关于废弃现有AD CS证书颁发机构并重新部署的技术咨询
Hey Thomas, let's walk through your questions with practical context based on managing AD CS and Entra integrations:
1. Is it acceptable to drop the complete CA in this case?
Absolutely—this is a totally valid call given your situation. Since your certificate templates are unconfigured and the root CA's 2048-bit key is below the current recommended standard (4096 bits is preferred for root CAs these days), starting fresh is a clean approach.
Just make sure you properly decommission the old CA instead of just uninstalling the role:
- Run
certutil -decommissionon the existing DC/CA to mark it as retired in Active Directory - Uninstall the AD CS role from the DC
- Clean up leftover CA objects in AD's Configuration partition (under
CN=Certification Authorities,CN=Public Key Services,CN=Services,CN=Configuration,DC=yourdomain,DC=com)
This prevents stale CA data from causing certificate trust issues down the line.
2. Will the DC just take a fresh domain-controller certificate or will it break?
No breakage here—your DC will smoothly transition to a new certificate from your fresh CA, as long as you set things up correctly:
- The built-in "Domain Controller" template is already available in AD; you just need to enable it on your new Enterprise CA.
- Once the new CA is deployed and published to AD (this happens automatically with the Enterprise CA role), the DC will automatically request a new certificate when the old one nears expiration.
- If you want to speed this up, you can force an enrollment manually with:
certreq -enroll -machine -q "Domain Controller"
Your existing valid DC certificate will keep working until it expires, so there's no downtime risk during the transition.
3. Any issues with Entra regarding this?
Entra (formerly Azure AD) integration will keep working seamlessly, as long as your DC has a valid Domain Controller certificate from a trusted CA:
- Entra Connect uses the DC's certificate for secure LDAP communication, but since your new Enterprise CA's root certificate will be pushed to all domain-joined machines (including the Entra Connect server) via Group Policy, trust is automatically established.
- Whether you're using password hash sync, pass-through authentication, or federation, there's no additional dependency on your old CA—so you won't hit any Entra-specific issues here.
备注:内容来源于stack exchange,提问作者Thomas

