgrade AD DS to 2019 but with AD DS I will no use in-place upgrade, but deploy two new servers and move FSMO roles and all settings from old AD DC to new and after that do decommission of old servers.

0 Votes 0 ·

Yes, this should work

0 Votes 0 ·
LimitlessTechnology-2700 avatar image
0 Votes"
LimitlessTechnology-2700 answered

Hello,

Thank you for reaching out.

Yes, It is advisable to take back before migration or upgradation.

All the step-by-steps instructions are well outlined in below Microsoft article.


https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-migrating-active-directory-certificate-service-from/ba-p/2328766
https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-migrating-the-active-directory-certificate-service/ba-p/697674

Thanks,

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.