Forum Discussion

Prayer Solanky's avatar
Prayer Solanky
Brass Contributor
Oct 03, 2017

Migrating Certificate Services

I am looking into migrating our Certificate Services running on 2008R2 to 2016.  There is no documentation specifically for migrating the role to 2016 here https://docs.microsoft.com/en-us/windows-server/get-started/migrate-roles-and-features .  However it says "In many cases, the steps in the Windows Server 2012 R2 migration guides are still relevant for Windows Server 2016".

 

There is a guide for migrating the role from 2008R2 to 2012R2 here https://technet.microsoft.com/library/dn486797.aspx?f=255&MSPPError=-2147217396 .

 

Has anyone tried doing this to confirm the steps are valid going from 2008 or 2012R2 to 2016 certificate services?  It would be beneficial to IT Pros if Microsoft would validate the steps and mark the documentation in some way.    The above quote should be "In THESE cases..."

2 Replies

  • Mike Patterson's avatar
    Mike Patterson
    Copper Contributor

    I am not sure if I would migrate as the Hash and key lenght might need to be changed to be more secure.  I know we have moved off of SHA1 to SHA256/512 and our root, Intermediate, & Issuing Keys are 4096, then our client keys are 2048.  What I have done in the past is stand up the new environment.  Create new Cert Templates and have the new server issue them.  Stop issuing from the old servers, then we can make sure all the new certs are being issues from the new environment and then mirgate what we can to the new servers.   That is my 2 cents.

    • Prayer Solanky's avatar
      Prayer Solanky
      Brass Contributor

      I had not thought of that Mike, I will investigate that route.  What are your thoughts of doing in place upgrades of the host OS.

Resources