Thursday, October 15, 2015

windows - Unnecessary Certificate Authority in Domain

I have an organization with a file server that is a secondary domain controller(2003 R2), an Exchange server(2008 R2), and a primary domain controller(2008 R2). We also have what used to be the primary domain controller, but has been demoted to be the third domain controller(2003).



I am wanting to remove this last one entirely, but am worried it will cause issues. Many years ago, someone set this server up as a Certificate Authority, I believe trying to do something with email encryption that never panned out. It currently only has 3 valid certificates issues, one to each of the domain controllers.



I am not at all familiar with the CA role. Can I simply revoke the three issued certificates and then remove the role, or will that cause some kind of unforeseen problem?

No comments:

Post a Comment

linux - How to SSH to ec2 instance in VPC private subnet via NAT server

I have created a VPC in aws with a public subnet and a private subnet. The private subnet does not have direct access to external network. S...