Share via


Rename Certificate Authority

Question

Tuesday, July 13, 2010 9:47 PM

I would like to rename my CA server. I know that if you back and restore the CA it has to be the same name (or you have tons of problems), but can you change the name of the server after it is restored? Is there something that will bite me if I do? My current CA is on Windows 2008 and I will upgrade to R2 soon, but I wanted to rename before I do, assuming that there is no big deal doing that.

SnoBoy

All replies (5)

Tuesday, July 13, 2010 10:15 PM âś…Answered

Hello,

the supported ways are here:

http://technet.microsoft.com/en-us/library/cc742388(WS.10).aspx

http://technet.microsoft.com/en-us/library/cc742466(WS.10).aspx

Best regards Meinolf Weber Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.


Tuesday, July 13, 2010 9:53 PM

Hello,

renaming a CA is not possible. You can install a new one that take over the functionality.

Best regards Meinolf Weber Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.


Tuesday, July 13, 2010 9:59 PM

Would that be through the back up and restore method, or a different method. From all that I have read, I don't want to do the back up and restore method to a server with a different name becuase of all the hassles getting it to work correctly.SnoBoy


Wednesday, July 23, 2014 11:39 PM

Can somebody help me, I renamed my domain controller without realizing it was a certificate authority. Can I just rename it back??? Now I am getting these errors in the event log:

Active Directory Certificate Services could not publish a Delta CRL for key 0 to the following location on server mydomain.local: ldap:///CN=mydomain-DOMAINCONTROLLE-CA,CN=mydomain,CN=CDP,CN=Public Key Services,CN=Services,CN=Configuration,DC=mydomain,DC=local.  Directory object not found. 0x8007208d (WIN32: 8333).

ldap: 0x20: 0000208D: NameErr: DSID-0310020A, problem 2001 (NO_OBJECT), data 0, best match of:
     'CN=CDP,CN=Public Key Services,CN=Services,CN=Configuration,DC=mydomain,DC=local'

The reason we renamed it in the first place was because the original host name had more than 15 characters and was breaking Hyper-V integration.

Note: i am in no way an experienced Windows admin so please be nice:)


Friday, July 25, 2014 9:10 AM

Hello,

i suggest to use a AD aware backup from BEFORE renaming and restore it.

http://technet.microsoft.com/en-us/library/cc753359(WS.10).aspx

Best regards

Meinolf Weber
MVP, MCP, MCTS
Microsoft MVP - Directory Services
My Blog: http://msmvps.com/blogs/mweber/

Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.