Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Re: Move the CA to a server with the same name or different name?

Reply
Thread Tools Display Modes

Re: Move the CA to a server with the same name or different name?

 
 
Paul Bergson [MVP-DS]
Guest
Posts: n/a

 
      06-04-2009
"jprstokato" <> wrote in message
news:97FC06C0-6FB5-4553-B297-...
> In Technet article
> http://technet.microsoft.com/en-us/l.../cc742388.aspx
> on performing a CA migration, in the section 'Option A: Migrate the CA to
> a
> New Host', the article states that "the computer name of the target
> computer
> can differ from the computer name of the source computer, but the CA name
> must stay the same."
>
> In KB 298138 http://support.microsoft.com/default.aspx/kb/298138 on the
> same
> subject of moving a certification authority to another server, it states
> "The
> new server must have the same computer name as the old server"
>
> Both articles are describing the same process. Only difference is that the
> Technet article applies to both Windows Server 2008 (and 2003) Domain
> controllers, and the KB applies to any Windows Server 2000 /2003.
>
> I'm performing Option B: 'Keep the CA on the Original Host and Move the
> Domain Controller' of the technet article, and using Option A as part of a
> rollback plan, if Option B fails to restore the CA to the same server.
>
> Can you tell me if I should therefore can follow the Technet article, and
> restore the CA to a another 32 bit Windows 2003 server in our domain (i.e.
> with a different name).
>
> Many thanks, JPSR.


If you change the name of your CA you break the trust and therefore you
break your CA. You HAVE to keep the CA the same name forever.

This NewsGroup is related to Active Directory, for future questions I would
suggest you post them in the server.security NewsGroup. I have included
them in on this response.

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.


 
Reply With Quote
 
 
 
 
jprstokato
Guest
Posts: n/a

 
      06-08-2009
Many thanks for your reply, and points noted..
(Understood that the The CA name must be the same)
I still need to know whether the name of the 'server' that the CA is moved
to can / should be changed..
Regards, JPSR.

"Paul Bergson [MVP-DS]" wrote:

> "jprstokato" <> wrote in message
> news:97FC06C0-6FB5-4553-B297-...
> > In Technet article
> > http://technet.microsoft.com/en-us/l.../cc742388.aspx
> > on performing a CA migration, in the section 'Option A: Migrate the CA to
> > a
> > New Host', the article states that "the computer name of the target
> > computer
> > can differ from the computer name of the source computer, but the CA name
> > must stay the same."
> >
> > In KB 298138 http://support.microsoft.com/default.aspx/kb/298138 on the
> > same
> > subject of moving a certification authority to another server, it states
> > "The
> > new server must have the same computer name as the old server"
> >
> > Both articles are describing the same process. Only difference is that the
> > Technet article applies to both Windows Server 2008 (and 2003) Domain
> > controllers, and the KB applies to any Windows Server 2000 /2003.
> >
> > I'm performing Option B: 'Keep the CA on the Original Host and Move the
> > Domain Controller' of the technet article, and using Option A as part of a
> > rollback plan, if Option B fails to restore the CA to the same server.
> >
> > Can you tell me if I should therefore can follow the Technet article, and
> > restore the CA to a another 32 bit Windows 2003 server in our domain (i.e.
> > with a different name).
> >
> > Many thanks, JPSR.

>
> If you change the name of your CA you break the trust and therefore you
> break your CA. You HAVE to keep the CA the same name forever.
>
> This NewsGroup is related to Active Directory, for future questions I would
> suggest you post them in the server.security NewsGroup. I have included
> them in on this response.
>
> --
> Paul Bergson
> MVP - Directory Services
> MCTS, MCT, MCSE, MCSA, Security+, BS CSci
> 2008, 2003, 2000 (Early Achiever), NT4
>
> http://www.pbbergs.com
>
> Please no e-mails, any questions should be posted in the NewsGroup This
> posting is provided "AS IS" with no warranties, and confers no rights.
>
>
>

 
Reply With Quote
 
Paul Bergson [MVP-DS]
Guest
Posts: n/a

 
      06-08-2009
Already answered. When I speak of name I'm not talking about the dns name,
I'm talking about your machine name.

"If you change the name of your CA you break the trust and therefore you
break your CA. You HAVE to keep the CA the same name forever."


--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.

"jprstokato" <> wrote in message
news:FBC57A59-841E-43CE-9D2F-...
> Many thanks for your reply, and points noted..
> (Understood that the The CA name must be the same)
> I still need to know whether the name of the 'server' that the CA is moved
> to can / should be changed..
> Regards, JPSR.
>
> "Paul Bergson [MVP-DS]" wrote:
>
>> "jprstokato" <> wrote in message
>> news:97FC06C0-6FB5-4553-B297-...
>> > In Technet article
>> > http://technet.microsoft.com/en-us/l.../cc742388.aspx
>> > on performing a CA migration, in the section 'Option A: Migrate the CA
>> > to
>> > a
>> > New Host', the article states that "the computer name of the target
>> > computer
>> > can differ from the computer name of the source computer, but the CA
>> > name
>> > must stay the same."
>> >
>> > In KB 298138 http://support.microsoft.com/default.aspx/kb/298138 on the
>> > same
>> > subject of moving a certification authority to another server, it
>> > states
>> > "The
>> > new server must have the same computer name as the old server"
>> >
>> > Both articles are describing the same process. Only difference is that
>> > the
>> > Technet article applies to both Windows Server 2008 (and 2003) Domain
>> > controllers, and the KB applies to any Windows Server 2000 /2003.
>> >
>> > I'm performing Option B: 'Keep the CA on the Original Host and Move the
>> > Domain Controller' of the technet article, and using Option A as part
>> > of a
>> > rollback plan, if Option B fails to restore the CA to the same server.
>> >
>> > Can you tell me if I should therefore can follow the Technet article,
>> > and
>> > restore the CA to a another 32 bit Windows 2003 server in our domain
>> > (i.e.
>> > with a different name).
>> >
>> > Many thanks, JPSR.

>>
>> If you change the name of your CA you break the trust and therefore you
>> break your CA. You HAVE to keep the CA the same name forever.
>>
>> This NewsGroup is related to Active Directory, for future questions I
>> would
>> suggest you post them in the server.security NewsGroup. I have included
>> them in on this response.
>>
>> --
>> Paul Bergson
>> MVP - Directory Services
>> MCTS, MCT, MCSE, MCSA, Security+, BS CSci
>> 2008, 2003, 2000 (Early Achiever), NT4
>>
>> http://www.pbbergs.com
>>
>> Please no e-mails, any questions should be posted in the NewsGroup This
>> posting is provided "AS IS" with no warranties, and confers no rights.
>>
>>
>>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
had windows 2000 server set as time server - now want to move it to 2003 gary Windows Server 13 03-16-2007 08:58 PM
2003 Server/Exchange Server...move to different subnet question Windows Server 2 11-17-2006 02:04 PM
2003 Server/Exchange Server...move to different subnet question Server Networking 1 11-17-2006 01:49 PM
Move Exchange Server 2003 From Old Server to New Server Mike_Y Windows Small Business Server 2 04-01-2006 04:13 AM
windows server 2003:move a domain nain into my server Roberto Windows Server 5 09-27-2005 05:31 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59