Exchange 2003 KMS to Certificate Management 2010
Hi All! Can anyone provide info about possibilities of migration from Exchange 2000 Key Management System to Certificate Management in FIM 2010. Currently we use KMS to encrypt messages and want to move databeseof issued/revoked certs to new FIMMCSE: M+S, SMS/SCCM, CCNA
October 12th, 2009 12:03pm

The short answer is that you can't do what you're trying to do. What you can do is the following:1. Stand up a Windows Server 2003 or 2008 or 2008 R2 Certificate Services infrastructure.2. Migrate the KMS database to the new Certificate Services infrastructure.3. Use clmutil to synch the Certificate Services database with the CM database.4. Associate the imported certificates with the Profile in CM.You should also give serious consideration to upgrading your Exchange infrastructure. Exchange 2000 mainstream support ended Jan. 10, 2006 and extended support ends on Jan. 1, 2011 - http://www.microsoft.com/exchange/2007/support/lifecycle/2000.mspxYou can find high-level steps for migrating from KMS to Certificate Services here - http://www.msexchange.org/tutorials/Key_Management_Server_Migration.htmlPaul Adare CTO IdentIT Inc. ILM MVP
Free Windows Admin Tool Kit Click here and download it now
October 13th, 2009 10:06am

Hi, Paul! Thx for info, i'm already read doc about exchange 2000 kms to Server 2003 CA migration, but i cannot find docs about steps 3 and 4 that you provide. Do you you have a links or docs about this?MCSE: M+S, SMS/SCCM, CCNA
October 13th, 2009 11:27am

You can find information about clmutil here:http://technet.microsoft.com/en-us/library/cc720647(WS.10).aspxFor information about #4:http://social.technet.microsoft.com/Forums/en-US/identitylifecyclemanager/thread/9e3527db-1965-4f70-a31b-92984ad0eb8c?prof=requiredhttp://social.technet.microsoft.com/Forums/en/winserversecurity/thread/81ceb74c-7785-46b6-b569-fb0e73c1caf2Paul Adare CTO IdentIT Inc. ILM MVP
Free Windows Admin Tool Kit Click here and download it now
October 13th, 2009 12:17pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics