Ask a question

ROBERT TAPPAN

AD Certificate Service Removal Fails - Component Store has been corrupted

I am getting this in step 11-7 of the migration tutorial removing the AD Cert Service.  At this point should I try to continue or take some other steps such as doing a force removal of the old DC.  Also at what point to am I to turn off the DFS between the old and new?

Thanks in advance!


Add Comment
Last Activity 04/10/2018 06:23

1 Answer(s)

  • Mariette Knap
    Add Comment
    ROBERT TAPPAN

    Hi Mariette

    The DFS is in sync and up to date and all the client machines are using the new server shares now so I think we can safely break the DFS and like you had mentioned set the old server to read only.

    Do you have any documentation or links on how to proceed on seizing the old DC with the ntdsutil?  My plan is to decommission the old server once these steps are completed.

    Thank you again

    Rob T

    Mariette Knap

    Hello Rob,

    Here is the documentation you need for seizing that old DC Using Ntdsutil.exe to transfer or seize FSMO roles to a domain controller.


    replied 04/06/2018 12:33
    ROBERT TAPPAN

    Hi Mariette

    The new server already has all the FSMO roles so I think we are good there.  If I just skip the graceful demotion of the old server I think there are cleanups I would need to do to remove it from the AD permanently.  I found this: https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc816826%28v%3dws.10%29

    Not sure if you agree this is best course of action.

     

    Thank you 

    Rob


    replied 04/06/2018 13:05
    Mariette Knap

    Hello Rob,

    After doing the above you need to follow this Seize the Operations Master Role | Microsoft Docs to complete the procedure.


    replied 04/07/2018 09:51
    ROBERT TAPPAN

    Again you were correct, the new server only had 3/5 roles.  I followed your instructions, broke the DFS replications, set the old server to read only on shares, before disconnecting it permanently and then seized the roles and cleaned AD.

    Couldn't have done it without you - wonderful site thank you.


    replied 04/09/2018 19:25

    Reply
    replied 04/06/2018 12:27
Add an Answer