Recovering Certificate Services
I have completely lost my domain CA before I had the chance to set up any DR on it. I have access to the hard drive and can view some files on it, but Windows will not boot, and there is no "back up" of the CA, as it wasn't set up yet. Small
domain with only the one CA server. Is there any way to recover this onto another machine to become a functioning CA without losing everything pertaining to existing certificates?
I think the original certificate database might still be accessible and intact, but not sure how to determine that for certain.
September 22nd, 2012 9:26pm
You really need a backup of the CA. You have to judge what will take less time:
1) Getting the domain CA computer to boot, start the CA and perform a proper backup of the CA and its private key
2) Build a new CA, deprecate all existing certificates (cannot revoke them), redeploy all certificates to all users, computers, service and devices
In your scenario, it sounds like option 2 may take less time and allow you to build with DR as part of the design
I am basing this on the statement (small domain)
Brian
Free Windows Admin Tool Kit Click here and download it now
September 23rd, 2012 11:57am


