How to decommission an old Root CA and Issuing CA after the new ones are already in live

Vishnu Priya 0 Reputation points
2024-10-01T08:27:33.8066667+00:00

I wanted to remove or decommission the old Root CA and the issuing CA. Already have the new Root CA and the issuing CA. Wanted to know the step by step process how to check the live certificates in the old CAs and then decommission them.

Azure Key Vault
Azure Key Vault
An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
1,282 questions
Azure DNS
Azure DNS
An Azure service that enables hosting Domain Name System (DNS) domains in Azure.
674 questions
Azure Load Balancer
Azure Load Balancer
An Azure service that delivers high availability and network performance to applications.
437 questions
Windows Server Setup
Windows Server Setup
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Setup: The procedures involved in preparing a software program or application to operate within a computer or mobile device.
252 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,654 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Daisy Zhou 23,346 Reputation points Microsoft Vendor
    2024-10-02T07:04:05.1666667+00:00

    Hello Vishnu Priya,

    Thank you for posting in Q&A forum.

    You can check all the certificates issued by CA in the "Issued Certificates" container on both root CA server and issuing CA server\ Certification Authority console (below).

    User's image

    And you can also check if you set up certificates autoenrollment via GPO.

    For more information, please refer to links below.

    https://www.vkernel.ro/blog/set-up-automatic-certificate-enrollment-autoenroll

    https://learn.microsoft.com/en-gb/troubleshoot/windows-server/certificates-and-public-key-infrastructure-pki/decommission-enterprise-certification-authority-and-remove-objects

    I hope the information above is helpful.

    If you have any questions or concerns, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.