Can we migrate the ROOT CA from Enterprise server to a Standalone server?

Santosh Kumar 0 Reputation points
2025-07-07T04:37:22.3033333+00:00

The Root CA was originally configured on an Enterprise Domain Controller. We now intend to migrate it to a new offline Standalone server. A Subordinate CA server is already in place and is currently used for issuing certificates. However, multiple certificates have also been issued directly by the Root CA as well.

Our objective is to migrate in such a way that there is no impact on the certificates previously issued by either the Root CA or the Subordinate CA Additionally, the new Standalone Root CA must retain the same CA name, the same CA certificate, and the existing private key.

Is this migration scenario feasible while preserving the trust and functionality of all existing certificates?

Windows for business | Windows Server | Devices and deployment | Install Windows updates, features, or roles
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.