<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Disaster Recovery Procedures for Active Directory Certificate Services (ADCS) </title><link>http://blogs.technet.com/b/pki/archive/2010/04/20/disaster-recovery-procedures-for-the-active-directory-certificate-services-adcs.aspx</link><description>Introduction: 
 When designing a public key infrastructure (PKI) for your organization, you must develop an effective disaster recovery plan to ensure that, in the event of failure of the computer hosting Certificate Services, you can recover in a timely</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Disaster Recovery Procedures for Active Directory Certificate Services (ADCS) </title><link>http://blogs.technet.com/b/pki/archive/2010/04/20/disaster-recovery-procedures-for-the-active-directory-certificate-services-adcs.aspx#3527256</link><pubDate>Wed, 17 Oct 2012 22:46:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3527256</guid><dc:creator>Amerk [MSFT]</dc:creator><description>&lt;p&gt;Hi Auro,&lt;/p&gt;
&lt;p&gt;You need to modify the registry key if you restored the CA to a different computer name, and re-acl the CA&amp;#39;s objects in Active Directory to make sure the CA can publish its CRL files. Step 12 in the article you referenced mentions you need to edit the registry keys.&lt;/p&gt;
&lt;p&gt;It is much simpler to restore the system to the same computer name.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3527256" width="1" height="1"&gt;</description></item><item><title>re: Disaster Recovery Procedures for Active Directory Certificate Services (ADCS) </title><link>http://blogs.technet.com/b/pki/archive/2010/04/20/disaster-recovery-procedures-for-the-active-directory-certificate-services-adcs.aspx#3527139</link><pubDate>Wed, 17 Oct 2012 11:45:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3527139</guid><dc:creator>Auro_vg</dc:creator><description>&lt;p&gt;Hello AmerK,&lt;/p&gt;
&lt;p&gt;Can you please verify the following two points ?&lt;/p&gt;
&lt;p&gt;&amp;quot;The new server must have the same computer name as the old server. Furthermore, it should have the same Operating System of the failed server&amp;quot;&lt;/p&gt;
&lt;p&gt;But, &lt;a rel="nofollow" target="_new" href="http://technet.microsoft.com/en-us/library/cc755153(v=ws.10).aspx"&gt;technet.microsoft.com/.../cc755153(v=ws.10).aspx&lt;/a&gt; did not saying anything about this.&lt;/p&gt;
&lt;p&gt;- As far my testing in lab am able to switch platforms and OS versions.&lt;/p&gt;
&lt;p&gt;- I have changed target server name and restore PKI pvt. Key and DB - this gives me an option to fall back to original server by modifying dNSHostName attribute.&lt;/p&gt;
&lt;p&gt;what is your view ?&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;
&lt;p&gt;Auro&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3527139" width="1" height="1"&gt;</description></item><item><title>re: Disaster Recovery Procedures for Active Directory Certificate Services (ADCS) </title><link>http://blogs.technet.com/b/pki/archive/2010/04/20/disaster-recovery-procedures-for-the-active-directory-certificate-services-adcs.aspx#3498241</link><pubDate>Wed, 16 May 2012 07:42:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3498241</guid><dc:creator>Terry</dc:creator><description>&lt;p&gt;Hi Amerk,&lt;/p&gt;
&lt;p&gt;Is the backup script worked for &amp;quot;Standalone root CA&amp;quot;?&lt;/p&gt;
&lt;p&gt;I try to perform &amp;quot;Certutil –catemplates &amp;gt; C:\Backup\CATemplates.txt&amp;quot;. However, it returned the error.&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Terry&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3498241" width="1" height="1"&gt;</description></item><item><title>re: Disaster Recovery Procedures for Active Directory Certificate Services (ADCS) </title><link>http://blogs.technet.com/b/pki/archive/2010/04/20/disaster-recovery-procedures-for-the-active-directory-certificate-services-adcs.aspx#3468196</link><pubDate>Wed, 30 Nov 2011 21:12:53 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3468196</guid><dc:creator>GregM</dc:creator><description>&lt;p&gt;Amerk&lt;/p&gt;
