Unsuccessful migration of Certificate Authority (CA) from Windows 2008R to Windows 2012 R2

Good day, dear reader,
I will tell you about my nightmare that I experienced while migrating CA from Windows 2008R2 to Windows 2012R2. There are a lot of articles on this topic online, and there shouldn’t have been any problems.

Unfortunately, I am not much of a Windows admin; I am more of a *nix admin, but I was tasked with the migration of CA — it had to be done.

Below, I will describe how I went through this process and ultimately did not achieve a Happy End.

So let’s get started…
Input data:
Source — Windows 2008 R2 with Root CA
Target — Windows 2012R2

I already had Windows 2012R2 server installed and minimally configured.

Initially, the plan of action was as follows (shortened steps):
1) Make a Backup of CA + Private Key and copy it to a shared directory for both computers
2) Remove the target from the domain and change its IP
3) Make a server snapshot
4) Change the IP on the source
5) Log into the new Windows 2012R2 server as an admin — add it to the domain with the same name and assign the old IP
6) Install the Active Directory Certificate Service role (CA, CA Web Enrollment, NDES, Online Responder)
7) Specify that this is an Enterprise CA
8) Restore CA + Private Key from the backup
9) Happy End

Agree, there’s nothing complicated here. I proceeded with the implementation. In fact, there were no issues, and everything went smoothly… The service started, Certificate Templates appeared, and the certificates themselves were present. Everything was fine. So I went to sleep. In the morning, there were no complaints about the CA operation, so I assumed everything was working and moved on to other tasks. While addressing these tasks, I needed a certificate. I created a .csr and went to the link vm_ca/certsrv, to sign and obtain the certificate, and it was at this stage that the error occurred. Unfortunately, I didn't take a screenshot, but it mentioned a mismatch in user information and some other errors. That's when I realized we were in trouble. I started googling, but unfortunately couldn't find anything clear.

By evening, we decided to remove CA Windows 2012R2 and reinstall everything, and here I made a mistake: instead of choosing Enterprise CA, I selected the Standalone CA option (I learned about my mistake later). I went through all the operations again… everything went without errors — but when selecting the Certificate Templates folder, I got an Element not found error, although if I chose Manage, the templates were there.
I thought that the rights for the CN=Certificate Templates might be insufficient, so I used ADSI Edit to grant Read access to vm_ca$. I restarted CertSvc and… the result: Element not found.
I felt gloomy here because it was around 2 AM... and the CA is not working. I am shutting down the CA on Windows 2012R2 and restoring the CA VM on Windows 2008R2 from a snapshot. I am returning the server to the AD (since trying to log in with a domain account gives a trust relationship error with AD). proxy server and AD).
Well, I think... everything should be okay now, but alas… the Certificate Templates still show Element not found. I'll leave everything until morning — because morning is wiser than evening.
In the morning, I googled, reading various articles — and decide to reinstall the CA on the old one server hoping to solve the Element Not Found issue and to issue certificates via Web.

The process is quite simple:
1) Remove the CA role
2) Reboot
3) Wait for the uninstallation process to finish
4) Add the CA role (specifying CA, CA Web Enrollment, NDES, Online Responder)
5) Specify that I have an Enterprise CA and I have a private key
6) Wait for the installation to finish and restore everything from the backup we made at the very beginning.
7) As usual, everything goes smoothly — without errors and the service started.

With bated breath, I click on the Certificate Templates — and… a list was generated — that's already a small victory. The next step is to check the certificate issuance via the Web. I go to the link: vm_ca/certsrv and click on Request a Certificate and then advanced certificate request… I enter the .csr request and receive the finished certificate. I breathe out… Restoring the CA worked.

Conclusions:
1) Always make a backup and snapshot
2) Document your actions — it will help to restore everything or find the error faster

P.S. I will have to try the CA migration from Windows 2008R to Windows 2012R2 again.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster