Removing an Enterprise Certificate Authority
Windows Server Forum Index Windows Server
Server discussion on Windows platform.
 
 FAQFAQ   MemberlistMemberlist     RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 
Google
 
Web winserverhelp.com
Removing an Enterprise Certificate Authority

 
Post new topic   Reply to topic    Windows Server Forum Index -> Active Directory
Author Message
Eric Maino
Guest





Posted: Wed Jan 12, 2005 11:49 pm    Post subject: Removing an Enterprise Certificate Authority Reply with quote

I was wondering if it is possible to remove an enterprise certificate
authority. I have a virtual environment I am testing a scenario with and it
appears that in this scenario there are 3 enterprise level CAs of only which
1 is valid. The other two existed on a server that is no longer available. I
would like to remove these from AD if possible so that when an admin
retargets the CA he/she will only see the valid CA rather then two invalid
ones and a valid one.
Back to top
Phillip Renouf
Guest





Posted: Thu Jan 13, 2005 1:53 am    Post subject: RE: Removing an Enterprise Certificate Authority Reply with quote

If there are 3 CAs in the environment you should make sure that this wasn't
setup to be a 3 tier PKI infrastructure. In that 3 tier setup there is only
one CA actually online, the others are shut off unless they are required. The
one online is an issuing CA and the two others are a CA to authorize issuing
CAs and the main CA that is in control of the entire PKI infrastructure (and
authorizes the intermediate CAs).

That may explain why the other two servers aren't available or seem to be
gone.

Phil

"Eric Maino" wrote:

Quote:
I was wondering if it is possible to remove an enterprise certificate
authority. I have a virtual environment I am testing a scenario with and it
appears that in this scenario there are 3 enterprise level CAs of only which
1 is valid. The other two existed on a server that is no longer available. I
would like to remove these from AD if possible so that when an admin
retargets the CA he/she will only see the valid CA rather then two invalid
ones and a valid one.
Back to top
Eric Maino
Guest





Posted: Thu Jan 13, 2005 1:59 am    Post subject: RE: Removing an Enterprise Certificate Authority Reply with quote

Phillip

Unfortunately this is not the situation. The other two CAs are officially no
longer valid CAs in the enterprise.

Eric

"Phillip Renouf" wrote:

Quote:
If there are 3 CAs in the environment you should make sure that this wasn't
setup to be a 3 tier PKI infrastructure. In that 3 tier setup there is only
one CA actually online, the others are shut off unless they are required. The
one online is an issuing CA and the two others are a CA to authorize issuing
CAs and the main CA that is in control of the entire PKI infrastructure (and
authorizes the intermediate CAs).

That may explain why the other two servers aren't available or seem to be
gone.

Phil

"Eric Maino" wrote:

I was wondering if it is possible to remove an enterprise certificate
authority. I have a virtual environment I am testing a scenario with and it
appears that in this scenario there are 3 enterprise level CAs of only which
1 is valid. The other two existed on a server that is no longer available. I
would like to remove these from AD if possible so that when an admin
retargets the CA he/she will only see the valid CA rather then two invalid
ones and a valid one.
Back to top
Phillip Renouf
Guest





Posted: Thu Jan 13, 2005 2:07 am    Post subject: RE: Removing an Enterprise Certificate Authority Reply with quote

After thinking about my response for another few minutes that may not explain
it since if the 3 tier architecture was done properly the two offline CAs
should be stand-alone CAs and not enterprise CAs. I also just noticed that
you mentioned that two of the CAs were on one server?

Phil

"Eric Maino" wrote:

Quote:
I was wondering if it is possible to remove an enterprise certificate
authority. I have a virtual environment I am testing a scenario with and it
appears that in this scenario there are 3 enterprise level CAs of only which
1 is valid. The other two existed on a server that is no longer available. I
would like to remove these from AD if possible so that when an admin
retargets the CA he/she will only see the valid CA rather then two invalid
ones and a valid one.
Back to top
 
Post new topic   Reply to topic    Windows Server Forum Index -> Active Directory All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




New Topics Powered by phpBB