&lt;p&gt;Thanks for the quick response. &amp;nbsp;That&amp;#39;s the beauty of virtualization! &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks much!&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Greg&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3468196" width="1" height="1"&gt;</description></item><item><title>re: Disaster Recovery Procedures for Active Directory Certificate Services (ADCS) </title><link>http://blogs.technet.com/b/pki/archive/2010/04/20/disaster-recovery-procedures-for-the-active-directory-certificate-services-adcs.aspx#3468192</link><pubDate>Wed, 30 Nov 2011 20:52:41 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3468192</guid><dc:creator>Amerk [MSFT]</dc:creator><description>&lt;p&gt;Greg,&lt;/p&gt;
&lt;p&gt;You can archive the Private Key of the CA using Certutil -backupkey option and then use System State for your regular backup. One thing to keep in mind here, System State is hardware dependent, so you need to make sure you are restoring the CA on similar hardware &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3468192" width="1" height="1"&gt;</description></item><item><title>re: Disaster Recovery Procedures for Active Directory Certificate Services (ADCS) </title><link>http://blogs.technet.com/b/pki/archive/2010/04/20/disaster-recovery-procedures-for-the-active-directory-certificate-services-adcs.aspx#3468185</link><pubDate>Wed, 30 Nov 2011 20:12:57 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3468185</guid><dc:creator>GregM</dc:creator><description>&lt;p&gt;Can&amp;#39;t I just archive the private key from my Enterprise CA and use System State to back up the CA going forward? &amp;nbsp;I&amp;#39;d imagine that, after a restore of system-state (after a failure), I&amp;#39;d then have to import the private key but that shouldn&amp;#39;t be a problem, right?&lt;/p&gt;
&lt;p&gt;Thanks for a great guide!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3468185" width="1" height="1"&gt;</description></item><item><title>re: Disaster Recovery Procedures for Active Directory Certificate Services (ADCS) </title><link>http://blogs.technet.com/b/pki/archive/2010/04/20/disaster-recovery-procedures-for-the-active-directory-certificate-services-adcs.aspx#3456951</link><pubDate>Mon, 03 Oct 2011 18:26:32 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3456951</guid><dc:creator>Amerk [MSFT]</dc:creator><description>&lt;p&gt;This blog is up to date and applies to Windows Server 2008 and 2008 R2.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3456951" width="1" height="1"&gt;</description></item><item><title>re: Disaster Recovery Procedures for Active Directory Certificate Services (ADCS) </title><link>http://blogs.technet.com/b/pki/archive/2010/04/20/disaster-recovery-procedures-for-the-active-directory-certificate-services-adcs.aspx#3453211</link><pubDate>Wed, 14 Sep 2011 13:53:41 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3453211</guid><dc:creator>eax</dc:creator><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;are there any windows updates that the private keys will store in future (2008 R) in the systemstate backup or is this block up to date what the backup of private keys belongs?&lt;/p&gt;
&lt;p&gt;i have done the points, i wonder that the Database Directory has 17 MB, after a new run 18 MB.&lt;/p&gt;
&lt;p&gt;every backup i made the database directory grow about 1 MB.&lt;/p&gt;
&lt;p&gt;Why?&lt;/p&gt;
&lt;p&gt;Regards Eax&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3453211" width="1" height="1"&gt;</description></item><item><title>re: Disaster Recovery Procedures for Active Directory Certificate Services (ADCS) </title><link>http://blogs.technet.com/b/pki/archive/2010/04/20/disaster-recovery-procedures-for-the-active-directory-certificate-services-adcs.aspx#3422814</link><pubDate>Tue, 19 Apr 2011 16:40:40 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3422814</guid><dc:creator>Amerk [MSFT]</dc:creator><description>&lt;p&gt;Yes, you can use the same script to backup a 2003 CA&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3422814" width="1" height="1"&gt;</description></item><item><title>re: Disaster Recovery Procedures for Active Directory Certificate Services (ADCS) </title><link>http://blogs.technet.com/b/pki/archive/2010/04/20/disaster-recovery-procedures-for-the-active-directory-certificate-services-adcs.aspx#3422666</link><pubDate>Tue, 19 Apr 2011 07:46:33 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3422666</guid><dc:creator>Laljeev Madanamma</dc:creator><description>&lt;p&gt;Hi &lt;/p&gt;
&lt;p&gt;Thanks for the post. Shall I use the same script to backup my Windows 2003 CA&lt;/p&gt;
&lt;p&gt;Regards&lt;/p&gt;
&lt;p&gt;LMS&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3422666" width="1" height="1"&gt;</description></item></channel></rss>