Root CA replace

Hi All,

I did not find, anything about how to replace the Root CA (We would like to generate, hence we decided to replace the old root CA and create a new one with 2 SUB CA.)

So i am looking after some technical documentation, or guide how to proceed with this?

I would be appreciated if you could send me some useful link or anything like that. Especially what kind of certificate should be replaced at Exchange, DC, File Server, Terminal Server etc.

June 1st, 2015 7:35am

Honestly, you are really asking this in the wrong forum. You should probably be asking this question in the Windows Servers forum.  Anyway here's a blog you can use to replace your internal CA.

http://blogs.technet.com/b/pki/archive/2012/01/27/steps-needed-to-decommission-an-old-certification-authority-without-affecting-previously-issued-certificates-and-then-switching-all-operations-to-a-new-certification-authority.aspx

Free Windows Admin Tool Kit Click here and download it now
June 1st, 2015 9:47am

Hi,

thank you sir, i will mark myself to move my topic :) 

cheers,

June 1st, 2015 9:48am

Hello,

If you replaced the Root CA, all the Exchange certificate which was generated by the CA should be replaced. Or the Outlook clients will report certificate trust issues.

Thanks,

Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com

Free Windows Admin Tool Kit Click here and download it now
June 10th, 2015 3:04am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics